Compare commits

...

3305 Commits

Author SHA1 Message Date
Matthew Bauer
1db42b7fe3 Merge pull request #121569 from midchildan/backport/20.03/exiftool
[20.03] perlPackages.ImageExifTool: apply fix for CVE-2021-22204
2021-05-03 10:30:14 -05:00
midchildan
f251766a21 perlPackages.ImageExifTool: apply fix for CVE-2021-22204 2021-05-03 15:34:37 +09:00
aszlig
6d1a044fc9 pythonPackages.hetzner: 0.8.2 -> 0.8.3
Recent changes in the Hetzner Robot API have removed a few obsolete
fields which version 0.8.2 was still referencing and which is now fixed
in version 0.8.3.

Due to a misunderstanding on my side I haven't updated to version 0.8.3
in nixpkgs yet, which resulted in this delay.

This fixes the NixOps Hetzner backend.

Signed-off-by: aszlig <aszlig@nix.build>
(cherry picked from commit e899b57c8a)
2021-04-05 21:10:27 +02:00
Justin Humm
1eea371907 Merge remote-tracking branch 'origin/staging-20.03' into release-20.03 2021-03-25 21:25:43 +01:00
Tyson Whitehead
9ef94a105f curl: fix hash mismatch issue by directly include CVE patches
Include instead of using fetchpatch due to boostrapping requirement.
2021-03-25 20:59:36 +01:00
Travis Athougies
462c6fe4b1 [nixos/prometheus] promTypes.filter.value -> promTypes.filter.values
The new configuration name for this is plural. Currently, attempting to enable ec2 SD results in a `promtool check config` error

(cherry picked from commit 8389fb8f16)
2021-02-26 19:39:31 -06:00
Tim Steinbach
929768261a linux: 5.4.83 -> 5.4.84
(cherry picked from commit d1a0eb7f0b)
2020-12-16 11:28:38 -05:00
Tim Steinbach
7f73e46625 linux: 5.4.81 -> 5.4.83 2020-12-11 12:42:59 -05:00
Tim Steinbach
18a87f7489 linux: 4.9.247 -> 4.9.248 2020-12-11 12:42:57 -05:00
Tim Steinbach
8cd43f2f57 linux: 4.4.247 -> 4.4.248 2020-12-11 12:42:55 -05:00
Tim Steinbach
09fd4805c6 linux: 4.19.161 -> 4.19.163 2020-12-11 12:42:54 -05:00
Tim Steinbach
634d5aa86c linux: 4.14.210 -> 4.14.212 2020-12-11 12:42:52 -05:00
markuskowa
030e2ce817 Merge pull request #105995 from markuskowa/cve-slurm-20.03
[20.03] slurm: 19.05.7.1 -> 19.05.8.1
2020-12-05 19:38:54 +01:00
Markus Kowalewski
f577872afb slurm: 19.05.7.1 -> 19.05.8.1
Addresses CVE-2020-27745 and CVE-2020-27746.
2020-12-05 17:13:05 +01:00
Tim Steinbach
0f8a31b992 linux: 5.4.80 -> 5.4.81 2020-12-02 14:40:24 -05:00
Tim Steinbach
3bd3b62c13 linux: 4.9.246 -> 4.9.247 2020-12-02 14:40:22 -05:00
Tim Steinbach
080f698b5d linux: 4.4.246 -> 4.4.247 2020-12-02 14:40:20 -05:00
Tim Steinbach
3b81ad9a4d linux: 4.19.160 -> 4.19.161 2020-12-02 14:40:19 -05:00
Tim Steinbach
48f4ff8668 linux: 4.14.209 -> 4.14.210 2020-12-02 14:40:17 -05:00
Martin Weinelt
df25e214c8 microcodeIntel: 20201112 -> 20201118
Fixes a regression on some "OEM platforms".

Relates to #104301

(cherry picked from commit 5928d66704)
2020-11-27 21:01:20 +01:00
Justin Humm
9518fac712 opensc: 0.20.0 -> 0.21.0
(cherry picked from commit 19036e0ca0)
2020-11-25 14:10:00 +01:00
Martin Weinelt
16ee69c872 sddm: add patch for CVE-2020-28049
> Local privilege escalation due to race condition in creation of the Xauthority file.

Fixes: CVE-2020-28049
(cherry picked from commit faf436ea79)
2020-11-24 20:35:55 +01:00
Tim Steinbach
d1b07d4cc4 linux: 5.4.79 -> 5.4.80 2020-11-24 10:06:00 -05:00
Tim Steinbach
12d4eedc6e linux: 4.9.245 -> 4.9.246 2020-11-24 10:05:58 -05:00
Tim Steinbach
df1c3b4ef9 linux: 4.4.245 -> 4.4.246 2020-11-24 10:05:56 -05:00
Tim Steinbach
9d4d0ffd41 linux: 4.19.159 -> 4.19.160 2020-11-24 10:05:53 -05:00
Tim Steinbach
bf14ca43fc linux: 4.14.208 -> 4.14.209 2020-11-24 10:05:51 -05:00
Martin Weinelt
eb86687de9 Merge pull request #102815 from veprbl/pr/motion_CVE-2020-26566_20.03
[20.03] motion: fix CVE-2020-26566
2020-11-23 22:17:58 +01:00
Tim Steinbach
9dba125845 linux: 5.4.78 -> 5.4.79 2020-11-23 10:56:23 -05:00
Tim Steinbach
690441cccc linux: 4.9.244 -> 4.9.245 2020-11-23 10:56:21 -05:00
Tim Steinbach
0b98507d9e linux: 4.4.244 -> 4.4.245 2020-11-23 10:56:20 -05:00
Tim Steinbach
096bad8d75 linux: 4.19.158 -> 4.19.159 2020-11-23 10:56:18 -05:00
Tim Steinbach
8e81f8f66b linux: 4.14.207 -> 4.14.208 2020-11-23 10:56:16 -05:00
Martin Weinelt
5a9e4f07f7 Merge pull request #104583 from stigtsp/package/mutt-patch-CVE-2020-28896-release-20.03
[20.03] mutt: apply patch for CVE-2020-28896
2020-11-22 13:23:37 +01:00
Stig Palmquist
4586b2f0d0 mutt: apply patch for CVE-2020-28896
mutt has improper handling of broken IMAP connections, this could result
in authentication credentials being sent over an unencrypted connection,
without $ssl_force_tls being consulted.

https://security.archlinux.org/CVE-2020-28896
04b06aaa3e
2020-11-22 11:27:10 +01:00
Martin Weinelt
eee7621c2a Merge pull request #104481 from taku0/thunderbird-bin-78.5.0_release-20.03
[20.03] thunderbird, thunderbird-bin: 78.4.0 -> 78.5.0 [High security fixes]
2020-11-22 01:30:05 +01:00
Martin Milata
8f90227892 glfw: 3.3.1 -> 3.3.2
(cherry picked from commit ebb3d1a9a4)
2020-11-21 11:44:53 +01:00
Robert Scott
8fdb672c6a opencv3, opencv4: use openblasCompat
without master's fix in #83888, opencv3 & opencv4 end up with an 8-byte
openblas, which it does work with. however this causes the python
bindings to also end up with an 8-byte openblas, which numpy doesn't work
with. force 4-byte openblas for opencv.
2020-11-21 11:42:45 +01:00
taku0
9582840033 thunderbird: 78.4.3 -> 78.5.0
(cherry picked from commit 19682545d9)
2020-11-21 18:31:52 +09:00
taku0
a49b9a2d47 thunderbird-bin: 78.4.3 -> 78.5.0
(cherry picked from commit 52f5b947f6)
2020-11-21 18:31:52 +09:00
taku0
b1f30a6328 thunderbird: 78.4.2 -> 78.4.3
(cherry picked from commit 205652e31a)
2020-11-21 18:31:52 +09:00
taku0
5a2ff043f4 thunderbird-bin: 78.4.2 -> 78.4.3
(cherry picked from commit ec5fc9b7a4)
2020-11-21 18:31:51 +09:00
taku0
aa5c34294f thunderbird: 78.4.1 -> 78.4.2
(cherry picked from commit bd03a75f6f)
2020-11-21 18:31:51 +09:00
taku0
bd561c832a thunderbird-bin: 78.4.1 -> 78.4.2
(cherry picked from commit d19906002f)
2020-11-21 18:31:51 +09:00
taku0
a4c4b509fc thunderbird: 78.4.0 -> 78.4.1
(cherry picked from commit 00213ef17f)
(with modification)
2020-11-21 18:31:38 +09:00
taku0
e1e6b25924 thunderbird-bin: 78.4.0 -> 78.4.1
(cherry picked from commit 33a3ac3169)
2020-11-21 18:30:35 +09:00
Frederik Rietdijk
fdcd102ddd Merge pull request #104362 from NixOS/staging-20.03
Merge staging-20.03 into release-20.03
2020-11-21 08:56:19 +01:00
Maximilian Bosch
c2967aeb05 neomutt: apply patch to mitigate CVE-2020-28896
See https://github.com/neomutt/neomutt/releases/tag/20201120 &
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28896 for
further information.

It seems as `neomutt` (and also `mutt`) had an improper handling of
broken IMAP connections and thus a risk of leaking sensitive
information. The relevant patch can be found at
9c36717a3e
2020-11-20 22:50:50 +01:00
Christian Kauhaus
6d27bb8d75 Merge pull request #102866 from redvers/update_balsa_2.5.9_to_balsa_2.5.11
balsa: 2.5.9 -> 2.5.11 [20.03]
2020-11-20 17:02:54 +01:00
Michael Weiss
7deaa010f9 chromium: 86.0.4240.198 -> 87.0.4280.66
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_17.html

This update includes 33 security fixes.

CVEs:
CVE-2020-16018 CVE-2020-16019 CVE-2020-16020 CVE-2020-16021
CVE-2020-16022 CVE-2020-16015 CVE-2020-16014 CVE-2020-16023
CVE-2020-16024 CVE-2020-16025 CVE-2020-16026 CVE-2020-16027
CVE-2020-16028 CVE-2020-16029 CVE-2020-16030 CVE-2019-8075
CVE-2020-16031 CVE-2020-16032 CVE-2020-16033 CVE-2020-16034
CVE-2020-16035 CVE-2020-16012 CVE-2020-16036

Note: We'll finally build with use_ozone=true on Hydra now :) \o/
(cherry picked from commit 54673b1f3b)
Backport of #104100.
2020-11-20 10:40:28 +01:00
Martin Weinelt
864a73be91 openldap: apply security patches
Fixes: CVE-2020-25692, CVE-2020-25709, CVE-2020-25710
2020-11-19 20:39:42 +01:00
Frederik Rietdijk
d9d65c6344 Merge release-20.03 into staging-20.03 2020-11-19 20:14:29 +01:00
Tim Steinbach
d488daf850 linux: 5.4.77 -> 5.4.78 2020-11-19 09:10:43 -05:00
Tim Steinbach
7fc57f2020 linux: 4.9.243 -> 4.9.244 2020-11-19 09:10:41 -05:00
Tim Steinbach
60003aa6e5 linux: 4.4.243 -> 4.4.244 2020-11-19 09:10:40 -05:00
Tim Steinbach
31cf3b3caa linux: 4.19.157 -> 4.19.158 2020-11-19 09:10:38 -05:00
Tim Steinbach
b88fbf2abd linux: 4.14.206 -> 4.14.207 2020-11-19 09:10:37 -05:00
Andreas Rammhold
f05c380a51 Merge pull request #104093 from stigtsp/package/firefox-bin-83.0-backport-20.03
[20.03] firefox-bin: 82.0 -> 83.0
2020-11-17 22:57:09 +01:00
Stig Palmquist
dcffaedac7 firefox-bin: 82.0.3 -> 83.0
(cherry picked from commit 668f3772d2)
2020-11-17 22:01:18 +01:00
Stig Palmquist
497b6020c2 firefox-bin: 82.0.2 -> 82.0.3
(cherry picked from commit 10712e7b5f)
2020-11-17 22:00:04 +01:00
Andreas Rammhold
c1118dae75 firefox-bin: 82.0 -> 82.0.2
(cherry picked from commit fdbdd72f5f)
2020-11-17 21:59:22 +01:00
Andreas Rammhold
30880c9275 firefox-esr: 78.4.0esr -> 78.4.1esr
(cherry picked from commit d93868a92b)
2020-11-17 13:44:44 +01:00
Andreas Rammhold
4c72e033de firefox: 82.0.2 -> 82.0.3
(cherry picked from commit 046002f472)
2020-11-17 13:44:07 +01:00
Vincent Demeester
db46d7b20a youtube-dl: 2020.11.01.1 -> 2020.11.12
Signed-off-by: Vincent Demeester <vincent@sbr.pm>
(cherry picked from commit b8065eeaef)
2020-11-16 16:30:41 +00:00
zowoq
7abaad0dc9 go_1_14: 1.14.11 -> 1.14.12
(cherry picked from commit 1692a8a584)
2020-11-14 23:47:03 +10:00
zowoq
590e678b8e go_1_14: 1.14.10 -> 1.14.11
(cherry picked from commit ffb658f66a)
2020-11-14 23:47:03 +10:00
zowoq
d36da9ac6f go_1_14: 1.14.9 -> 1.14.10
(cherry picked from commit 4f282b19bd)
2020-11-14 23:47:03 +10:00
zowoq
9a6c02e8a0 go_1_14: 1.14.8 -> 1.14.9
(cherry picked from commit 619061532a)
2020-11-14 23:47:03 +10:00
Andreas Rammhold
86fa45b0ff Merge pull request #103707 from mweinelt/20.03/microcodeIntel
[20.03] microcodeIntel: 20200616 -> 20201112
2020-11-14 02:48:13 +01:00
Martin Weinelt
bad3f7b693 microcodeIntel: 20201110 -> 20201112
Update to Pentium Silver N/J5xxx, Celeron N/J4xxx

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00381.html
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389.html

Fixes: CVE-2020-8694, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698
(cherry picked from commit eaf889aea0)
2020-11-13 15:38:22 +01:00
Martin Weinelt
18a94f814f microcodeIntel: 20200616 -> 20201110
Release notes:
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20201110

Security advisories:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00381.html
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389.html

Fixes: CVE-2020-8694, CVE-2020-8695, CVE-2020-8696, CVE-2020-8698
(cherry picked from commit a79902f23e)
2020-11-13 15:38:16 +01:00
Martin Weinelt
51105e33db librdf_raptor2: add patch for CVE-2017-18926
Fixes two heap overflows in the raptor2 rdf parsing library.

https://www.openwall.com/lists/oss-security/2017/06/07/1
(cherry picked from commit 22140b27f2)
2020-11-13 15:06:01 +01:00
Dominik Xaver Hörl
16b3b1eef0 tor-browser-bundle-bin: 10.0.2 -> 10.0.4
(cherry picked from commit 9e8f4ff79a)
2020-11-13 13:18:14 +01:00
Chuck
9315a5fcd8 tor-browser-bundle-bin: Fix extension path. Fixes NoScript.
(cherry picked from commit 4117c0b7df)
2020-11-13 13:14:31 +01:00
Michael Weiss
b5f0a7db05 chromium: 86.0.4240.193 -> 86.0.4240.198
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html

This update includes 2 security fixes. Google is aware of reports that
exploits for CVE-2020-16013 and CVE-2020-16017 exist in the wild.

CVEs: CVE-2020-16013 CVE-2020-16017
(cherry picked from commit b91153fd7a)
Backport of #103595.
2020-11-13 11:23:08 +01:00
Tim Steinbach
5d820315cd linux: 5.4.76 -> 5.4.77 2020-11-11 15:43:56 -05:00
Tim Steinbach
c539e2fced linux: 4.9.242 -> 4.9.243 2020-11-11 15:43:54 -05:00
Tim Steinbach
e4f15b2fa6 linux: 4.4.242 -> 4.4.243 2020-11-11 15:43:53 -05:00
Tim Steinbach
838e06daba linux: 4.19.156 -> 4.19.157 2020-11-11 15:43:51 -05:00
Tim Steinbach
6e3ca0f8cc linux: 4.14.205 -> 4.14.206 2020-11-11 15:43:50 -05:00
Michael Weiss
abe53c3191 chromium: 86.0.4240.183 -> 86.0.4240.193
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_9.html

This update includes 1 security fix (no CVE).

(cherry picked from commit 841664a172)
2020-11-11 16:17:41 +01:00
Michael Weiss
67d9c40ccd chromium: Extend update.py to automatically update gn
The gn version depends on the channel and new gn versions aren't always
backward compatible. Therefore we should also include it in
upstream-info.json (I've scoped it under "deps" as we'll likely have to
add more like this in the future).

(cherry picked from commit d7f5386474)
2020-11-11 16:16:42 +01:00
Martin Weinelt
3b28e23a04 nats-server: 2.1.7 -> 2.1.9
Fixes: CVE-2020-26521, CVE-2020-26892
(cherry picked from commit b2a20c2a51)
2020-11-11 11:21:12 +01:00
R. RyanTM
f341eb2728 nats-server: 2.1.0 -> 2.1.7
(cherry picked from commit 47d8d4a54d)
2020-11-11 11:21:12 +01:00
Ivan Kozik
30e67e965c linuxPackages.wireguard: fix the build on linux 5.4.76
Patch copied from https://github.com/archlinux/svntogit-packages/blob/packages/wireguard-dkms/trunk/lts.diff

This fixes:

```
In file included from <command-line>:
/build/source/src/compat/compat-asm.h:44: warning: "SYM_FUNC_START" redefined
   44 | #define SYM_FUNC_START ENTRY
      |
In file included from /build/source/src/compat/compat-asm.h:9,
                 from <command-line>:
/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/include/linux/linkage.h:218: note: this is the location of the previous definition
  218 | #define SYM_FUNC_START(name)    \
      |
In file included from <command-line>:
/build/source/src/compat/compat-asm.h:45: warning: "SYM_FUNC_END" redefined
   45 | #define SYM_FUNC_END ENDPROC
      |
In file included from /build/source/src/compat/compat-asm.h:9,
                 from <command-line>:
/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/include/linux/linkage.h:265: note: this is the location of the previous definition
  265 | #define SYM_FUNC_END(name)    \
      |
/build/source/src/crypto/zinc/blake2s/blake2s-x86_64.S: Assembler messages:
/build/source/src/crypto/zinc/blake2s/blake2s-x86_64.S:50: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/blake2s/blake2s-x86_64.S:176: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/blake2s/blake2s-x86_64.S:180: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/blake2s/blake2s-x86_64.S:257: Error: invalid character '(' in mnemonic
make[3]: *** [/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/scripts/Makefile.build:348: /build/source/src/crypto/zinc/blake2s/blake2s-x86_64.o] Error 1
make[3]: *** Waiting for unfinished jobs....
In file included from <command-line>:
/build/source/src/compat/compat-asm.h:44: warning: "SYM_FUNC_START" redefined
   44 | #define SYM_FUNC_START ENTRY
      |
In file included from /build/source/src/compat/compat-asm.h:9,
                 from <command-line>:
/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/include/linux/linkage.h:218: note: this is the location of the previous definition
  218 | #define SYM_FUNC_START(name)    \
      |
In file included from <command-line>:
/build/source/src/compat/compat-asm.h:45: warning: "SYM_FUNC_END" redefined
   45 | #define SYM_FUNC_END ENDPROC
      |
In file included from /build/source/src/compat/compat-asm.h:9,
                 from <command-line>:
/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/include/linux/linkage.h:265: note: this is the location of the previous definition
  265 | #define SYM_FUNC_END(name)    \
      |
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S: Assembler messages:
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:123: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:185: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:187: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:319: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:1016: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:1616: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:1620: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:1810: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:1812: Error: invalid character '(' in mnemonic
/build/source/src/crypto/zinc/chacha20/chacha20-x86_64.S:1959: Error: invalid character '(' in mnemonic
make[3]: *** [/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/scripts/Makefile.build:348: /build/source/src/crypto/zinc/chacha20/chacha20-x86_64.o] Error 1
make[2]: *** [/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/Makefile:1729: /build/source/src] Error 2
make[1]: *** [/nix/store/cz60577g5hwk78c2z7rhxl21bklaqr0d-linux-5.4.77-dev/lib/modules/5.4.77-hardened/source/Makefile:179: sub-make] Error 2
make: *** [Makefile:26: module] Error 2
builder for '/nix/store/hll3sjyrwa55arzlsxnbacqdd8s842l1-wireguard-1.0.20200908.drv' failed with exit code 2
```

(cherry picked from commit c945b47a25)
2020-11-11 10:28:35 +01:00
Tim Steinbach
336baf0d09 linux: 5.4.75 -> 5.4.76 2020-11-10 09:13:07 -05:00
Tim Steinbach
6bb461e607 linux: 4.9.241 -> 4.9.242 2020-11-10 09:13:05 -05:00
Tim Steinbach
276fcac12b linux: 4.4.241 -> 4.4.242 2020-11-10 09:13:04 -05:00
Tim Steinbach
626729bdfe linux: 4.19.155 -> 4.19.156 2020-11-10 09:13:03 -05:00
Tim Steinbach
c80ec27929 linux: 4.14.204 -> 4.14.205 2020-11-10 09:13:01 -05:00
Maximilian Bosch
2257e6cf4d element-desktop: 1.7.12 -> 1.7.13
https://github.com/vector-im/element-desktop/releases/tag/v1.7.13
(cherry picked from commit ad63addc5e)
2020-11-09 18:06:00 +01:00
Maximilian Bosch
9dc018cac9 element-web: 1.7.12 -> 1.7.13
https://github.com/vector-im/element-web/releases/tag/v1.7.13
(cherry picked from commit feb893a6f8)
2020-11-09 18:06:00 +01:00
Andreas Rammhold
ad42cb8406 Merge pull request #102844 from redvers/update_apacheAnt_1_9_2003_1.9.15
apacheAnt_1_9: 1.9.6 -> 1.9.15 [20.03]
2020-11-09 11:52:55 +01:00
Martin Weinelt
18f8c1fe06 libexif: apply patches for CVE-2020-0198, CVE-2020-0452
* CVE-2020-0198: unsigned integer overflow in exif_data_load_data_content
* CVE-2020-0452: compiler optimization could remove an a bufferoverflow check, making a buffer overflow possible with some EXIF tags

Fixes: CVE-2020-0198, CVE-2020-0452
(cherry picked from commit 602d26e8bd)
2020-11-08 22:12:14 +01:00
Florian Klink
0bf298df24 Merge pull request #102159 from toonn/release-20.03
[20.03] wire-desktop: linux 3.20.2934 -> 3.21.2936, mac 3.20.3912 -> 3.21.3959
2020-11-06 16:28:38 +01:00
Robert Hensing
29b450fd8b Merge pull request #100332 from mcmtroffaes/feature/wolfssl-backport
wolfssl: 4.4.0 -> 4.5.0 [backport to 20.03]
2020-11-06 00:48:18 +01:00
markuskowa
5a62e5632f Merge pull request #100895 from jbedo/singularity-20.03
[20.03] singularity: 3.6.1 -> 3.6.4
2020-11-06 00:14:47 +01:00
Justin Bedo
b63c23511c singularity: 3.6.1 -> 3.6.4
Addresses CVEs:

- CVE-2020-25040
- CVE-2020-25039
2020-11-06 08:33:53 +11:00
Andreas Rammhold
a0756f9e88 Merge pull request #102941 from mweinelt/20.03/tmux
[20.03] tmux: apply patch for CVE-2020-27347
2020-11-05 19:28:55 +01:00
Martin Weinelt
d81f5d9ef3 Merge pull request #102863 from redvers/update_axel_2.17.7_to_2.17.9
axel: 2.17.7 -> 2.17.9 [20.03]
2020-11-05 17:09:47 +01:00
Martin Weinelt
e138b425ea tmux: apply patch for CVE-2020-27347
Fixes a buffer overflow in the escape sequence parser.

Fixes: CVE-2020-27347
2020-11-05 17:01:55 +01:00
Tim Steinbach
688286e5e9 linux: 5.4.74 -> 5.4.75 2020-11-05 09:51:50 -05:00
Tim Steinbach
3f3186c76b linux: 4.19.154 -> 4.19.155 2020-11-05 09:51:48 -05:00
Tim Steinbach
75bde93266 linux: 4.14.203 -> 4.14.204 2020-11-05 09:51:46 -05:00
Martin Weinelt
9ec0d8c8a5 Merge pull request #96881 from aanderse/solr-backport
solr: 8.4.1 -> 8.6.1 [20.03 backport]
2020-11-05 13:11:29 +01:00
Red Davies
32d313ffb6 balsa: 2.5.9 -> 2.5.11 2020-11-05 06:00:41 +00:00
R. RyanTM
5619d39e1d axel: 2.17.8 -> 2.17.9
(cherry picked from commit b467a11d76)
2020-11-05 05:40:03 +00:00
R. RyanTM
1fbed80dfe axel: 2.17.7 -> 2.17.8
(cherry picked from commit 6eee5229c5)
2020-11-05 05:39:51 +00:00
Daniel Șerbănescu
d70b1e2d2d ant: 1.9.6 -> 1.9.15
(cherry picked from commit 9072b63bcb)
2020-11-05 00:01:42 +00:00
Dmitry Kalinkin
d6582d8876 motion: fix CVE-2020-26566
https://nvd.nist.gov/vuln/detail/CVE-2020-26566
2020-11-04 12:20:29 -05:00
Michael Weiss
d2f4600282 chromium: 86.0.4240.111 -> 86.0.4240.183
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html

This update includes 10 security fixes. Google is aware of reports that
an exploit for CVE-2020-16009 exists in the wild.

CVEs:
CVE-2020-16004 CVE-2020-16005 CVE-2020-16006 CVE-2020-16007
CVE-2020-16008 CVE-2020-16009 CVE-2020-16011

(cherry picked from commit 531decc11d)
Backport of #102608. I'll push this directly as it should build fine and
we need the security fixes timely (see above).
2020-11-03 19:34:39 +01:00
Michael Weiss
90c1c4056c chromiumDev: 88.0.4292.2 -> 88.0.4298.4
This should also fix VA-API for chromiumBeta (though that part needs
some cleanup). However, chromiumDev likely still fails due to the
absence of dirmd (not included in the tarball so far, we might have to
package and add it as a dependency).

(cherry picked from commit 50a2f50acb)
2020-11-03 19:34:39 +01:00
Andreas Rammhold
fc997fd8f5 Merge pull request #102646 from mweinelt/20.03/salt
[20.03] salt: 2019.2.4 -> 2019.2.7
2020-11-03 19:32:44 +01:00
Martin Weinelt
34883479d7 salt: 2019.2.4 -> 2019.2.7
Fixes: CVE-2020-16846, CVE-2020-17490, CVE-2020-25592
2020-11-03 19:22:41 +01:00
Tim Steinbach
fbd345dd00 linux: 5.4.73 -> 5.4.74 2020-11-03 10:55:49 -05:00
Anderson Torres
e3d393e717 Merge pull request #102374 from mweinelt/20.03/ytdl
[20.03] youtube-dl: 2020-09-20 -> 2020.11.01.1
2020-11-01 18:58:47 -03:00
Jörg Thalheim
c3d544e2ef Merge pull request #102371 from mweinelt/20.03/openldap
[staging-20.03] openldap: add patch to fix unauthenticated nullptr dereference in slapd
2020-11-01 19:32:42 +01:00
Martin Weinelt
57b3ed6c47 youtube-dl: 2020-09-20 -> 2020.11.01.1
(cherry picked from commit 2038e9139ce70517bd4e7fe929bad174b4cbc4e7)
2020-11-01 19:25:57 +01:00
Martin Weinelt
3b3b0d5ba7 openldap: add patch to fix unauthenticated nullptr dereference in slapd
This vulnerability does not have a CVE yet.

https://security-tracker.debian.org/tracker/TEMP-0000000-DD4835
https://bugs.openldap.org/show_bug.cgi?id=9370
(cherry picked from commit 307abd9eae)
2020-11-01 18:54:29 +01:00
WORLDofPEACE
6a6e7c9512 Merge pull request #99911 from andir/20.03/zoneminder-CVE-2020-25729
[20.03] zoneminder: fix CVE-2020-25729
2020-10-31 15:29:13 -04:00
WORLDofPEACE
5c52210f33 Merge pull request #101239 from matthiasbeyer/nixos-20.03-backport-yed
[20.03] backport yed updates
2020-10-31 15:28:28 -04:00
S. Nordin Abouzahra
e09c7f0b1f firefox: place alsaLib in lib search patch
libcubeb has dlopened libraries for awhile now. In nixpkgs there was
support for the PulseAudio backend doing this, however the ALSA backend
support was missed and caused issue #79310 (no sound with ALSA). This
gives ALSA users the ability to hear sound once again.

(cherry picked from commit 57ea265674)
2020-10-31 19:30:37 +01:00
Maximilian Bosch
050b0068e5 matrix-synapse: 1.22.0 -> 1.22.1
https://github.com/matrix-org/synapse/releases/tag/v1.22.1
(cherry picked from commit 460a30c15b)
2020-10-31 19:07:27 +01:00
Tim Steinbach
291e3c6d5c linux: 4.19.153 -> 4.19.154 2020-10-30 09:38:30 -04:00
toonn
3343effc32 wire-desktop: mac 3.20.3912 -> 3.21.3959
(cherry picked from commit e6a44b2fc4)
2020-10-30 09:05:25 +01:00
toonn
34e48e0313 wire-desktop: linux 3.20.2934 -> 3.21.2936
(cherry picked from commit fa20999c64)
2020-10-30 09:05:20 +01:00
Tim Steinbach
27212188ee linux: 5.4.72 -> 5.4.73 2020-10-29 17:07:17 -04:00
Tim Steinbach
91cf7b7481 linux: 4.9.240 -> 4.9.241 2020-10-29 17:07:15 -04:00
Tim Steinbach
08acf53426 linux: 4.4.240 -> 4.4.241 2020-10-29 17:07:13 -04:00
Tim Steinbach
90a9f46240 linux: 4.19.152 -> 4.19.153 2020-10-29 17:07:11 -04:00
Tim Steinbach
25bc63ca7b linux: 4.14.202 -> 4.14.203 2020-10-29 17:07:08 -04:00
Maximilian Bosch
504f993df9 matrix-synapse: make dependency for hiredis optional
This is only needed for replication which isn't even supported by the
current NixOS module.

(cherry picked from commit ff9487703e)
2020-10-28 22:39:07 +01:00
Maximilian Bosch
e39c1f4ef1 matrix-synapse: 1.21.2 -> 1.22.0
https://github.com/matrix-org/synapse/releases/tag/v1.22.0
(cherry picked from commit 2e2eea4338)
2020-10-28 22:39:07 +01:00
Maximilian Bosch
e416746006 element-desktop: 1.7.10 -> 1.7.12
https://github.com/vector-im/element-desktop/releases/tag/v1.7.11
https://github.com/vector-im/element-desktop/releases/tag/v1.7.12
(cherry picked from commit 9d5c765e33)
2020-10-28 22:39:07 +01:00
Maximilian Bosch
00f3a335e3 element-web: 1.7.10 -> 1.7.12
https://github.com/vector-im/element-web/releases/tag/v1.7.11
https://github.com/vector-im/element-web/releases/tag/v1.7.12
(cherry picked from commit 135f6b62dd)
2020-10-28 22:39:07 +01:00
WilliButz
ae6f01d549 prometheus-snmp-exporter: 0.18.0 -> 0.19.0
https://github.com/prometheus/snmp_exporter/releases/tag/v0.19.0
(cherry picked from commit 1c90c5bcc4)
2020-10-28 16:16:23 +01:00
Sergey Lukjanov
e58039a750 snmp_exporter: 0.17.0 -> 0.18.0
(cherry picked from commit 01c937fd47)
2020-10-28 16:16:15 +01:00
Cole Mickens
6b5f85a62c google-chrome: add libxkbcommon+wayland for ozone/wayland
(cherry picked from commit 9eaddfda7f)
2020-10-27 21:55:19 +01:00
Samuel Gräfenstein
e2b583332a google-chrome-{beta,dev}: fix icons (#95389)
The icon naming scheme for Chrome Beta/Dev has changed from
`product_logo_{res}.png` to `product_logo_{res}_{branch}.png`.

(cherry picked from commit 9b06980c61)
2020-10-27 21:55:18 +01:00
Jörg Thalheim
8148771b1a Merge #101611: firefox-bin: 81.0.2 -> 82.0
(cherry picked from commit 2f31499703)
vcunat tested it briefly on 20.03.
2020-10-27 10:47:33 +01:00
Justin Humm
7cfafd014f tor-browser-bundle-bin: 10.0 -> 10.0.2
(cherry picked from commit 03d85e8aac)
2020-10-25 19:46:07 +01:00
rnhmjoj
e350840f0a arx-libertatis: remove old override
(cherry picked from commit 9ae47f9e64)
2020-10-25 17:31:14 +01:00
Benjamin Hipple
e171f096a2 Merge pull request #101491 from buckley310/release-20.03
[20.03] brave: 1.11.97 -> 1.15.76
2020-10-24 22:59:51 -04:00
Vladimír Čunát
a26e92a67d Merge #101380: thunderbird*: 78.3.2 -> 78.4.0
(cherry picked from commit c0a646edd0)
Re-tested both briefly atop 20.03.
2020-10-24 11:11:28 +02:00
TredwellGit
90c27d8f12 mumble: 1.3.1 -> 1.3.3
https://github.com/mumble-voip/mumble/releases/tag/1.3.3
(cherry picked from commit 1bc72b3494)
2020-10-23 23:29:55 +02:00
Sean Buckley
124e931ed0 brave: 1.11.97 -> 1.15.76 2020-10-23 14:57:30 -04:00
Eelco Dolstra
b7bcf5e247 test-driver.py: Fix deadlock when the log queue gets full
If a program (e.g. nixos-install) writes more than 1000 lines to
stderr during execute(), then process_serial_output() deadlocks
waiting for the queue to be processed. So use an unbounded queue
instead.

We should probably get rid of the structured log output (log.xml),
since then we don't need the log queue anymore.

(cherry picked from commit 78f2a83029)
2020-10-23 05:44:38 +02:00
Justin Humm
afcf35320d freetype: patch CVE-2020-15999
We can't backport https://github.com/NixOS/nixpkgs/pull/101199 as it
would break freetype API, but this patch should fix the issue.
2020-10-22 12:26:15 +02:00
TredwellGit
b560967c7e chromium: 86.0.4240.75 -> 86.0.4240.111
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html

CVE-2020-16000 CVE-2020-16001 CVE-2020-16002 CVE-2020-15999 CVE-2020-16003

(cherry picked from commit 7dc2d9f819)
Backport of #101306.
2020-10-22 11:54:17 +02:00
Michael Weiss
648d838d3d chromiumDev: M87 -> M88
(cherry picked from commit aee3076ba7)
2020-10-22 11:54:07 +02:00
Michael Weiss
f433ace3fd chromiumBeta: M86 -> M87
(cherry picked from commit a667bc7ae1)
2020-10-22 11:54:06 +02:00
Justin Humm
9641db654f Revert "freetype: 2.10.2 -> 2.10.4"
This reverts commit 3f8fd69df2.

As it broke at least ghostscript and therefore caused a huge amount
of dependency failures.
2020-10-22 11:42:24 +02:00
Maximilian Bosch
ba9579acd8 element-desktop: 1.7.9 -> 1.7.10
https://github.com/vector-im/element-desktop/releases/tag/v1.7.10
(cherry picked from commit d976433296)
2020-10-22 11:10:26 +02:00
Maximilian Bosch
0b30848632 element-web: 1.7.9 -> 1.7.10
https://github.com/vector-im/element-web/releases/tag/v1.7.10
(cherry picked from commit 96f29b90a1)
2020-10-22 11:10:25 +02:00
TredwellGit
3f8fd69df2 freetype: 2.10.2 -> 2.10.4
https://sourceforge.net/projects/freetype/files/freetype2/2.10.4/
(cherry picked from commit 3775af7057)
2020-10-22 00:53:01 +02:00
Kim Lindberger
574fd3e4e2 Merge pull request #100562 from talyz/20.03-nomachine-6.12.3
nomachine-client: 6.11.2 -> 6.12.3
2020-10-21 19:01:58 +02:00
Maximilian Bosch
4f036a5548 Merge pull request #101181 from etu/2003-php72-update
[20.03] php72: 7.2.32 -> 7.2.34
2020-10-21 15:51:08 +02:00
Maxwell L-T
680cf57169 yed: 3.20 -> 3.20.1
(cherry picked from commit d3a2be1e7e)
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
2020-10-21 09:47:20 +02:00
R. RyanTM
674b4dd8e3 yed: 3.19.1.1 -> 3.20
(cherry picked from commit 0e0995d14c)
Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
2020-10-21 09:47:19 +02:00
Andreas Rammhold
023c219aa3 Merge pull request #101190 from andir/20.03/firefox-82
[20.03] firefox: 81.0.2 -> 82.0, firefox-esr-78: 78.3.1esr -> 78.4.0esr
2020-10-20 20:49:52 +02:00
Justin Humm
b94c22f717 opensc: patch for CVE-2020-26570, CVE-2020-26572
(cherry picked from commit c4237e2be1)
2020-10-20 17:34:35 +02:00
Andreas Rammhold
386af259ce firefox: 78.3.1esr -> 78.4.0esr
(cherry picked from commit 910a4bc162a3a2d884999d0ba3e65a454721f10a)
2020-10-20 17:10:09 +02:00
Andreas Rammhold
f20eefd55e firefox: 81.0.2 -> 82.0
(cherry picked from commit df959d06c40af7f275741530ad7158faf0a46e1a)
2020-10-20 17:10:09 +02:00
Andreas Rammhold
16a3eb65f5 nss_latest: 3.56 -> 3.57 2020-10-20 17:10:09 +02:00
Elis Hirwing
ed0d061c19 php72: 7.2.32 -> 7.2.34 2020-10-20 16:43:55 +02:00
Vladimír Čunát
7c2a362b58 Merge #100808: thunderbird*: 78.3.2 -> 78.3.3
(cherry picked from commit 176243b059)
Re-tested both of them briefly atop 20.03 as well.
2020-10-20 09:32:31 +02:00
Vladimír Čunát
0056f627a0 Merge #98415: wordnet: Fix darwin build
(cherry picked from commit 81b1356944)
2020-10-20 08:53:11 +02:00
Christian Kauhaus
d7d3210188 Merge pull request #100753 from woffs/shotcut-remove-upgrade-prompt-20.03
shotcut: disable upgrade prompt
2020-10-19 20:51:28 +02:00
Tim Steinbach
f702aab2d9 linux: 5.4.71 -> 5.4.72 2020-10-17 15:27:16 -04:00
Tim Steinbach
9a9d5ac83c linux: 4.9.239 -> 4.9.240 2020-10-17 15:27:14 -04:00
Tim Steinbach
357b14cfe9 linux: 4.4.239 -> 4.4.240 2020-10-17 15:27:12 -04:00
Tim Steinbach
2db182abc8 linux: 4.19.151 -> 4.19.152 2020-10-17 15:27:10 -04:00
Tim Steinbach
8117e60bef linux: 4.14.201 -> 4.14.202 2020-10-17 15:27:08 -04:00
Maximilian Bosch
90813d6e12 matrix-synapse: 1.21.0 -> 1.21.2
https://github.com/matrix-org/synapse/releases/tag/v1.21.1 [1]
https://github.com/matrix-org/synapse/releases/tag/v1.21.2

[1] Not really relevant for as since only a bug in the Debian packaging
    was fixed.

(cherry picked from commit 8886cb63e2)
2020-10-16 22:22:13 +02:00
Frank Doepper
47a0d2d414 shotcut: disable upgrade prompt
as suggested by @ddennedy
fixes #99851
2020-10-16 21:47:02 +02:00
Vladimír Čunát
eed40fcc8e Merge #100493: thunderbird-*: 78.3.1 -> 78.3.2 2020-10-16 08:14:21 +02:00
talyz
b1eaa2d6d2 nomachine-client: 6.11.2 -> 6.12.3
(cherry picked from commit e635dccfdd)
2020-10-15 09:47:54 +02:00
Jan Tojnar
8fa9a8aa02 Revert "nixos/display-managers: install sessionData.desktops"
This reverts commit d74573d8ae.

Seems to cause issues with MATE for some reason and not really worth it investigating so close to EOL.

Fixes: https://github.com/NixOS/nixpkgs/issues/100464
2020-10-15 00:06:01 +02:00
Tim Steinbach
eabc31612e linux: 5.4.70 -> 5.4.71 2020-10-14 08:57:34 -04:00
Tim Steinbach
6d16bb3c09 linux: 4.9.238 -> 4.9.239 2020-10-14 08:57:31 -04:00
Tim Steinbach
33a72a3ca6 linux: 4.4.238 -> 4.4.239 2020-10-14 08:57:29 -04:00
Tim Steinbach
aecb627f89 linux: 4.19.150 -> 4.19.151 2020-10-14 08:57:26 -04:00
Tim Steinbach
f973d9f813 linux: 4.14.200 -> 4.14.201 2020-10-14 08:57:23 -04:00
taku0
7def3b549e thunderbird-bin: 78.2.2 -> 78.3.2
(cherry picked from commit 456106fe2a)
2020-10-14 21:51:12 +09:00
taku0
65153e9f14 thunderbird: 78.2.2 -> 78.3.2
(cherry picked from commit e46afe0f89)
2020-10-14 21:51:12 +09:00
Rok Garbas
c1e3ea8c2b Merge pull request #100468 from taku0/flashplayer-32.0.0.445_release-20.03
[20.03] flashplayer: 32.0.0.433 -> 32.0.0.445 (Critical security fix)
2020-10-14 14:12:04 +02:00
Rok Garbas
b7ae362054 Merge pull request #100458 from taku0/firefox-bin-81.0.2_release-20.03
[20.03] firefox, firefox-bin: 81.0 -> 81.0.2, firefox-esr: 78.3.0esr -> 78.3.1esr
2020-10-14 14:03:46 +02:00
taku0
51e920df6d flashplayer: 32.0.0.433 -> 32.0.0.445
(cherry picked from commit 52dcd5b211)
(removed ungoogled-chromium)
2020-10-14 12:32:30 +09:00
taku0
9ce60fdcf2 firefox-esr: 78.3.0esr -> 78.3.1esr
(cherry picked from commit 560cc80818)
2020-10-14 09:29:29 +09:00
taku0
7c42577155 firefox-bin: 81.0 -> 81.0.2
(cherry picked from commit 68a9d42e0d)
2020-10-14 09:29:28 +09:00
taku0
e1c3cfecb8 firefox: 81.0 -> 81.0.2
(cherry picked from commit 05b955a133)
2020-10-14 09:29:28 +09:00
R. RyanTM
3a10a004bb python37Packages.canonicaljson: 1.3.0 -> 1.4.0
(cherry picked from commit ed9c3d4796)
2020-10-13 17:58:20 +02:00
Maximilian Bosch
8e5088cd2d matrix-synapse: 1.20.1 -> 1.21.0
https://github.com/matrix-org/synapse/releases/tag/v1.21.0
(cherry picked from commit 87414de4ca)
2020-10-13 17:56:59 +02:00
Michele Guerini Rocco
2871784d7c Merge pull request #100407 from mweinelt/20.03/pdns-recursor/cve-2020-25829
[20.03] pdns-recursor: 4.2.2 -> 4.2.5
2020-10-13 16:17:36 +02:00
Martin Weinelt
62d986406e pdns-recursor: 4.2.2 -> 4.2.5
Fixes: CVE-2020-25829
2020-10-13 14:25:32 +02:00
Claudio Bley
d3784204ba podman: Add patch for CVE-2020-14370
This backports the changes from upstream[1] to version 1.8.0.

Fixes #99829

[1]: a7e864e6e7.patch
2020-10-13 20:00:30 +10:00
Maximilian Bosch
2d6c3c34fa Merge pull request #100361 from fadenb/graylog_3.3.8_20.03
[20.03] graylog: 3.3.7 -> 3.3.8
2020-10-13 09:18:12 +02:00
Tristan Helmich
5854ffb036 graylog: 3.3.7 -> 3.3.8
Bumps Graylog and integration plugins to version 3.3.8.

(cherry picked from commit 26c66d0f33)
2020-10-12 20:54:02 +00:00
Maximilian Bosch
53c37f9d80 element-desktop: 1.7.8 -> 1.7.9
https://github.com/vector-im/element-desktop/releases/tag/v1.7.9
(cherry picked from commit 7db09ea70a)
2020-10-12 16:57:18 +02:00
Maximilian Bosch
b601cd5e1d element-web: 1.7.8 -> 1.7.9
https://github.com/vector-im/element-web/releases/tag/v1.7.9
(cherry picked from commit 50394cec59)
2020-10-12 16:57:18 +02:00
R. RyanTM
9d27d8357e wolfssl: 4.4.0 -> 4.5.0 2020-10-12 13:55:37 +01:00
Mario Rodas
9ab537f115 Merge pull request #100221 from fadenb/graylog_3.3.7_20.03
[20.03] graylog: 3.3.6 -> 3.3.7
2020-10-11 11:55:27 -05:00
Michael Weiss
ff6fda6160 Merge pull request #100163 from primeos/chromium-backport
[20.03] chromium: 85.0.4183.121 -> 86.0.4240.75
2020-10-11 12:38:59 +02:00
Tristan Helmich
b206b2d737 graylog: 3.3.6 -> 3.3.7
Bumps Graylog and integration plugins to version 3.3.7.

(cherry picked from commit 4115906195)
2020-10-11 10:01:39 +00:00
Vladimír Čunát
2a27a95edd thunderbird*-68: mark as insecure
(cherry picked from commit 230728216a)
2020-10-11 11:17:58 +02:00
Anderson Torres
0fd4e3c877 Merge pull request #100183 from OPNA2608/update/palemoon-28.14.2@20.03
[20.03] palemoon: 28.13.0 -> 28.14.2
2020-10-10 22:04:13 -03:00
OPNA2608
deebf775f8 palemoon: 28.13.0 -> 28.14.2
(cherry picked from commit 559cf217d6)
2020-10-11 01:14:38 +02:00
Gabor Greif
fa304506f3 llvm_11: 11.0.0rc3 -> 11.0.0rc5
(cherry picked from commit a64eabfe7c)
2020-10-10 18:31:18 +02:00
Gabor Greif
1637c07275 llvm_11: 11.0.0rc2 -> 11.0.0rc3
(cherry picked from commit 1c0cbf8aea)
2020-10-10 18:31:18 +02:00
Michael Weiss
208a8f867b chromium: Disable VA-API by default
This is done to avoid driver specific issues and restores the previous
behaviour. Like before video acceleration can be enabled without having
to rebuild Chromium.

(cherry picked from commit 73b67da169)
2020-10-10 18:28:25 +02:00
TredwellGit
b89c2710b5 chromium: Fix and enable our ANGLE support
This will additionally install the following files:
libEGL.so libGLESv2.so
libVkICD_mock_icd.so libvk_swiftshader.so libvulkan.so

libEGL.so and libGLESv2.so are required to fix our ANGLE support.
The rest should help with the Vulkan support (currently an experimental
feature that is disabled by default).

(cherry picked from commit 757bbdd948)
2020-10-10 18:28:19 +02:00
Michael Weiss
4a39f29084 chromium: 85.0.4183.121 -> 86.0.4240.75
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html

This update includes 35 security fixes.

CVEs:
CVE-2020-15967 CVE-2020-15968 CVE-2020-15969 CVE-2020-15970
CVE-2020-15971 CVE-2020-15972 CVE-2020-15990 CVE-2020-15991
CVE-2020-15973 CVE-2020-15974 CVE-2020-15975 CVE-2020-15976
CVE-2020-6557 CVE-2020-15977 CVE-2020-15978 CVE-2020-15979
CVE-2020-15980 CVE-2020-15981 CVE-2020-15982 CVE-2020-15983
CVE-2020-15984 CVE-2020-15985 CVE-2020-15986 CVE-2020-15987
CVE-2020-15992 CVE-2020-15988 CVE-2020-15989

(cherry picked from commit f79703e50c)
2020-10-10 18:28:19 +02:00
WORLDofPEACE
d74573d8ae nixos/display-managers: install sessionData.desktops
Fixes https://github.com/NixOS/nixpkgs/issues/100108

(cherry picked from commit 3cd2b59b8c)
2020-10-09 19:32:28 -04:00
Vladimír Čunát
08d429920b knot-dns: 2.9.6 -> 2.9.7
https://gitlab.nic.cz/knot/knot-dns/-/tags/v2.9.7

(cherry picked from commit a786d00cda)
2020-10-09 12:38:26 +02:00
Mario Rodas
eba1d0126b Merge pull request #99944 from toonn/release-20.03
wire-desktop: backport to release-20.03
2020-10-08 18:17:36 -05:00
Maximilian Bosch
0d474ee1ae nixos/nextcloud: fix nginx config to allow copy/move-operations again
(cherry picked from commit 609c4f497d)
2020-10-08 23:20:17 +02:00
Tim Steinbach
067d8e6c9f linux: 5.4.69 -> 5.4.70 2020-10-07 08:23:30 -04:00
Tim Steinbach
bb7dc854f5 linux: 4.19.149 -> 4.19.150 2020-10-07 08:23:29 -04:00
toonn
095485644d wire-desktop: mac 3.18.3728 -> 3.20.3912
(cherry picked from commit 4448bd4e10)
2020-10-07 12:38:30 +02:00
toonn
0e5d4c28ab wire-desktop: linux 3.18.2925 -> 3.20.2934
(cherry picked from commit ad9d115682)
2020-10-07 12:38:17 +02:00
Andreas Rammhold
776313e8d1 zoneminder: fix CVE-2020-25729
Relates to #99872

(cherry picked from commit fb963742337d0b4b471def8f8fb6d28437e09059)
2020-10-07 01:00:03 +02:00
Vladimír Čunát
06ce0d954b thunderbird*: switch default: 68 -> 78
I didn't feel comfortable with *immediately* removing 68,
even though nixers have rollbacks etc.

(cherry picked from commit 2be22836b1)
It's not nice, but the 68 branch seems unsupported upstream now,
and soon it will surely contain public vulnerabilities.
2020-10-06 18:28:24 +02:00
WORLDofPEACE
041a24254e Merge pull request #99661 from cole-h/fix-nix-shell-and-borg-20.03
[20.03] top-level: ignore unexpected args
2020-10-05 17:14:59 -04:00
Cole Helbling
b2a04c5f28 top-level: ignore unexpected args
This fixes both `nix-shell` failing to eval with `nixUnstable`, as well
as ofborg's failure to eval on aarch64 due to passing an "unexpected
arg" (1112e3a8c8/ofborg/src/nix.rs (L334-L340)).

(cherry picked from commit 11eddd61bc)
2020-10-05 13:24:53 -07:00
Cole Helbling
0872da1080 Revert "top-level: fix nix-shell eval w/nixUnstable"
This reverts commit fa6064ad86.

(cherry picked from commit d91cab87b1)
2020-10-05 13:24:52 -07:00
Justin Humm
0d0660fde3 Merge pull request #99558 from erictapen/20.03-python2-fontforge
[20.03] python.pkgs.fontforge: disable with Python 2
2020-10-04 21:36:32 +02:00
Justin Humm
d6f46d2a91 monoid: 2016-07-21 -> 2018-06-03
Also applied a patch, so we can build with python3Packages.fontforge, as
fontforge doesn't have python2 bindings anymore.
2020-10-04 15:45:52 +02:00
Jan Tojnar
f8d4aa5c1c python.pkgs.fontforge: disable with Python 2
Since the latest update, fontforge no longer supports building with Python 2. Let's prevent failing builds.

(cherry picked from commit ce55b09ad5)
2020-10-04 15:23:51 +02:00
Maximilian Bosch
adc7650bf2 nixos/nextcloud: fix nginx-config for Nextcloud 19 and older
It seems as I misconfigured `nginx` for certain cases such as the
`ldap`-plugin[1] in 42f6244899. This patch
fixes the `nginx`-config to match the upstream recommendations[2].

Also added a comment to the module to remind myself to ensure that
`nginx` will work with both v19 and v20 as soon as the latter is
released and can be packaged in `nixpkgs`.

Co-authored-by: nivadis <nivadis@users.noreply.github.com>

[1] https://github.com/nextcloud/server/issues/16194#issuecomment-688839888
[2] https://docs.nextcloud.com/server/19/admin_manual/installation/nginx.html

(cherry picked from commit 8d8871c565)
2020-10-04 14:37:25 +02:00
Maximilian Bosch
760c6ec78c matrix-synapse: 1.19.3 -> 1.20.1
https://github.com/matrix-org/synapse/releases/tag/v1.20.0
https://github.com/matrix-org/synapse/releases/tag/v1.20.1
(cherry picked from commit 631d92d8dc)
2020-10-03 21:22:14 +02:00
Elis Hirwing
8c9449ef59 php73: 7.3.20 -> 7.3.23
- https://www.php.net/ChangeLog-7.php#7.3.21
 - https://www.php.net/ChangeLog-7.php#7.3.22
 - https://www.php.net/ChangeLog-7.php#7.3.23

(cherry picked from commit e04af50179)
(cherry picked from commit beea5227d0)
2020-10-03 18:15:33 +02:00
Elis Hirwing
960c3fcda2 php74: 7.4.8 -> 7.4.11
https://www.php.net/ChangeLog-7.php#7.4.9
https://www.php.net/ChangeLog-7.php#7.4.10
https://www.php.net/ChangeLog-7.php#7.4.11
(cherry picked from commit a792db658f)
(cherry picked from commit 07c6f1f8ea)
2020-10-03 18:15:05 +02:00
Tim Steinbach
b2d463f0e3 linux: 4.9.237 -> 4.9.238 2020-10-02 11:27:29 -04:00
Tristan Helmich (omniIT)
b7b36a2fbe element-web: 1.7.7 -> 1.7.8
(cherry picked from commit f10049cef3)
2020-10-01 17:41:55 +02:00
Tristan Helmich (omniIT)
151e1aa066 element-desktop: 1.7.7 -> 1.7.8
(cherry picked from commit 0bf368d339)
2020-10-01 17:41:55 +02:00
Tim Steinbach
e6810a0dfb Merge pull request #99266 from NeQuissimus/linux_4_14_200
linux: 4.14.199 -> 4.14.200
(cherry picked from commit 2f177a2f21)
2020-10-01 09:03:37 -04:00
Tim Steinbach
612629526f Merge pull request #99267 from NeQuissimus/linux_4_19_149
linux: 4.19.148 -> 4.19.149
(cherry picked from commit b2a80bebe9)
2020-10-01 09:03:15 -04:00
Tim Steinbach
6c822ca88c Merge pull request #99269 from NeQuissimus/linux_4_4_238
linux: 4.4.237 -> 4.4.238
(cherry picked from commit ea11b55f44)
2020-10-01 09:03:07 -04:00
Tim Steinbach
b8a2127b5b Merge pull request #99270 from NeQuissimus/linux_5_4_69
linux: 5.4.68 -> 5.4.69
(cherry picked from commit de6f754b6e)
2020-10-01 09:02:57 -04:00
Daniël de Kok
b4db68ff56 Merge pull request #98483 from danieldk/freeoffice-979-20.03
[20.03] Update SoftMaker Office/FreeOffice
2020-09-30 16:23:41 +02:00
Maximilian Bosch
414eedcf4e Merge pull request #99081 from fadenb/graylog_3.3.6_20.03
[20.03] graylog: 3.3.4 -> 3.3.6
2020-09-30 13:38:37 +02:00
Maximilian Bosch
629fe7b145 Merge pull request #99048 from asbachb/update/roundcube-20.03
[20.03] roundcube: 1.4.8 -> 1.4.9
2020-09-29 11:24:47 +02:00
Tristan Helmich (omniIT)
5accfcfa77 graylog: 3.3.4 -> 3.3.6
Bumps Graylog and integration plugins to version 3.3.6.
Fixes wrong description of aggregates plugin.

(cherry picked from commit dee78b7032)
2020-09-29 09:09:42 +00:00
Maximilian Bosch
6b80a3d38d roundcube: 1.4.8 -> 1.4.9
https://github.com/roundcube/roundcubemail/releases/tag/1.4.9
(cherry picked from commit f09ae7e371)
(cherry picked from commit f8bd03c7fd)
2020-09-29 01:21:25 +02:00
Tim Steinbach
f646148ba7 linux: 5.4.67 -> 5.4.68 2020-09-28 19:10:13 -04:00
Tim Steinbach
c9fb1778ff linux: 4.19.147 -> 4.19.148 2020-09-28 19:10:13 -04:00
Andreas Rammhold
ad246fb874 nixos/security/wrapper: ensure the tmpfs is not world writeable
The /run/wrapper directory is a tmpfs. Unfortunately, it's mounted with
its root directory has the standard (for tmpfs) mode: 1777 (world writeable,
sticky -- the standard mode of shared temporary directories). This means that
every user can create new files and subdirectories there, but can't
move/delete/rename files that belong to other users.
2020-09-28 22:54:41 +02:00
Maximilian Bosch
a6f277f9ff Merge pull request #98332 from Ma27/nextcloud-20.03
[20.03]  nextcloud: 17.0.6 -> 17.0.9, 18.0.7 -> 18.0.9, 19.0.1 -> 19.0.3
2020-09-27 19:53:10 +02:00
Vladimír Čunát
16f0e6b95a Merge branch 'staging-20.03' into release-20.03
Only a few thousand aarch64 builds are missing on Hydra ATM.
2020-09-27 17:22:02 +02:00
Michael Weiss
d110708115 Merge pull request #98856 from primeos/chromium-backport
[20.03] Backport LLVM 11 to build Chromium M86
2020-09-27 11:34:05 +02:00
Vladimír Čunát
360e2af4f8 Merge #98628: thunderbird*: 78.2.2 -> 78.3.1 (security)
(cherry picked from commit 4212f719bb)
Briefly re-tested atop 20.03.
2020-09-26 15:35:33 +02:00
Michael Weiss
c8561e5c0a Merge pull request #98844 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.36.2 -> 1.36.3
2020-09-26 14:13:50 +02:00
Michael Weiss
fdb4b8f9ac chromiumBeta: Fix the build by using LLVM 11
We'll need a working build of Chromium M86 for NixOS 20.03 to provide
security updates for 30 days after the release of 20.09.
2020-09-26 14:10:09 +02:00
Michael Weiss
f6a84a223a chromiumDev: Fix "patchShebangs ."
Note: The following might also need to be updated:
substituteStream(): WARNING: pattern '/usr/share/xcb' doesn't match anything in file 'ui/gfx/x/BUILD.gn'

(cherry picked from commit 8815c9e186)
2020-09-26 12:57:56 +02:00
Michael Weiss
ef889f43d9 chromiumDev: Drop the optional VA-API patches
I didn't look into this yet but IIRC M86 will finally have a flag for
Linux to enable VA-API. So we shouldn't need
enable-video-acceleration-on-linux.patch anymore.

But we likely need to update enable-vdpau-support-for-nvidia.patch
when/before M86 hits the stable channel if we want to keep VDPAU
support.

(cherry picked from commit bf0e13a322)
2020-09-26 12:57:41 +02:00
Michael Weiss
bed75af2bb chromiumDev: Drop nix_plugin_paths_68.patch
Ok, so I was about to update the patch (didn't apply anymore) when I
also started looking at it's usage and realized that
NIX_CHROMIUM_PLUGIN_PATH_ (and other substrings) only appears in the
patch itself (i.e. it seemed like we don't need this patch anymore).

Turns out that we have this patch since 2014 (1b84fbf0ca) and it was
only ever used for NIX_CHROMIUM_PLUGIN_PATH_WIDEVINE (and from the log
it isn't clear if/when or how well that worked). But in 2019 that last
usage got removed (545d58a1ef) so we should be able to safely drop this
patch now :) \o/

(I just wanted to note that as it seemed somewhat of a funny story :D
But there is of course nothing wrong with it.)
Git history (git log --oneline -S NIX_CHROMIUM_PLUGIN_PATH_):
7205bd64a3 ungoogled-chromium: init at 81.0.4044.92-2
545d58a1ef chromium: fix widevine
cd3283f921 chromium: 67.0.3396.99 -> 68.0.3440.75
72d7b5ddb1 chromium: fix nix_plugin_paths for 68+
7a3a16dd80 chromium: Remove plugin paths patch for version 50
79d18eb604 chromium: Update dev channel to v52.0.2743.10
c7a3645e7b chromium: Remove stuff for versions <= v51
8b97ca270e chromium: Update all channels to latest versions
b9093f1c64 chromium: Updates, fixes #11492
471cdd15e2 chromium: Update beta and dev channels.
5c6aa391fc chromium: Cleanup old patch and update stable
af54ddf8b6 chromium: Drop plugin_paths patch for old versions.
6a8afa4bb3 chromium: Fix plugin_paths patch for version 44.
0aad4b7ee4 chromium: Update all channels to latest versions.
1b84fbf0ca chromium: Allow env vars for passing plugin paths.

(cherry picked from commit 2213c464f6)
2020-09-26 12:57:12 +02:00
Gabor Greif
3768fdea92 llvm_11: 11.0.0rc1 -> 11.0.0rc2
http://lists.llvm.org/pipermail/release-testers/2020-August/001321.html
(cherry picked from commit df267a4cca)
2020-09-26 12:53:10 +02:00
Gabor Greif
dac4a48b45 llvm_11: init at 11.0.0rc1
http://lists.llvm.org/pipermail/release-testers/2020-July/001305.html

TODO: Enable Polly.

Co-authored-by: conferno <conferno@camfex.cz>
(cherry picked from commit 0a8334d5a0)
2020-09-26 12:53:01 +02:00
Michael Weiss
5662a6faae llvm_11: Copy all files from llvmPackages_10
This is simply the result of:
cp -r pkgs/development/compilers/llvm/10 pkgs/development/compilers/llvm/11/

(cherry picked from commit 28f2797a81)
2020-09-26 12:50:48 +02:00
Michael Weiss
bef364c849 signal-desktop: 1.36.2 -> 1.36.3
(cherry picked from commit 2e6844040e)
2020-09-26 12:48:05 +02:00
Vladimír Čunát
9f5ba92b94 Merge #98684: brotli: fix patch URL
(cherry picked from commit 779ad182cf)
2020-09-26 09:53:53 +02:00
Vladimír Čunát
93c68eaf4f firefox-esr-68: mark as insecure
This is a weaker version of commit 264693f9d7 from master.
2020-09-26 09:29:02 +02:00
Stig P
a0075f2333 Merge pull request #98219 from stigtsp/package/perl-DBI-1.643-backport-20.03
[20.03] perlPackages.DBI: 1.642 -> 1.643 (for CVE-2020-14392, CVE-2020-14393)
2020-09-25 17:45:33 +00:00
Andreas Rammhold
7b75c796f4 Merge pull request #98680 from yoctocell/backport-tbb-10.0
[20.03] tor-browser-bundle-bin: 9.5.4 -> 10.0
2020-09-25 17:46:58 +02:00
Andreas Rammhold
fe9a045ae3 Merge pull request #96843 from primeos/backports
[20.03] Backport telegram-desktop to fix CVE-2020-17448
2020-09-25 17:45:58 +02:00
Andreas Rammhold
75872280c3 Merge pull request #98650 from taku0/firefox-bin-81.0_20.03
[20.03] firefox: 80.0 -> 81.0, firefox-bin: 79.0 -> 81.0, firefox-esr: 78.2.0esr -> 78.3.0esr
2020-09-25 17:40:14 +02:00
taku0
fd6a66f882 firefox: 80.0.1 -> 81.0
(cherry picked from commit 0669cd9d3f)
2020-09-25 16:58:03 +02:00
Stig Palmquist
147b303509 firefox: 80.0 -> 80.0.1
(cherry picked from commit bbdb19269a)
2020-09-25 16:58:02 +02:00
Andreas Rammhold
a33f7dc091 nss_latest: 3.55 -> 3.56 2020-09-25 16:58:02 +02:00
Michael Weiss
623fe4b26b Merge pull request #98740 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.36.1 -> 1.36.2
2020-09-25 16:15:18 +02:00
Michael Weiss
a4915764ec signal-desktop: 1.36.1 -> 1.36.2
(cherry picked from commit 6b0794caa5)
2020-09-25 13:49:02 +02:00
Michael Weiss
1dd693976f Merge pull request #98557 from primeos/chromium-backport
[20.03] chromium: 85.0.4183.83 -> 85.0.4183.121
2020-09-25 13:29:18 +02:00
yoctocell
c483a72642 tor-browser-bundle-bin: 9.5.4 -> 10.0
(cherry picked from commit 281f44fb76)
2020-09-24 22:08:16 +02:00
taku0
9515a3751f firefox-bin: 80.0.1 -> 81.0
(cherry picked from commit 3ad81fd022)
2020-09-24 22:19:55 +09:00
Stig Palmquist
9703bb2340 firefox-bin: 80.0 -> 80.0.1
(cherry picked from commit 197799c263)
2020-09-24 22:19:54 +09:00
Atemu
3bbe4c8e4f firefox-bin: 79.0 -> 80.0 (#96279)
(cherry picked from commit b12ca077c0)
2020-09-24 22:19:54 +09:00
taku0
75c850d4f3 firefox-esr: 78.2.0esr -> 78.3.0esr
(cherry picked from commit 2460e0e6cd)
2020-09-24 22:19:54 +09:00
Rok Garbas
5659cb448e Merge pull request #98647 from raboof/rename-guide-to-nixpkgs-manual-20.03
doc: rename guide to 'Nixpkgs Manual'
2020-09-24 15:07:48 +02:00
Arnout Engelen
754d7bbfd7 doc: rename guide to 'Nixpkgs Manual'
For consistency with 'NixOS Manual' and 'Nix Manual', to better match what it's
often called in practice, and to match its URL and HTML title.
2020-09-24 15:05:23 +02:00
Tim Steinbach
0bc6da3ab0 linux: 5.4.66 -> 5.4.67 2020-09-23 09:04:28 -04:00
Tim Steinbach
9ae9a70c15 linux: 4.9.236 -> 4.9.237 2020-09-23 09:04:28 -04:00
Tim Steinbach
f1773ffb3c linux: 4.4.236 -> 4.4.237 2020-09-23 09:04:28 -04:00
Tim Steinbach
70c8913197 linux: 4.19.146 -> 4.19.147 2020-09-23 09:04:28 -04:00
Tim Steinbach
ce758e6daa linux: 4.14.198 -> 4.14.199 2020-09-23 09:04:28 -04:00
Michael Weiss
39d5f7e0f1 chromium: 85.0.4183.102 -> 85.0.4183.121
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html

This update includes 10 security fixes.

CVEs:
CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963
CVE-2020-15965 CVE-2020-15966 CVE-2020-15964

(cherry picked from commit d1a27a5f00)
2020-09-23 12:23:41 +02:00
Michael Weiss
40b58a1fca chromiumDev: M86 -> M87
(cherry picked from commit e249baca22)
2020-09-23 12:23:32 +02:00
Michael Weiss
f535718ae6 chromium: update.py: Keep the channel order consistent
This makes Git diffs way easier to read.
Using sort_keys=True is usually better but with this implementation the
output is a bit nicer to read IMO.

(cherry picked from commit ceb3acfa8b)
2020-09-23 12:22:32 +02:00
Michael Weiss
8504341eda chromium: 85.0.4183.83 -> 85.0.4183.102
https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html

This update includes 5 security fixes.

CVEs:
CVE-2020-6573 CVE-2020-6574 CVE-2020-6575 CVE-2020-6576 CVE-2020-15959

(cherry picked from commit a9c78519d6)
2020-09-23 12:21:23 +02:00
Michael Weiss
0cd31b9ec2 chromium: Prefix $PATH with xdg_utils (#96922)
This is required for certain URIs that require launching external
programs (e.g. mailto:, magnet:, or irc:) or setting the default browser
via xdg-settings.
Fix #96897 and fix #92751.

(cherry picked from commit 1fa610bdf0)
2020-09-23 12:21:04 +02:00
Tethys Svensson
79b88efc58 chromium: Unblock nixos-unstable by using the correct argument to fetchurl
(cherry picked from commit 2927a19be3)
2020-09-23 12:20:18 +02:00
Florian Klink
bc8cb021fb chromiumBeta: 85.0.4183.83 -> 86.0.4240.22
(cherry picked from commit 6c92847e81)
2020-09-23 12:19:58 +02:00
Alyssa Ross
00740317ec chromium: replace update.nix with Python impl
update.nix was a huuuuge hack, abusing checksum collisions, etc., and
was extremely difficult to read and maintain, especially because
values from update.nix were also used in the derivations themselves!

I've replaced this with an implementation in Python, which I chose for
readability.  Rather than generating Nix, I chose to
generate JSON, since Python can do that in the standard library and
Nix can read it.

I also set update.py as an updateScript, so Chromium can now
automatically be updated!

Fixes: https://github.com/NixOS/nixpkgs/issues/89635
(cherry picked from commit de69b705d2)
2020-09-23 12:19:20 +02:00
Alyssa Ross
710d968247 chromiumDev: 86.0.4238.0 -> 86.0.4240.8
(cherry picked from commit 5811b6c1cd)
2020-09-23 12:15:37 +02:00
Vladimír Čunát
445b4026d6 Merge branch 'release-20.03' into staging-20.03 2020-09-23 10:38:58 +02:00
Vladimír Čunát
ad76375bfc gnutls: 3.6.14 -> 3.6.15
Security: on-wire alert could cause NULL pointer dereference.
https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html
(cherry picked from commit 2363e6eb9c)
2020-09-23 10:38:40 +02:00
Daniël de Kok
f8271cb336 softmaker-office: 976 -> 978 2020-09-22 19:50:04 +02:00
Daniël de Kok
4b55b4853a freeoffice: 976 -> 978
Fixes #98385.

(cherry picked from commit ac49c2f72a)
2020-09-22 19:46:21 +02:00
Daniël de Kok
de0137d27a softmaker-office: remove /bin/ls intercept
This does not seem to be necessary anymore and fixes segmentation
faults on 20.03.

(cherry picked from commit e883c6578c)
2020-09-22 19:45:00 +02:00
Lancelot SIX
6ec10fc77e pythonPackages.django: 2.2.15 -> 2.2.16
See https://docs.djangoproject.com/en/dev/releases/2.2.16/

(cherry picked from commit bd4805b659)
2020-09-22 17:15:42 +01:00
Frederik Rietdijk
68efe6dbf9 python3Packages.Django: 2.2.14 -> 2.2.15
(cherry picked from commit 6eaaf2e5a0)
2020-09-22 17:15:14 +01:00
R. RyanTM
683736a0f2 coturn: 4.5.1.2 -> 4.5.1.3
(cherry picked from commit 5c67b5ef94)

Fixes CVE-2020-4067.
2020-09-22 12:01:48 +02:00
Vladimír Čunát
13a15f262a Merge #97969: thunderbird*-78: 78.2.1 -> 78.2.2 2020-09-22 01:45:32 +02:00
Vladimír Čunát
abf627cc15 thunderbird-78: fix #97994: broken UI in 78.2.2
(cherry picked from commit 114202e369)
2020-09-21 21:44:12 +02:00
zowoq
21d8e70a69 fzf: 0.21.1 -> 0.22.0
https://github.com/junegunn/fzf/blob/master/CHANGELOG.md#0220
(cherry picked from commit 6a8ca288e7)
2020-09-21 08:10:19 +10:00
zowoq
a0b222ccf3 fzf: 0.21.0-1 -> 0.21.1
https://github.com/junegunn/fzf/blob/master/CHANGELOG.md#0211
(cherry picked from commit cc21aa99a4)
2020-09-21 08:10:19 +10:00
zowoq
f3e31990a9 fzf: 0.21.0 -> 0.21.0-1
(cherry picked from commit 179aa6ec04)
2020-09-21 08:10:19 +10:00
zowoq
5289f227c2 fzf: 0.20.0 -> 0.21.0
https://github.com/junegunn/fzf/blob/master/CHANGELOG.md#0210
(cherry picked from commit da13cdb56c)
2020-09-21 08:10:19 +10:00
Maximilian Bosch
6b11dbe967 matrix-synapse: 1.19.2 -> 1.19.3
https://github.com/matrix-org/synapse/releases/tag/v1.19.3
(cherry picked from commit 44c558b219)
2020-09-20 20:04:51 +02:00
Martin Puppe
6f12279ae3 nextcloud19: 19.0.1 -> 19.0.3 2020-09-20 18:23:09 +02:00
Martin Puppe
488bb6ad2a nextcloud18: 18.0.7 -> 18.0.9 2020-09-20 18:23:09 +02:00
Martin Puppe
28651044ad nextcloud17: 17.0.6 -> 17.0.9 2020-09-20 18:23:08 +02:00
Luflosi
773ef5ae78 youtube-dl: 2020.09.14 -> 2020.09.20
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.09.20
(cherry picked from commit 907fd8d6f6)
cc #98319
2020-09-20 10:51:36 -04:00
volth
2b803260a6 [cpan2nix] perlPackages.DBI: 1.642 -> 1.643 (for CVE-2020-14392, CVE-2020-14393)
(cherry picked from commit 12ebbef0ea)
2020-09-18 17:52:33 +02:00
Dmitry Kalinkin
985047d3c9 texlive: fix arara
(cherry picked from commit 37d65c8698)
cc #97609
2020-09-17 22:04:51 -04:00
Tim Steinbach
faf5bdea5d linux: 5.4.65 -> 5.4.66 2020-09-17 09:59:00 -04:00
Tim Steinbach
eb92e8876d linux: 4.19.145 -> 4.19.146 2020-09-17 09:59:00 -04:00
ajs124
5177665caf Merge pull request #98114 from tokudan/2003-matrix
matrix-synapse: 1.19.1 -> 1.19.2 [20.03]
2020-09-16 23:07:48 +02:00
ajs124
732163c10f matrix-synapse: 1.19.1 -> 1.19.2
(cherry picked from commit 21779aece5)
2020-09-16 19:23:01 +02:00
Anderson Torres
e82b1de75a Merge pull request #97767 from superherointj/release-20.03
[20.03] nixos/dmidecode: added recommended patches
2020-09-15 23:16:14 -03:00
Robert Scott
3709ab3b48 Merge pull request #97980 from risicle/ris-pyscard-darwin-199-fix-20.03
[20.03] pythonPackages.pyscard: Fix build on Darwin
2020-09-14 22:46:14 +01:00
Maximilian Bosch
8a6e7487fb element-desktop: 1.7.5 -> 1.7.7
https://github.com/vector-im/element-desktop/releases/tag/v1.7.6
https://github.com/vector-im/element-desktop/releases/tag/v1.7.7
(cherry picked from commit 441818c4ff)
2020-09-14 19:15:13 +02:00
Maximilian Bosch
d2409578c5 element-web: 1.7.5 -> 1.7.7
https://github.com/vector-im/element-web/releases/tag/v1.7.6
https://github.com/vector-im/element-web/releases/tag/v1.7.7
(cherry picked from commit 33d02b3396)
2020-09-14 19:15:13 +02:00
Kevin Griffin
13d38bfb26 pythonPackages.pyscard: Fix build on Darwin
The previously provided patch is still necessary,
as nix python reports an old version of macOS
that has the bug, when in fact modern macOS
does not have the misspelling.

The patch has been upstreamed, so we take it
to fix 1.9.9 in anticipation of the next release.

(cherry picked from commit 44fd570d73)
2020-09-14 16:03:20 +01:00
Tim Steinbach
a9f0ffa06f linux: 5.4.64 -> 5.4.65 2020-09-14 08:42:52 -04:00
Tim Steinbach
7097e94511 linux: 4.9.235 -> 4.9.236 2020-09-14 08:42:52 -04:00
Tim Steinbach
96d3c3f316 linux: 4.4.235 -> 4.4.236 2020-09-14 08:42:52 -04:00
Tim Steinbach
947d26d343 linux: 4.19.144 -> 4.19.145 2020-09-14 08:42:52 -04:00
Tim Steinbach
db8285166a linux: 4.14.197 -> 4.14.198 2020-09-14 08:42:52 -04:00
taku0
c33f2caedf thunderbird-bin: 78.2.1 -> 78.2.2
(cherry picked from commit eff618541e)
2020-09-14 19:25:15 +09:00
taku0
fb8e820bf8 thunderbird: 78.2.1 -> 78.2.2
(cherry picked from commit 5bcc37d79e)
2020-09-14 19:25:15 +09:00
Vladimír Čunát
ec0bf90519 Merge branch 'staging-20.03' into release-20.03
The main platform has been rebuilt; let's not block the security fixes.
2020-09-14 11:25:24 +02:00
Maximilian Bosch
732684b720 top-level: fix nix-shell eval w/nixUnstable
For a full description of the underlying issue please read
https://github.com/NixOS/nix/issues/4003

(cherry picked from commit fa6064ad86)
2020-09-14 09:11:36 +02:00
Luflosi
10ecc023a9 youtube-dl: 2020.09.06 -> 2020.09.14
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.09.14
(cherry picked from commit 4a11f046a6)
2020-09-14 09:00:52 +02:00
Anderson Torres
5cc3e2bde1 Merge pull request #97931 from OPNA2608/backport-20.03-update-palemoon-28.13.0
[20.03] palemoon: 28.12.0 -> 28.13.0
2020-09-14 01:10:56 -03:00
Christoph Neidahl
9103fba5a0 palemoon: 28.12.0 -> 28.13.0
(cherry picked from commit 5efe403c93)
2020-09-13 22:59:01 +02:00
Michael Weiss
252bfe0107 Merge pull request #97777 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.35.1 -> 1.36.1
2020-09-12 11:41:49 +02:00
Félix Baylac-Jacqué
0da86f0a51 Merge pull request #97754 from andir/20.03/prosody-0-11-6
[20.03] prosody: 0.11.5 -> 0.11.6
2020-09-11 22:00:26 +02:00
Maxine E. Aubrey
4ea5363034 traefik: 1.17.21 -> 1.17.26
Fixes CVE-202-15129 (#96836)
2020-09-11 17:34:42 +02:00
superherointj
fac425ccec nixos/dmidecode: added recommended patches
Co-authored-by: Jörg Thalheim <Mic92@users.noreply.github.com>
(cherry picked from commit d284d3203a)
2020-09-11 08:58:24 -03:00
Félix Baylac-Jacqué
4a4c92212d prosody: 0.11.5 -> 0.11.6
See https://blog.prosody.im/prosody-0.11.6-released/ for the release
notes.

(cherry picked from commit b47cabb6ac)
2020-09-11 12:10:48 +02:00
Michael Weiss
849ef3ba9b signal-desktop: 1.35.1 -> 1.36.1
(cherry picked from commit f192636304)
2020-09-11 11:31:13 +02:00
Mario Rodas
0da54872f9 Merge pull request #97557 from risicle/ris-terraform-0.12-go-1.14-mojave-r20.03
[20.03] terraform_0_12: add patch with fix for macos mojave when built with go 1.14
2020-09-10 22:46:12 -05:00
Tethys Svensson
c291195eed discord-canary: 0.0.111 -> 0.0.112
(cherry picked from commit 1937fd3f19)
2020-09-10 14:26:28 -07:00
Tethys Svensson
67985ae151 discord-ptb: 0.0.21 -> 0.0.22
(cherry picked from commit 3ca40eebf9)
2020-09-10 14:26:28 -07:00
Tethys Svensson
53b01bdfe9 discord: 0.0.11 -> 0.0.12
(cherry picked from commit 977147bd04)
2020-09-10 14:26:28 -07:00
Dominique Martinet
e6bc03bea0 systemd-confinement: handle ExecStarts etc being lists
systemd-confinement's automatic package extraction does not work correctly
if ExecStarts ExecReload etc are lists.

Add an extra flatten to make things smooth.

Fixes #96840.

(cherry picked from commit fd196452f0)
2020-09-10 21:19:27 +02:00
Tim Steinbach
2756149464 jenkins: 2.235.5 -> 2.249.1 2020-09-10 10:38:37 -04:00
Tim Steinbach
73c6b9a88d jenkins: 2.235.3 -> 2.235.5
(cherry picked from commit bae91fb6c9)
2020-09-10 10:38:31 -04:00
Tim Steinbach
6a0009824e linux: 5.4.63 -> 5.4.64 2020-09-10 10:37:36 -04:00
Tim Steinbach
dd1ddd1d69 linux: 4.19.143 -> 4.19.144 2020-09-10 10:37:36 -04:00
Tim Steinbach
ac43451abe linux: 4.14.196 -> 4.14.197 2020-09-10 10:37:36 -04:00
zowoq
95ab853387 Merge pull request #97566 from maxeaubrey/20.03_go_cves
[20.03] go: 1.13.12 -> 1.13.15, 1.14.4 -> 1.14.8
2020-09-10 19:03:03 +10:00
zowoq
d3f3208a6e go_1_14: 1.14.7 -> 1.14.8
(cherry picked from commit eef56567c4)
2020-09-10 10:45:33 +02:00
zowoq
0b8db6f717 go: 1.14.6 -> 1.14.7
(cherry picked from commit 792f562ad5)
2020-09-10 10:45:23 +02:00
zowoq
fa7a3c1ca8 go_1_13: 1.13.14 -> 1.13.15
(cherry picked from commit 1a83aa1190)
2020-09-10 10:45:17 +02:00
zowoq
b2cb46557b go_1_13: 1.13.13 -> 1.13.14
(cherry picked from commit 9cbf74bb7b)
2020-09-10 10:45:09 +02:00
zowoq
3b601bb991 go_1_13: 1.13.12 -> 1.13.13
(cherry picked from commit ea3d6dddd8)
2020-09-10 10:45:00 +02:00
zowoq
7817ddd0d7 go: 1.14.5 -> 1.14.6
(cherry picked from commit 4c99c5543c)
2020-09-10 10:44:47 +02:00
zowoq
72614e199a go: 1.14.4 -> 1.14.5
(cherry picked from commit af1b0c92ad)
2020-09-10 10:44:38 +02:00
Hannes Weisbach
57a83122d9 tbb: fix library install name on macOS
by adding fixDarwinDylibNames to nativeBuildInputs

(cherry picked from commit 1488e7d1c4)
cc #97238
2020-09-09 12:42:09 -04:00
Robert Scott
6e9eedf268 terraform_0_12: add patch with fix for macos mojave when built with go 1.14
otherwise we get a crash on startup
2020-09-09 16:57:24 +01:00
WORLDofPEACE
8658d6c4f2 Merge pull request #97538 from taku0/flashplayer-32.0.0.433_20.03
[20.03] flashplayer: 32.0.0.330 -> 32.0.0.433
2020-09-09 10:22:48 -04:00
WORLDofPEACE
04ea21924f Merge pull request #97506 from arapov/release-20.03
[20.03] nodePackages.node-red: fix build
2020-09-09 10:10:19 -04:00
taku0
167d2db830 flashplayer: 32.0.0.414 -> 32.0.0.433
(cherry picked from commit 807e4ae439)

without ungoogled_chromium
2020-09-09 21:58:17 +09:00
Anton Arapov
43a6e63b31 nodePackages.node-red: fix build
resolves issue #89205

Signed-off-by: Anton Arapov <arapov@gmail.com>
(cherry picked from commit e5701710e3)
2020-09-09 07:53:13 +02:00
WORLDofPEACE
e75598b70e Merge pull request #97442 from OPNA2608/backport-20.03-palemoon-wrapping-libpulseaudio
[20.03] palemoon: Add libpulseaudio to wrapper
2020-09-08 19:38:58 -04:00
WORLDofPEACE
243666de11 Merge pull request #95102 from risicle/ris-openexr-2.4.1-r20.03
[20.03] openexr,imlbase: 2.3.0 -> 2.4.2 to fix numerous security issues
2020-09-08 19:36:22 -04:00
WORLDofPEACE
299e25ae0f Merge pull request #95688 from marius851000/backport_tor_browser_fix
[20.03] tor-browser: disable hardening by default (#93154)
2020-09-08 19:35:22 -04:00
WORLDofPEACE
50c60af938 Merge pull request #95964 from danieldk/rescuetime-backport
[20.03] rescuetime: 2.16.2.1 -> 2.16.3.1
2020-09-08 19:34:35 -04:00
WORLDofPEACE
2d0df46770 Merge pull request #95990 from risicle/ris-nghttp2-CVE-2020-11080-r20.03
[20.03] nghttp2: add patch for CVE-2020-11080
2020-09-08 19:34:05 -04:00
WORLDofPEACE
a675ceaaf1 Merge pull request #91553 from regnat/fix-termdown-20.03
Fix termdown for 20.03
2020-09-08 19:30:28 -04:00
WORLDofPEACE
54a8612b60 Merge pull request #97049 from Ma27/hydra-backports
[20.03] nixUnstable: pre20200721_ff314f1 -> pre20200829_f156513, hydra-unstable: 2020-08-04 -> 2020-09-02
2020-09-08 19:28:20 -04:00
WORLDofPEACE
fb3ac1abd8 Merge pull request #97357 from ckauhaus/91310-adns-cve-20.03
[20.03] adns: 1.5.1 -> 1.5.2
2020-09-08 19:26:43 -04:00
WORLDofPEACE
3ce91af2de Merge pull request #97318 from worldofpeace/pantheon-backport-sep-2020
[20.03] Pantheon updates sep 2020
2020-09-08 19:25:49 -04:00
Maximilian Bosch
26a05bf3da linuxPackages.wireguard: 1.0.20200729 -> 1.0.20200908
https://lists.zx2c4.com/pipermail/wireguard/2020-September/005817.html
(cherry picked from commit c73ef96b7e)
2020-09-08 22:38:31 +02:00
Maximilian Bosch
5dd6ab5959 Merge pull request #97441 from jtojnar/drop-fc-210-conf
nixos/fontconfig: Fix compatibility with unstable apps
2020-09-08 20:37:56 +02:00
Christoph Neidahl
d397c6ac16 palemoon: Add libpulseaudio to wrapper
(cherry picked from commit 5ee5bbef84)
2020-09-08 16:05:12 +02:00
Tim Steinbach
835392d69d linux: 5.4.62 -> 5.4.63 2020-09-08 08:54:09 -04:00
Jan Tojnar
eb6ac6ab68 nixos/fontconfig: Fix compatibility with unstable apps
Fontconfig 2.14 from unstable reverted back to using /etc/fonts/fonts.conf
for its configuration. Unfortunately, on NixOS 20.03, this still points
to configuration for Fontconfig 2.10, with cache version 3.

When an app linked against Fontconfig 2.14 reads the config and does not
find a compatible cache, it writes a new cache entries to ~/.cache/fontconfig.
Unfortunately, the fontconfig 2.14 uses the same cache version as 2.12 in 20.03 (7)
so when the apps from 20.03 later read the cache, they cannot make much sense
of it and are unable to find any fonts.

I added a new fonts.fontconfig.disableVersionedFontConfiguration option, which,
when enabled, makes /etc/fonts/fonts.conf point to the configuration file
for the latest fontconfig, instead of the ancient 2.10 version.
This is necessary to prevent packages from Nixpkgs unstable breaking apps
from 20.03.

Enabling this should not cause any issues as there are no programs
using the legacy fontconfig version since NixOS 15.03.

Unfortunately, if a person already ran an app from unstable
before applying this patch, they will need to delete ~/.cache/fontconfig manually.
2020-09-08 13:24:33 +02:00
Christian Kauhaus
aa8ccad1b1 adns: 1.5.1 -> 1.5.2
Security update which fixes various CVEs:

CVE-2017-9103
CVE-2017-9104
CVE-2017-9109
CVE-2017-9105
CVE-2017-9106
CVE-2017-9107
CVE-2017-9108

Closes #91310

(cherry picked from commit b3bcf1022cadaec983164155f8e85424487b2d9b)
2020-09-07 15:09:41 +02:00
Martin Weinelt
4bd1938e03 Merge pull request #97333 from makefu/pkgs/hovercraft/backport-update
backport hovercraft fix
2020-09-07 13:06:55 +02:00
makefu
f59f61817c hovercraft: remove broken meta tag 2020-09-07 08:56:02 +02:00
Konrad Borowski
95bf5a41c5 hovercraft: 2.6 -> 2.7
(cherry picked from commit 46d3cf2c1b)
2020-09-07 08:53:41 +02:00
worldofpeace
4bada3ac11 pantheon.appcenter: 3.4.0 -> 3.4.2 2020-09-06 21:44:03 -04:00
worldofpeace
3cb2ca50e9 pantheon.elementary-dock: fix double includedir in .pc
(cherry picked from commit ac05da41bd)
2020-09-06 21:37:56 -04:00
worldofpeace
e4cb606d38 pantheon: remove plank
We don't use this anymore. Oops.

(cherry picked from commit 8845cb868c)
2020-09-06 21:37:56 -04:00
worldofpeace
7778e992e1 appstream: 0.12.6 -> 0.12.11
(cherry picked from commit 1a5f54c404)
2020-09-06 21:37:56 -04:00
worldofpeace
e7f41c0abe pantheon.wingpanel-indicator-sound: 2.1.5 -> 2.1.6
https://github.com/elementary/wingpanel-indicator-sound/releases/tag/2.1.6
(cherry picked from commit afb065f374)
2020-09-06 21:37:55 -04:00
worldofpeace
e6dcb33e96 pantheon.wingpanel-indicator-power: 2.1.5 -> 2.2.0
https://github.com/elementary/wingpanel-indicator-power/releases/tag/2.2.0
(cherry picked from commit 80108e7aa4)
2020-09-06 21:37:55 -04:00
worldofpeace
ec418c6f71 pantheon.wingpanel-indicator-nightlight: 2.0.3 -> 2.0.4
https://github.com/elementary/wingpanel-indicator-nightlight/releases/tag/2.0.4
(cherry picked from commit 05ad41decb)
2020-09-06 21:37:55 -04:00
worldofpeace
8034d716f4 pantheon.switchboard-plug-sound: 2.2.4 -> 2.2.5
https://github.com/elementary/switchboard-plug-sound/releases/tag/2.2.5
(cherry picked from commit 87f3b4082d)
2020-09-06 21:37:55 -04:00
worldofpeace
d5c0c7351b pantheon.switchboard-plug-network: 2.3.1 -> 2.3.2
https://github.com/elementary/switchboard-plug-keyboard/releases/tag/2.4.1
(cherry picked from commit 72d29c975d)
2020-09-06 21:37:54 -04:00
worldofpeace
65e39afb92 pantheon.switchboard-plug-keyboard: 2.3.6 -> 2.4.1
https://github.com/elementary/switchboard-plug-keyboard/releases/tag/2.4.1
(cherry picked from commit b592c888ad)
2020-09-06 21:37:54 -04:00
worldofpeace
b2b4ac3fdc pantheon.elementary-files: 4.4.4 -> 4.5.0
https://github.com/elementary/files/releases/tag/4.5.0
(cherry picked from commit 4b64a23f26)
2020-09-06 21:37:54 -04:00
worldofpeace
e3ac5913d3 pantheon.elementary-calendar: 5.0.6 -> 5.1.6
https://github.com/elementary/calendar/releases/tag/5.1.0
(cherry picked from commit 7dea5d2735)
2020-09-06 21:37:53 -04:00
worldofpeace
2cf7cad291 pantheon: update hashes
(cherry picked from commit 7961afc58a)
2020-09-06 21:37:48 -04:00
worldofpeace
42674051d1 pantheon.gala: fix build with latest vala
(cherry picked from commit 6df7a93ce7)
2020-09-06 21:21:08 -04:00
worldofpeace
e62f338732 pantheon.wingpanel-indicator-session: fix build with latest vala
(cherry picked from commit 1e084a85d2)
2020-09-06 21:21:00 -04:00
Jörg Thalheim
43a27ce45d radare2: 4.5.0 -> 4.5.1
(cherry picked from commit 4bdcea4634)
2020-09-06 20:37:10 +02:00
zowoq
b0976a302c youtube-dl: 2020.07.28 -> 2020.09.06
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.09.06
(cherry picked from commit e2d02e469a)
2020-09-06 11:45:05 +02:00
worldofpeace
c2c55c94c1 Merge branch 'staging-20.03' into release-20.03 2020-09-05 17:08:42 -04:00
worldofpeace
c0c2bbeabe Merge remote-tracking branch 'upstream/release-20.03' into staging-20.03 2020-09-05 17:08:09 -04:00
Maximilian Bosch
ba0c64775b mautrix-whatsapp: 0.1.3 -> 0.1.4
https://github.com/tulir/mautrix-whatsapp/releases/tag/v0.1.4
(cherry picked from commit 86a1a0a68d)
2020-09-05 16:35:55 +02:00
Robert Scott
9fd2ed5e62 Merge pull request #96196 from risicle/ris-ghostscript-CVE-2020-15900-r20.03
[20.03] ghostscript: add patch for CVE-2020-15900
2020-09-05 12:36:55 +01:00
Tobias Happ
51d115ac89 rustup: add zlib as runtime dependency
Fixes https://github.com/NixOS/nixpkgs/issues/92946.

(cherry picked from commit b2679e8b41)
2020-09-04 14:07:56 -07:00
Michael Raskin
5607e74b1d Merge pull request #96884 from ryneeverett/backport-firejail-fix-CVE-2020-17368-CVE-2020-17367
[20.03] firejail: add patches to fix CVE-2020-17367 and CVE-2020-17368
2020-09-04 05:23:53 +00:00
Maximilian Bosch
20b78803b9 hydra-unstable: 2020-08-04 -> 2020-09-02
Needed to fix Hydra with latest `nixUnstable`.

(cherry picked from commit 1c55613cd7)
2020-09-03 22:39:51 +02:00
Konstantin Alekseev
2868763c2b nixUnstable: pre20200721_ff314f1 -> pre20200829_f156513
(cherry picked from commit 4243ebb07e)
2020-09-03 22:39:50 +02:00
Matthew Bauer
fa3fb57d32 nix-bundle: 0.3 -> 0.4
(cherry picked from commit faa7ae8643)
2020-09-03 13:41:37 -05:00
Tim Steinbach
7f0e429056 linux: 5.4.61 -> 5.4.62 2020-09-03 14:15:40 -04:00
Tim Steinbach
bb02ef01d7 linux: 4.9.234 -> 4.9.235 2020-09-03 14:15:40 -04:00
Tim Steinbach
3cf63860e2 linux: 4.4.234 -> 4.4.235 2020-09-03 14:15:40 -04:00
Tim Steinbach
7a78d2ec6f linux: 4.19.142 -> 4.19.143 2020-09-03 14:15:40 -04:00
Tim Steinbach
3f44ab2219 linux: 4.14.195 -> 4.14.196 2020-09-03 14:15:40 -04:00
Maximilian Bosch
10aede9bcf element-desktop: 1.7.4 -> 1.7.5
https://github.com/vector-im/element-desktop/releases/tag/v1.7.5
(cherry picked from commit bf007a2c0a)
2020-09-03 10:49:53 +02:00
Maximilian Bosch
c5f903f242 element-web: 1.7.4 -> 1.7.5
https://github.com/vector-im/element-web/releases/tag/v1.7.5
(cherry picked from commit 412a28d43f)
2020-09-03 10:49:52 +02:00
Vladimír Čunát
d92de0eb18 Merge #96893: adobe-reader: add knownVulnerabilities 2020-09-03 06:41:18 +02:00
Michael Weiss
0d60b0b10e signal-desktop: 1.34.5 -> 1.35.1
(cherry picked from commit 9c6f11f89d)
2020-09-02 14:28:31 -07:00
Daniël de Kok
0ee482c818 adobe-reader: add knownVulnerabilities
We should really avoid that people unknowingly use Adobe Reader, it
has literally tens of known high-score code execution vulnerabilities,
probably exploited in the wild.

(cherry picked from commit 4b07b00c0d)
2020-09-01 10:00:50 +02:00
Stig Palmquist
65c4f28c72 firejail: add patches to fix CVE-2020-17367 and CVE-2020-17368
(cherry picked from commit e15cab8e9c)

Resolve #96783.
2020-09-01 03:36:19 +00:00
R. RyanTM
977ee466ae solr: 8.5.2 -> 8.6.1
(cherry picked from commit 563b73d880)
2020-08-31 20:22:01 -04:00
R. RyanTM
7a4bae9c2f solr: 8.5.1 -> 8.5.2
(cherry picked from commit 41a81c4f04)
2020-08-31 20:21:52 -04:00
R. RyanTM
dc6333cfa6 solr: 8.5.0 -> 8.5.1
(cherry picked from commit f82006b9af)
2020-08-31 20:21:41 -04:00
R. RyanTM
fd702775c0 solr: 8.4.1 -> 8.5.0
(cherry picked from commit 7613ae0ea7)
2020-08-31 20:21:29 -04:00
Vladimír Čunát
ff6a070b4e knot-dns: 2.9.5 -> 2.9.6
This is mostly a bug fix version with some small improvements.
https://gitlab.nic.cz/knot/knot-dns/-/tags/v2.9.6

(cherry picked from commit 1dbe47ced5)
2020-08-31 17:05:46 +02:00
Vladimír Čunát
27ac8de4a8 Merge #96360: thunderbird*: updates
(cherry picked from commit f56bda0c0c)
I briefly re-tested all of them atop 20.03.
2020-08-31 17:05:27 +02:00
oxalica
c3219cdf8f tdesktop: 2.1.13 -> 2.2.0 (#93901)
(cherry picked from commit 2bd78b209d)
2020-08-31 16:24:26 +02:00
Michael Weiss
9b2648a05e tdesktop: 2.1.12 -> 2.1.13
(cherry picked from commit 10b11fe5c8)
2020-08-31 16:24:24 +02:00
Michael Weiss
ddf54a16c7 tdesktop: 2.1.11 -> 2.1.12
(cherry picked from commit b713e97c30)
2020-08-31 16:24:23 +02:00
Michael Weiss
50236f40d6 tdesktop: 2.1.10 -> 2.1.11
(cherry picked from commit a1aecffc97)
2020-08-31 16:24:22 +02:00
Michael Weiss
4b340518df tdesktop: 2.1.7 -> 2.1.10
(cherry picked from commit 7ef22b9ff1)
2020-08-31 16:24:21 +02:00
Michael Weiss
a7447cb22b tdesktop: 2.1.6 -> 2.1.7
(cherry picked from commit 6d923b36cd)
2020-08-31 16:24:20 +02:00
Michael Weiss
49f36c1983 tdesktop: 2.1.4 -> 2.1.6
(cherry picked from commit 6e5b1a71eb)
2020-08-31 16:24:20 +02:00
Michael Weiss
1b4c1c9394 tdesktop: 2.1.2 -> 2.1.4
(cherry picked from commit 22fef8ebb1)
2020-08-31 16:24:19 +02:00
Michael Weiss
e7b56c5c07 tdesktop: 2.1.1 -> 2.1.2
(cherry picked from commit 69dc7e64ad)
2020-08-31 16:24:18 +02:00
Michael Weiss
b7276091ec tdesktop: 2.1.0 -> 2.1.1
Regarding microsoft_gsl: The CMake scripts from Telegram-Desktop did not
find it anymore (I didn't investigate this) and Arch already made this
change during the last update. It's probably best to do the same here
especially since Telegram-Desktop is currently based on GSL 3.0.1 while
our version is still at 2.1.0.

(cherry picked from commit e9e2f81590)
2020-08-31 16:22:58 +02:00
Tim Steinbach
1fc2400c44 linux: 5.7.18 -> 5.7.19 2020-08-31 08:55:30 -04:00
Stig Palmquist
2847777ec7 firefox: 79.0 -> 80.0
(cherry picked from commit c408178cab)
PR for master: #96454.
2020-08-30 11:32:04 +02:00
Stig Palmquist
852e90b19a firefox-esr-78: 78.1.0esr -> 78.2.0esr
(cherry picked from commit ba671f6906)
PR for master: #96454.
2020-08-30 10:13:59 +02:00
Stig Palmquist
196bbc32ee firefox-esr-68: 68.11.0esr -> 68.12.0esr
(cherry picked from commit 057b30b698)
PR for master: #96454.
2020-08-30 09:03:21 +02:00
Jos van den Oever
925ae0dee6 sonic-visualiser: 2.4.1 -> 4.0.1
The program is no longer broken.

(cherry picked from commit 528e27b33c)
2020-08-30 01:50:47 -04:00
Jos van den Oever
c86eb53a88 libfishsound at 1.0.0
(cherry picked from commit eb1ffda13c)
2020-08-30 01:50:47 -04:00
Jonathan Ringer
7fe5ff27a3 nixpkgs-review: 2.3.1 -> 2.4.0
(cherry picked from commit 66cb0b52a1)
2020-08-30 07:06:31 +02:00
Maximilian Bosch
1fb95d956c wireguard-tools: 1.0.20200820 -> 1.0.20200827
https://lists.zx2c4.com/pipermail/wireguard/2020-August/005790.html
(cherry picked from commit 1ce368f975)
2020-08-29 23:13:59 +02:00
Maximilian Bosch
8ad3199368 Merge pull request #96592 from TethysSvensson/tor-browser-954
tor-browser-bundle-bin: 9.5.3 -> 9.5.4
2020-08-29 19:06:53 +02:00
Maximilian Bosch
f9c4493288 matrix-synapse: 1.19.0 -> 1.19.1
https://github.com/matrix-org/synapse/releases/tag/v1.19.1
(cherry picked from commit 42173099bf)
2020-08-29 09:32:12 +02:00
Tethys Svensson
c1da480f51 tor-browser-bundle-bin: 9.5.3 -> 9.5.4 2020-08-29 09:18:36 +02:00
Michael Weiss
3182792128 Merge pull request #96457 from primeos/chromium-backport
[20.03] chromium: 84.0.4147.135 -> 85.0.4183.83
2020-08-28 14:41:28 +02:00
Michael Weiss
4737bed3ed chromium: Make the gnChromium overrides depend on the version
This is more robust than depending on the channel, though the version
should only matter if the configuration phase fails.
This also switches to the intended version for `chromium` which should
be higher since M85 is in the stable channel.

Thanks `@volth` for pointing this out.

(cherry picked from commit 25aed428aa)
2020-08-27 12:53:50 +02:00
Michael Weiss
9f966bae0d chromium: 84.0.4147.135 -> 85.0.4183.83
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_25.html

This update includes 20 security fixes.

CVEs:
CVE-2020-6558 CVE-2020-6559 CVE-2020-6560 CVE-2020-6561 CVE-2020-6562
CVE-2020-6563 CVE-2020-6564 CVE-2020-6565 CVE-2020-6566 CVE-2020-6567
CVE-2020-6568 CVE-2020-6569 CVE-2020-6570 CVE-2020-6571

(cherry picked from commit 4252ba90f4)
2020-08-27 12:53:50 +02:00
Benjamin Hipple
2739290bb0 Merge pull request #96398 from obsidiansystems/cuda11-20.03
[20.03] Add cuda 11
2020-08-26 20:39:19 -04:00
Matthew Bauer
eb1df99366 cudatoolkit: init v11.0.3
(cherry picked from commit 164f8024e9)
2020-08-26 14:26:51 -05:00
Michael Reilly
19ce42e4c2 cudnn_cudatoolkit_10_2: init at 7.6.5
(cherry picked from commit 972db874b3)
2020-08-26 14:26:34 -05:00
Tim Steinbach
feff2fa665 linux: 5.7.17 -> 5.7.18 2020-08-26 13:56:40 -04:00
Tim Steinbach
cfa0fe3a0f linux: 5.4.60 -> 5.4.61 2020-08-26 13:56:40 -04:00
Tim Steinbach
0a3583509d linux: 4.9.233 -> 4.9.234 2020-08-26 13:56:40 -04:00
Tim Steinbach
a91afce9f2 linux: 4.4.233 -> 4.4.234 2020-08-26 13:56:40 -04:00
Tim Steinbach
4c46ce89c5 linux: 4.19.141 -> 4.19.142 2020-08-26 13:56:40 -04:00
Tim Steinbach
f4da1743b0 linux: 4.14.194 -> 4.14.195 2020-08-26 13:56:40 -04:00
Robert Scott
6884c3135f ghostscript: add patch for CVE-2020-15900
(cherry picked from commit 9292dbf7fa)
2020-08-24 18:34:46 +01:00
Dmitry Kalinkin
14006b724f Merge pull request #96130 from eqyiel/fix/port-95826-to-stable
[20.03] qtwebengine: fix build for darwin
2020-08-23 20:07:29 -07:00
Silvan Mosberger
a5584ab70d Merge pull request #95263 from ckauhaus/88407-sysstat-cve-2019-19725
sysstat: 12.2.0 -> 12.2.3
2020-08-23 23:20:32 +02:00
Ruben Maher
e5612ebe3f qtwebengine: fix build for darwin
(cherry picked from commit 68bf9101d7)
2020-08-23 13:45:40 +09:00
Maximilian Bosch
0c59c1296b wireguard-tools: 1.0.20200513 -> 1.0.20200820
https://lists.zx2c4.com/pipermail/wireguard/2020-August/005780.html
(cherry picked from commit 05a4dc3ce9)
2020-08-22 22:42:02 +02:00
R. RyanTM
b83b54d0a8 freerdp: 2.1.2 -> 2.2.0
(cherry picked from commit 2a597059fe)
2020-08-22 17:16:05 +02:00
Lassulus
05fb4a2099 Merge pull request #89782 from paperdigits/displaycal-backport
displaycal: 3.5 -> 3.8.9.3
2020-08-22 13:58:36 +02:00
WilliButz
ebf5991623 freeradius: 3.0.20 -> 3.0.21
(cherry picked from commit 609cdfae9a)
2020-08-22 09:42:59 +02:00
Steven Shaw
4a6bf887e4 rescuetime: 2.16.2.1 -> 2.16.3.1
(cherry picked from commit 4315835d63)
2020-08-22 08:23:22 +02:00
Silvan Mosberger
666d3103bb Merge pull request #95583 from risicle/ris-sigil-0.9.16-r20.03
[r20.03] sigil: 0.9.14 -> 0.9.16, addressing CVE-2019-14452
2020-08-22 01:29:49 +02:00
Robert Scott
6986e78e50 nghttp2: add patch for CVE-2020-11080
included in-tree due to bootstrapping difficulties with fetchpatch
2020-08-21 23:42:33 +01:00
Tim Steinbach
2d580cd279 linux: 5.7.16 -> 5.7.17 2020-08-21 15:54:36 -04:00
Tim Steinbach
abf66574d3 linux: 5.4.59 -> 5.4.60 2020-08-21 15:54:34 -04:00
Tim Steinbach
d5b3ca78e3 linux: 4.9.232 -> 4.9.233 2020-08-21 15:54:32 -04:00
Tim Steinbach
73b4448562 linux: 4.4.232 -> 4.4.233 2020-08-21 15:54:30 -04:00
Tim Steinbach
1d634f69e1 linux: 4.19.140 -> 4.19.141 2020-08-21 15:54:28 -04:00
Tim Steinbach
1ec6859307 linux: 4.14.193 -> 4.14.194 2020-08-21 15:54:26 -04:00
Michael Weiss
64fec31a24 Merge pull request #95820 from primeos/chromium-backport
[20.03] chromium: 84.0.4147.125 -> 84.0.4147.135
2020-08-21 21:24:27 +02:00
Robert Scott
fceb87e537 openexr: 2.4.1 -> 2.4.2 2020-08-21 19:14:10 +01:00
Florian Klink
de3780b937 nixos/nginx: move configuration testing script into reload command
nginx -t not only verifies configuration, but also creates (and chowns)
files. When the `nginx-config-reload` service is used, this can cause
directories to be chowned to `root`, causing nginx to fail.

This moves the nginx -t command into a second ExecReload command, which
runs as nginx's user. While fixing above issue, this will also cause the
configuration to be verified when running `systemctl reload nginx`, not
only when restarting the dummy `nginx-config-reload` unit. The latter is
mostly a workaround for missing features in our activation script
anyways.

(cherry picked from commit 300049ca51)
2020-08-20 09:41:18 +02:00
Michael Weiss
fb4ddfd6d7 chromium: 84.0.4147.125 -> 84.0.4147.135
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_18.html

This update includes 1 security fix.

CVEs:
CVE-2020-6556

(cherry picked from commit f9c3038465)
2020-08-20 00:05:19 +02:00
Benno Fünfstück
fc966732c8 lbzip2: fix build
This is backport of #80560 (since we don't have updated gnulib in 20.03)
and #80906.

Based on 07cf03630f
2020-08-19 17:27:20 +02:00
Tim Steinbach
c8d79aa989 linux: 5.7.15 -> 5.7.16 2020-08-19 08:51:29 -04:00
Tim Steinbach
30a6ef8b1f linux: 5.4.58 -> 5.4.59 2020-08-19 08:51:29 -04:00
Tim Steinbach
280a347024 linux: 4.19.139 -> 4.19.140 2020-08-19 08:51:29 -04:00
Maximilian Bosch
f0924dbf55 matrix-synapse: 1.18.0 -> 1.19.0
https://github.com/matrix-org/synapse/releases/tag/v1.19.0
(cherry picked from commit 53dc9e8103)
2020-08-18 15:15:15 +02:00
Maximilian Bosch
af10edeb40 python3Packages.canonicaljson: 1.1.4 -> 1.3.0
(cherry picked from commit 2d72eaf616)
2020-08-18 15:15:15 +02:00
Maximilian Bosch
32324de6d2 element-desktop: 1.7.3 -> 1.7.4
https://github.com/vector-im/element-desktop/releases/tag/v1.7.4
(cherry picked from commit 2cb4d19268)
2020-08-18 15:15:14 +02:00
Maximilian Bosch
43e11555d0 element-web: 1.7.3 -> 1.7.4
https://github.com/vector-im/element-web/releases/tag/v1.7.4
(cherry picked from commit 01ff24f1b5)
2020-08-18 15:15:14 +02:00
Silvan Mosberger
38bfbd5d6f Merge pull request #91937 from spacefrogg/openafs-1.6.24
[20.03] openafs: 1.6.23 -> 1.6.24
2020-08-18 01:08:47 +02:00
Maximilian Bosch
eb8080d979 nixos/nextcloud: update nginx config
This patch ensures that latest Nextcloud works flawlessly again on our
`nginx`. The new config is mostly based on upstream recommendations
(again)[1]:

* Trying to access internals now results in a 404.
* All `.php`-routes get properly resolved now.
* Removed 404/403 handling from `nginx` as the app itself takes care of
  this. Also, this breaks the `/ocs`-API.
* `.woff2?`-files expire later than other assets like images.

Closes #95293

[1] https://docs.nextcloud.com/server/latest/admin_manual/installation/nginx.html

(cherry picked from commit 42f6244899)
2020-08-17 20:20:51 +02:00
Martin Weinelt
cbaaba7a20 Merge pull request #95676 from dotlambda/dovecot-2.3.11.3
dovecot: 2.3.10.1 -> 2.3.11.3
2020-08-17 15:04:18 +02:00
Lassulus
bfdf25f3ff tor-browser: disable hardening by default (#93154)
* tor-browser: disable hardening by default

this seems to cause crashes with certain tabs.
relevant issue: https://github.com/NixOS/nixpkgs/issues/86356

* Update pkgs/applications/networking/browsers/tor-browser-bundle-bin/default.nix

Co-authored-by: Jörg Thalheim <Mic92@users.noreply.github.com>
(cherry picked from commit 45e2ff349f)
2020-08-17 14:33:55 +02:00
Robert Schütz
d24914ff0c dovecot_pigeonhole: 0.5.10 -> 0.5.11
(cherry picked from commit c62812c321)
2020-08-17 12:46:46 +02:00
Robert Schütz
c679e26098 dovecot: 2.3.10.1 -> 2.3.11.3
(cherry picked from commit 4f5b797ec3)
2020-08-17 12:46:41 +02:00
R. RyanTM
fcbe539d34 dovecot_pigeonhole: 0.5.9 -> 0.5.10
(cherry picked from commit da5e9d4ab9)
2020-08-17 12:46:35 +02:00
worldofpeace
f184fe352b Merge pull request #95654 from OPNA2608/backport-update-palemoon-28.11.0
[20.03] palemoon: 28.10.0 -> 28.12.0
2020-08-17 05:01:42 -04:00
Christoph Neidahl
ab92fa63a5 palemoon: 28.10.0 -> 28.12.0
(cherry picked from commit a5ffb7cf8a)
2020-08-17 08:26:56 +02:00
Florian Klink
cb1996818e Merge pull request #93056 from dasj19/nautilus-2003-update
[20.03] nautilus: 3.34.2 -> 3.34.3
2020-08-17 00:09:25 +02:00
Martin Weinelt
9319284c1d Merge pull request #95518 from risicle/ris-asyncpg-CVE-2020-17446-r20.03
[r20.03] pythonPackages.asyncpg: add patch for CVE-2020-17446
2020-08-16 20:25:55 +02:00
Robert Scott
24e7620cb5 pythonPackages.asyncpg: add patch for CVE-2020-17446 2020-08-16 19:19:05 +01:00
Martin Weinelt
f8a10a7719 python3Packages.uvloop: disable test_write_to_closed_transport test on 3.8+
Reenables the TCP testsuite and only disables the single failing test.

https://github.com/MagicStack/uvloop/issues/355
(cherry picked from commit affa7726ac)
2020-08-16 10:46:41 -07:00
Robert Scott
fecd3c6d7f sigil: 0.9.14 -> 0.9.16
addressing CVE-2019-14452
2020-08-16 12:52:00 +01:00
Michael Weiss
f59b2717b1 Merge pull request #95176 from primeos/chromium-backport
[20.03] chromium: 84.0.4147.105 -> 84.0.4147.125
2020-08-15 22:33:20 +02:00
Martin Weinelt
3506bce1d4 Merge pull request #95456 from risicle/ris-pure-ftpd-CVE-2020-9274-r20.03
[r20.03] pure-ftpd: add patches for CVE-2020-9274, CVE-2020-9365
2020-08-15 00:30:11 +02:00
Robert Scott
1b382475d8 pure-ftpd: add patches for CVE-2020-9274, CVE-2020-9365
Fixes merged to upstream's master but no release yet.

(cherry picked from commit 5b072a4fc0)
2020-08-14 22:14:29 +01:00
Martin Weinelt
48b95e21aa Merge pull request #95195 from mweinelt/20.03/ansible
[20.03] ansible: 2.9.11 -> 2.9.12; 2.8.13 -> 2.8.14
2020-08-14 22:02:23 +02:00
worldofpeace
4fa7cc60c1 Merge pull request #95206 from worldofpeace/gi-backport
[20.03] Fix ibus
2020-08-13 19:13:33 -04:00
Vladimír Čunát
05195accdc rtlwifi_new: switch fetchFromGitHub to a working repo
Fixes #95324.

(cherry picked from commit 4451f9b68f)
2020-08-13 16:50:33 +02:00
Aaron Andersen
b4dac6714d Merge pull request #94912 from aanderse/apacheHttpd-20.03
apacheHttpd: 2.4.43 -> 2.4.46 [20.03 backport]
2020-08-12 21:27:25 -04:00
Christian Kauhaus
492fd3c655 sysstat: 12.2.0 -> 12.2.3
Point release which contains various fixes including one for
CVE-2019-19725.
2020-08-12 17:57:19 +02:00
Christian Kauhaus
2a403c9476 Merge pull request #95233 from jerith666/alpine-2-23-backport
alpine: 2.21 -> 2.23
2020-08-12 16:51:42 +02:00
Samuel Gräfenstein
7a4047da63 flashplayer: 32.0.0.403 -> 32.0.0.414
(cherry picked from commit 7a34bf1aae)
2020-08-12 08:03:47 -05:00
Florian Klink
4e4906da4e Merge pull request #94970 from flokli/20.03-gitlab-13.0.12
[20.03] gitlab: 13.0.12
2020-08-12 12:32:28 +02:00
Maximilian Bosch
2090411800 evcxr: 0.5.1 -> 0.5.3
https://github.com/google/evcxr/blob/v0.5.3/RELEASE_NOTES.md
(cherry picked from commit de96815a2e)
2020-08-11 23:04:34 +02:00
Tor Hedin Brønner
b79747ead8 nixos/ibus: fix evaluation
Need to reference through `config` when checking what other modules have set.

(cherry picked from commit c9d988b0e1)
2020-08-11 14:42:27 -04:00
worldofpeace
6a0f658dcf nixos/ibus: add ibus portal if portals are enabled
(cherry picked from commit 76f7fc1476)
2020-08-11 14:42:26 -04:00
Symphorien Gibol
22fdd693d8 Revert "Revert "ibus: fix dconf db installation""
This reverts commit ee5cba24c3.

(cherry picked from commit 11d6318a01)
2020-08-11 14:42:04 -04:00
Symphorien Gibol
0d341125c3 ibus: fix installation of dconf database
Fixes this warning at ibus-daemon startup:

(ibus-dconf:15691): dconf-WARNING **: 21:49:24.018: unable to open file '/etc/dconf/db/ibus': Failed to open file ?/etc/dconf/db/ibus?: open() failed: No such file or directory; expect degraded performance

(cherry picked from commit 3dbd629fa4)
2020-08-11 14:41:58 -04:00
worldofpeace
3e09a95377 Revert "ibus: fix dconf db installation"
(cherry picked from commit ee5cba24c3)
2020-08-11 14:41:51 -04:00
Symphorien Gibol
2eda645134 nixos/tests/ibus: fix test
(cherry picked from commit 5b7ffe6140)
2020-08-11 14:41:44 -04:00
Symphorien Gibol
3419ccb574 ibus: fix installation of dconf database
Fixes this warning at ibus-daemon startup:

(ibus-dconf:15691): dconf-WARNING **: 21:49:24.018: unable to open file '/etc/dconf/db/ibus': Failed to open file ?/etc/dconf/db/ibus?: open() failed: No such file or directory; expect degraded performance

(cherry picked from commit a71dc0b27e)
2020-08-11 14:41:43 -04:00
Symphorien Gibol
c61471dde9 ibus: fix generation of 00-upstream-settings
(cherry picked from commit bd6c12ba32)
2020-08-11 14:41:42 -04:00
Jan Tojnar
572b49b147 wrapGAppsHook: add comments
(cherry picked from commit 0be3b18d3e)
2020-08-11 14:31:24 -04:00
Jan Tojnar
7293136913 wrapGAppsHook: add tests
(cherry picked from commit 49b89afcc2)
2020-08-11 14:31:23 -04:00
Jan Tojnar
e1d83fcc0b wrapGAppsHook: move to a separate file
(cherry picked from commit 69b89979ba)
2020-08-11 14:31:22 -04:00
Jan Tojnar
4af94d3384 gobject-introspection: Ensure the giDiscoverSelf is run before gappsWrapperArgsHook
gappsWrapperArgsHook tries to collect GI_TYPELIB_PATH environment variable so if we want it to see the path giDiscoverSelf adds, we need to force the order.

(cherry picked from commit 8f7387f219)
2020-08-11 14:27:46 -04:00
worldofpeace
f2825d2cca Merge pull request #94749 from worldofpeace/vala-update-20.03
[20.03] vala: 0.46.5 -> 0.46.12
2020-08-11 14:27:13 -04:00
Martin Weinelt
3cf1c9ae26 ansible_2_8: 2.8.13 -> 2.8.14
(cherry picked from commit 9e6ee27597)
2020-08-11 19:17:39 +02:00
Martin Weinelt
e048ee3e44 ansible_2_9: 2.9.11 -> 2.9.12
(cherry picked from commit a75097d2c1)
2020-08-11 19:17:26 +02:00
Tim Steinbach
246b11b18f linux: 5.7.14 -> 5.7.15 2020-08-11 13:05:46 -04:00
Tim Steinbach
38caa17c3b linux: 5.4.57 -> 5.4.58 2020-08-11 13:05:46 -04:00
Tim Steinbach
7f99680f8f linux: 4.19.138 -> 4.19.139 2020-08-11 13:05:46 -04:00
f4814n
1d1d585f99 chromium: Add missing dependency on coreutils (#94578)
The script that runs chromium calls tr from coreutils - however
it just assumed that coreutils are in PATH.

With missing coreutils chromium did still launch (at least with
d433839007 applied) but emitted
`line 15: tr: command not found` error messages.

(cherry picked from commit 6e4d33a001)
2020-08-11 14:59:48 +02:00
Griffin Smith
59c4961de4 chromium: Add missing dependency on gnugrep
The bin script that runs chromium calls out to gnugrep - but gnugrep is
missing as a runtime dependency of the chromium package. I found this
out when I was trying to put it in a docker image.

(cherry picked from commit d433839007)
2020-08-11 14:59:43 +02:00
Michael Weiss
8d924ba947 chromium: 84.0.4147.105 -> 84.0.4147.125
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html

This update includes 15 security fixes.

CVEs:
CVE-2020-6542 CVE-2020-6543 CVE-2020-6544 CVE-2020-6545 CVE-2020-6546
CVE-2020-6547 CVE-2020-6548 CVE-2020-6549 CVE-2020-6550 CVE-2020-6551
CVE-2020-6552 CVE-2020-6553 CVE-2020-6554 CVE-2020-6555

(cherry picked from commit edb0920697)
2020-08-11 14:58:07 +02:00
Michael Weiss
46fccc51db chromium{Beta,Dev}: M84 -> M85 -> M86 (broken)
Mark chromiumDev as broken since the build requires LLVM 11 which is not
yet in Nixpkgs (due to the lack of an RC, see #93324). Build error:
clang (LLVM option parsing): Unknown command line argument '-basic-aa-recphi=0'.  Try: 'clang (LLVM option parsing) --help'
clang (LLVM option parsing): Did you mean '--basicaa-recphi=0'?
ninja: build stopped: subcommand failed.

(cherry picked from commit 11fbe97810)
2020-08-11 14:57:50 +02:00
Tristan Helmich (omniIT)
d84d3632ab graylog: 3.3.3 -> 3.3.4
Bumps Graylog and integration plugins to version 3.3.4

(cherry picked from commit f797bed266)
2020-08-11 11:56:12 +02:00
Jörg Thalheim
0606ad4114 Merge pull request #95093 from Mic92/busybox
[20.03] busybox: Pull in upstream patch for CVE-2018-1000500
2020-08-11 05:53:37 +01:00
Benjamin Asbach
3a78bb222c roundcube: 1.4.7 -> 1.4.8
(cherry picked from commit e513a4e1f9)
2020-08-10 23:18:13 +02:00
Tethys Svensson
ea783ce72f busybox: Pull in upstream patch for CVE-2018-1000500
(cherry picked from commit 87af0f9871)
2020-08-10 18:19:41 +01:00
Tim Steinbach
c64b791f4d Merge pull request #94603 from asbachb/backport/openjdk11
[20.03] openjdk: 11.06 -> 11.08
2020-08-10 08:05:06 -04:00
Tim Steinbach
366e2109fa Merge pull request #94868 from asbachb/backport/openjdk8
[20.03] openjdk: 8u222 -> 8u265
2020-08-10 08:04:58 -04:00
R. RyanTM
e54dc9d9ac element-desktop: 1.7.2 -> 1.7.3
(cherry picked from commit 7602e05d84)
2020-08-10 10:15:24 +02:00
Griffin Smith
3c64d2addf openexr,ilmbase: Switch to cmake-based build
It appears that the autotools based build isn't supported on Darwin.
Just use the stdenv-builtin cmake build everywhere, as it works just
fine and is simpler.

(cherry picked from commit f509255ff7)
2020-08-10 00:16:20 +01:00
Bernardo Meurer
a5449e7540 openexr,imlbase: 2.3.0 -> 2.4.1
(cherry picked from commit e5e31593ce)
2020-08-10 00:16:11 +01:00
Vladimír Čunát
e9bd19d4d3 thunderbird*: add 78 and update (to release-20.03)
This basically syncs the versions with master PR #94863.
2020-08-09 11:31:27 +02:00
Vladimír Čunát
0e72e54d03 thunderbird-78: fixes to build on 20.03 2020-08-09 11:06:51 +02:00
Vladimír Čunát
8708d3aac2 thunderbird-78: init at 78.1.1
The expression was taken from current master;
the list of commits getting there would be too complex for me.
(This doesn't work; fixes come in a child commit.)
2020-08-09 11:05:42 +02:00
Vladimír Čunát
672679ce9e thunderbird-bin-78: init at 78.1.1
The expressions were taken from current master;
the list of commits getting there would be too complex for me.
Re-tested briefly atop 20.03.
2020-08-09 10:39:52 +02:00
taku0
c52b770a43 thunderbird: 68.9.0 -> 68.11.0
(cherry picked from commit 997e6315f2)
2020-08-09 10:22:21 +02:00
Vladimír Čunát
acf948e48b thunderbird*: rename *.nix to make cherry-picks easier
Unfortunately, renaming the patch file causes a rebuild.
2020-08-09 10:18:12 +02:00
Maximilian Bosch
d3a1eb06ba python3Packages.dlib: 19.20 -> 19.21
https://github.com/davisking/dlib/releases/tag/v19.21
(cherry picked from commit 3c7fe5bb6a)
2020-08-08 23:47:42 +02:00
Maximilian Bosch
be7e7e0f53 EmptyEpsilon: 2020-04-09 -> 2020-08-07
https://github.com/daid/EmptyEpsilon/releases/tag/EE-2020.08.07
(cherry picked from commit be9676bda1)
2020-08-08 23:47:41 +02:00
Florian Klink
16ec57b36e gitlab: 13.0.9 -> 13.0.12
(cherry picked from commit 30309e1d62dcefefbf8fa69bfede1e197bacc8eb)
2020-08-08 23:44:51 +02:00
Milan Pässler
347d3c4184 gitlab: 13.0.8 -> 13.0.9
Security release: https://about.gitlab.com/releases/2020/07/06/critical-security-release-gitlab-13-1-3-released/

(cherry picked from commit f3a353f184)
2020-08-08 23:40:27 +02:00
Florian Klink
58293362b9 gitlab: 13.0.6 -> 13.0.8 (#92060)
(cherry picked from commit d986fccd9d)
2020-08-08 23:40:26 +02:00
Florian Klink
027cef0f9f gitlab: 13.0.4 -> 13.0.6
CI Token Access Control

An authorization issue discovered in the mirroring logic allowed read access to private repositories. This issue is now mitigated in the latest release and is waiting for a CVE ID to be assigned.

https://about.gitlab.com/releases/2020/06/10/critical-security-release-13-0-6-released/
(cherry picked from commit 38a4af7d19)
2020-08-08 23:40:26 +02:00
talyz
28a66949ef gitlab: 13.0.3 -> 13.0.4
https://about.gitlab.com/releases/2020/06/03/critical-security-release-13-0-4-released/
(cherry picked from commit 0b5c534598)
2020-08-08 23:40:26 +02:00
Robin Gloster
020666f17a gitlab: 12.10.8 -> 13.0.3
https://about.gitlab.com/releases/2020/05/22/gitlab-13-0-released/
https://about.gitlab.com/releases/2020/05/27/security-release-13-0-1-released/
https://about.gitlab.com/releases/2020/05/29/gitlab-13-0-3-released/

The gitaly gitlab-shell config has moved into gitaly.toml. See
https://gitlab.com/gitlab-org/gitaly/-/issues/2182 for more info.

(cherry picked from commit 79454f15ac)
2020-08-08 23:39:57 +02:00
Jörg Thalheim
85eef615fb Merge pull request #94897 from Mic92/r2-backport 2020-08-08 20:36:17 +01:00
Tim Steinbach
5ac56e221f linux: 5.7.13 -> 5.7.14 2020-08-08 10:07:37 -04:00
Tim Steinbach
301c3e36b5 linux: 5.4.56 -> 5.4.57 2020-08-08 10:07:37 -04:00
Tim Steinbach
127c8de521 linux: 4.19.137 -> 4.19.138 2020-08-08 10:07:37 -04:00
Tim Steinbach
9e0f049162 linux: 4.14.192 -> 4.14.193 2020-08-08 10:07:37 -04:00
Aaron Andersen
a0057fc010 apacheHttpd: 2.4.43 -> 2.4.46
(cherry picked from commit 6302eb2bfb)
2020-08-07 21:05:09 -04:00
Jörg Thalheim
18188bacd6 radare2-cutter: 1.10.3 -> 1.11.0
(cherry picked from commit fca28bc496)
2020-08-07 20:06:43 +01:00
Jörg Thalheim
60e11a9158 radare2: 4.4.0 -> 4.5.0
(cherry picked from commit 63576ebc07)
2020-08-07 20:06:41 +01:00
Jörg Thalheim
66b6d761ef radare2-cutter: 1.10.2 -> 1.10.3
(cherry picked from commit 11fa2d4340)
2020-08-07 20:06:39 +01:00
Jörg Thalheim
3ccc453893 radare2: 4.3.1 -> 4.4.0
(cherry picked from commit 91b71a7b60)
2020-08-07 20:06:37 +01:00
Jörg Thalheim
9c1d529710 radare2-cutter: 1.10.1 -> 1.10.2
(cherry picked from commit f565c8fd1c)
2020-08-07 20:06:17 +01:00
Jörg Thalheim
218efad7a9 radare2: 4.3.0 -> 4.3.1
(cherry picked from commit 09ad2cffdc)
2020-08-07 20:06:15 +01:00
Jörg Thalheim
3097539fb6 radare2: 4.2.1 -> 4.3.0 (#81730)
(cherry picked from commit fb6f2d1488)
2020-08-07 20:06:14 +01:00
Jörg Thalheim
b422280363 r2: 4.2.0 -> 4.2.1
(cherry picked from commit b878000c66)
2020-08-07 20:06:12 +01:00
Matt McHenry
a3d104acfe openjdk8: 1.8.0_242 -> 1.8.0_265
(cherry picked from commit 0afe6a282a)
2020-08-07 16:19:31 +02:00
Benjamin Asbach
da0211c10d openjdk8: 8u222b10 -> 8u242b08
(cherry picked from commit b87e7d00f3)
2020-08-07 16:19:20 +02:00
Benjamin Asbach
ec3bf7a909 openjdk8: 8u222 -> 8u242
(cherry picked from commit 36c53f703b)
2020-08-07 16:19:10 +02:00
Florian Klink
4364ff933e Merge pull request #94759 from toonn/release-20.03
[20.03] wire-desktop: linux 3.18.2925 -> 3.19.2928, mac 3.18.3728 -> 3.19.3799
2020-08-07 10:01:12 +02:00
Jonathan Ringer
825c68c4ae discord-canary: 0.0.105 -> 0.0.106
(cherry picked from commit 9fbbe30a44)
2020-08-06 13:00:33 -07:00
Jonathan Ringer
2afca2f9f2 discord-ptb: 0.0.20 -> 0.0.21
(cherry picked from commit 76ee4f6dbc)
2020-08-06 13:00:33 -07:00
ldesgoui
8bb823f261 discord: 0.0.10 -> 0.0.11
(cherry picked from commit ded6c3db4e)
2020-08-06 13:00:33 -07:00
Florian Klink
e23e05452c Merge pull request #94746 from helsinki-systems/backport/20.03/firefox-79
[20.03] Firefox 79
2020-08-06 15:33:30 +02:00
Matt McHenry
00c32cd3be alpine: 2.21 -> 2.23
(cherry picked from commit a8fa0269ee)
2020-08-05 19:32:34 -04:00
taku0
74ddece731 firefox: 78.0.2 -> 79.0
(cherry picked from commit 6a4e0ee698)
2020-08-06 01:28:54 +02:00
toonn
5870db01e6 wire-desktop: mac 3.18.3728 -> 3.19.3799
(cherry picked from commit 787a38bf6b)
2020-08-06 01:19:27 +02:00
toonn
5cb3967ded wire-desktop: linux 3.18.2925 -> 3.19.2928
(cherry picked from commit cc8d2ba291)
2020-08-06 01:19:15 +02:00
Maximilian Bosch
0c0fe6d85b kitty: remove myself from the maintainer list
I don't use this as terminal emulator anymore and it's
pretty well-maintained by my fellow co-maintainers.

(cherry picked from commit 1f01916d50)
2020-08-05 22:22:03 +02:00
yoctocell
e0c983e2e6 neovim: 0.4.3 -> 0.4.4
(cherry picked from commit 7f137849e8)
2020-08-05 22:21:22 +02:00
Martin Weinelt
f80b8d1d2d element-desktop: 1.7.2 -> 1.7.3
https://github.com/vector-im/element-desktop/releases/tag/v1.7.3
(cherry picked from commit 6e405a8e85)
2020-08-05 21:57:42 +02:00
Martin Weinelt
5580251cf9 element-web: 1.7.2 -> 1.7.3
https://github.com/vector-im/element-web/releases/tag/v1.7.3
(cherry picked from commit 3d53c0514c)
2020-08-05 21:57:41 +02:00
worldofpeace
7016c5f7c2 Merge pull request #94709 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.34.4 -> 1.34.5
2020-08-05 14:50:04 -04:00
worldofpeace
e78679ed98 Revert "Revert "pantheon.elementary-files: 4.4.3 -> 4.4.4""
This reverts commit caf8427f6f.
2020-08-05 14:37:32 -04:00
worldofpeace
bebdaa353e vala: 0.46.5 -> 0.46.12 2020-08-05 14:37:24 -04:00
worldofpeace
37178a3cca Merge branch 'release-20.03' into staging-20.03 2020-08-05 14:36:11 -04:00
worldofpeace
caf8427f6f Revert "pantheon.elementary-files: 4.4.3 -> 4.4.4"
This reverts commit bfb78aaf0e.

Fixes https://github.com/NixOS/nixpkgs/issues/94707. Needs a vala update
will will happen in staging-20.03 (also reverting this).
2020-08-05 14:34:04 -04:00
symphorien
13fe7cfb14 epkowa: update hashes (#93846) 2020-08-05 20:25:28 +02:00
ajs124
de38facb66 nspr_latest: init at 4.26
firefox 79 needs this

based on cebca41b3c
2020-08-05 20:03:51 +02:00
ajs124
3a9edda794 rust-cbindgen_0_14_1 -> rust-cbindgen_latest: 0.14.1 -> 0.14.3
firefox 79 requires this version

based on dc5a3f9f13
2020-08-05 20:03:51 +02:00
Alyssa Ross
39498eb925 rust: add 1.44.0
Thunderbird and Firefox don't build with 1.41 (or 1.45 for that matter)

based on 1f9cd4cf0a
2020-08-05 20:03:49 +02:00
Tim Steinbach
a7dc43b3a9 linux: 5.7.12 -> 5.7.13 2020-08-05 08:46:02 -04:00
Tim Steinbach
a7d47c2f2a linux: 5.4.55 -> 5.4.56 2020-08-05 08:46:02 -04:00
Tim Steinbach
1df624627f linux: 4.19.136 -> 4.19.137 2020-08-05 08:46:02 -04:00
Tim Steinbach
ab47539707 linux: 4.14.191 -> 4.14.192 2020-08-05 08:46:02 -04:00
Michael Weiss
f04bcbf815 signal-desktop: 1.34.4 -> 1.34.5
(cherry picked from commit 695b69ac7d)
2020-08-05 11:26:13 +02:00
Profpatsch
d5fee0a57a lorri: 1.1 -> 1.1.1
Patch release which adds a manpage.

Adding a `man` and a `doc` output, and copying the files to the
corresponding directories.

The `overrideAttrs` is necessary because `buildRustPackage` does not
allow adding outputs.
2020-08-04 17:57:02 +02:00
Maximilian Bosch
b8151a4c25 hydra-unstable: 2020-07-28 -> 2020-08-04
Moving just one patch forward to fix importing store-paths from
`hydra-queue-runner`[1]. The other patches[2] require a newer
`pkgs.nixUnstable` and can't be used currently due to this.

[1] https://github.com/NixOS/nixpkgs/pull/93945#issuecomment-668244478
[2] 77c33c1d71...4b5813051b

(cherry picked from commit ae9ab324b7)
2020-08-04 15:54:07 +02:00
Tim Steinbach
f3dac135ba linux: 5.7.11 -> 5.7.12 2020-08-03 16:36:45 -04:00
Tim Steinbach
5bbf17d09d linux: 5.4.54 -> 5.4.55 2020-08-03 16:36:43 -04:00
Tim Steinbach
ce44e99303 linux: 4.9.231 -> 4.9.232 2020-08-03 16:36:42 -04:00
Tim Steinbach
91a0d232da linux: 4.4.231 -> 4.4.232 2020-08-03 16:36:41 -04:00
Tim Steinbach
a45141c95f linux: 4.19.135 -> 4.19.136 2020-08-03 16:36:39 -04:00
Tim Steinbach
49acaeaf75 linux: 4.14.190 -> 4.14.191 2020-08-03 16:36:38 -04:00
Karl Hallsby
77909d6eae tor-browser-bundle-bin: 9.5 -> 9.5.3
(cherry picked from 1970c2dbd0)
2020-08-03 22:18:52 +02:00
Maximilian Bosch
f631400a71 Merge pull request #94616 from pacien/mautrix-telegram-postgres-2003
[20.03] mautrix-telegram: add postgresql database driver
2020-08-03 20:27:00 +02:00
pacien
f3b21db6ab mautrix-telegram: add postgresql database driver
PostgreSQL is listed as an officially supported database backend.

(cherry picked from commit 1bee4762c3)
2020-08-03 20:07:19 +02:00
Benjamin Asbach
c4bb2630f5 openjdk: 11.0.7 -> 11.0.8
Also added `minor` variable to reflect naming scheme introduced in java 9: https://bugs.openjdk.java.net/browse/JDK-8061493

(cherry picked from commit 56cff958e8)
2020-08-03 12:40:40 +02:00
Benjamin Asbach
5cf660465e openjdk: 11.0.6 -> 11.0.7
(cherry picked from commit 890485a2bd)
2020-08-03 12:40:16 +02:00
Maximilian Bosch
d971fd7cba oraclejdk8: update jce hash
See c5dd1fba89 (commitcomment-41126603)

(cherry picked from commit 3c155bb20c)
2020-08-02 23:35:21 +02:00
Justin Bedo
6967dc37df singularity: 3.2.1 -> 3.6.1 2020-08-02 22:49:16 +02:00
Vladimír Čunát
ea0b3dd875 firefox: backport updates into release-20.03
We've been slipping behind on backporting for the default
firefox version.  This doesn't make it perfect, but using ESR 78
should make it easier for us to keep up.

Certainly feel free to work on backporting 79+ as well.

I briefly tested both affected versions (68 and 78).
2020-08-02 12:46:00 +02:00
taku0
61acfba631 firefox-esr-78: init at 78.1.0esr
(cherry picked from commit 1d730e1629)
/cc master PR #94421.
2020-08-02 11:13:44 +02:00
ajs124
a939519e7e firefox: 77.0.1 -> 78.0.1 (security)
(cherry picked from commit d4e479aae7)
/cc original PR #92043.
2020-08-02 11:13:00 +02:00
Vladimír Čunát
9ae7d8d348 firefox*: build with nodejs 13
Later firefox versions won't build with the current nodejs;
it's just build-time dependency and 13 seems to work fine.
2020-08-02 11:09:51 +02:00
Mario Rodas
5eabc6d148 icu67: init at 67.1
Changelog: https://github.com/unicode-org/icu/releases/tag/release-67-1
(cherry picked from commit 878ed3e2b5)
2020-08-02 11:08:52 +02:00
Vladimír Čunát
97cb5d7d77 nss_latest: 3.52.1 -> 3.55
It's exactly code written for nixpkgs master (over multiple commits),
except that gyp is used from python2 as the version in nixpkgs 20.03
refuses to work with python3.
2020-08-02 11:08:52 +02:00
Vladimír Čunát
6096bfbc48 nss_3_52: rename to nss_latest
That way the name can make sense without being changed often.
2020-08-02 10:11:10 +02:00
Vladimír Čunát
443d41f3bd firefox*-bin: pick updates to 20.03
/cc the last PR #94421.  I ran each for a minute or two.
2020-08-02 09:49:34 +02:00
taku0
b03ee28d80 firefox-bin: 78.0.2 -> 79.0
(cherry picked from commit 2409432f74)
2020-08-02 09:39:07 +02:00
adisbladis
7ccc77293b firefox-bin: 78.0.1 -> 78.0.2
(cherry picked from commit 29c38efa84)
2020-08-02 09:38:55 +02:00
adisbladis
87d40436d6 firefox-devedition-bin: 76.0b1 -> 79.0b7
(cherry picked from commit 8b893ecde1)
2020-08-02 09:38:22 +02:00
adisbladis
3826cd8de2 firefox-beta-bin: 79.0b2 -> 79.0b7
(cherry picked from commit e97bd70624)
2020-08-02 09:37:01 +02:00
adisbladis
fb917d05e0 firefox-bin: Work around bug in upstream SHA sums files
(cherry picked from commit 11acd8b30e)
2020-08-02 09:36:11 +02:00
adisbladis
3713d27d5f firefox-bin: Switch to sha256 sums in update scripts
There is no extra security properties provided by sha512, they are
just bigger.

(cherry picked from commit f84cd5f8aa)
2020-08-02 09:35:48 +02:00
taku0
f1dcf0a2b1 firefox-esr: 68.10.0.esr -> 68.11.0esr
(cherry picked from commit 9f5628da43)
Re-tested briefly on 20.03.  /cc PR #94421.
2020-08-02 09:29:54 +02:00
worldofpeace
7dc4385dc7 atom: Fix #92487
We rewrote the expression to use phases from genericBuilder.
https://github.com/NixOS/nixpkgs/issues/92487#issuecomment-654552010

(cherry picked from commit 35cb34cf27)
2020-08-01 20:46:21 -04:00
Martin Weinelt
fb378d52a9 Merge pull request #94458 from dotlambda/postfix-3.4.16
postfix: 3.4.14 -> 3.4.16
2020-08-01 21:56:38 +02:00
Robert Schütz
b1c42c4c2e postfix: 3.4.14 -> 3.4.16 2020-08-01 18:31:03 +02:00
Piotr Bogdan
f862ef5fe4 accountsservice: add patch for upstream issue #55
https://gitlab.freedesktop.org/accountsservice/accountsservice/-/issues/55
(cherry picked from commit b67e25bf89)
2020-07-31 23:38:58 -04:00
R. RyanTM
bfb78aaf0e pantheon.elementary-files: 4.4.3 -> 4.4.4
(cherry picked from commit 7319882162)
2020-07-31 23:38:58 -04:00
John Ericson
977000f149 Merge pull request #94392 from kmicklas/fix-gplates
[20.03] gplates: 2.0.0 -> 2.2.0, unbreak
2020-07-31 20:11:18 -04:00
Peter Simons
5d93c173ab Merge pull request #93940 from ggreif/ghc884-backport
[20.03] ghc: add new version 8.8.4
2020-07-31 21:30:54 +02:00
Maximilian Bosch
c9f5211b76 matrix-synapse: 1.17.0 -> 1.18.0
https://github.com/matrix-org/synapse/releases/tag/v1.18.0
(cherry picked from commit 835d36186d)
2020-07-31 14:23:47 +02:00
Maximilian Bosch
5f646ea531 Merge pull request #94309 from fadenb/graylog_3.3.3_backport
[20.03] graylog: 3.3.2 -> 3.3.3
2020-07-31 14:02:31 +02:00
Tristan Helmich (omniIT)
6a6cbf03d8 doc/rl-2003: Add warning on Graylog changes in version 3.3.3 2020-07-31 08:38:53 +00:00
Tristan Helmich (omniIT)
3de1ba01fd graylog: 3.3.2 -> 3.3.3
Bumps Graylog and integrations plugins to 3.3.3 which fixes CVE-2020-15813

(cherry picked from commit 1bb1b67087)

Reason: Security fix for CVE-2020-15813 (closes #94001)
2020-07-31 08:19:51 +00:00
Ivan Kozik
38516a273c hydra-unstable: 2020-06-23 -> 2020-07-28
This fixes the build:

```
config.status: creating hydra-config.h
config.status: executing depfiles commands
config.status: executing libtool commands
config.status: executing executable-scripts commands
building
build flags: -j8 -l8 SHELL=/nix/store/c4wxsn4jays9j31y5z9f83nr2cp7l4pa-bash-4.4-p23/bin/bash
make  all-recursive
make[1]: Entering directory '/build/source'
Making all in src
make[2]: Entering directory '/build/source/src'
Making all in hydra-evaluator
make[3]: Entering directory '/build/source/src/hydra-evaluator'
g++ -DHAVE_CONFIG_H -I. -I../..    -std=c++17 -I/nix/store/2xhb4hlskn33pbyph36v4wxcan56dnrw-boehm-gc-8.0.4-dev/include -I/nix/store/5rjgsqjdm71cflfb68q7m771a1rqcsk3-nix-2.4pre20200719_a79b6dd-dev/include/nix -Wall -I ../libhydra -Wno-deprecated-declarations -g -O2 -std=c++17 -include nix/config.h -c -o hydra_evaluator-hydra-evaluator.o `test -f 'hydra-evaluator.cc' || echo './'`hydra-evaluator.cc
hydra-evaluator.cc:27:27: error: template argument 1 is invalid
   27 |     std::unique_ptr<Config> config;
      |                           ^
hydra-evaluator.cc:27:27: error: template argument 2 is invalid
hydra-evaluator.cc: In constructor 'Evaluator::Evaluator()':
hydra-evaluator.cc:61:56: error: base operand of '->' is not a pointer
   61 |         , maxEvals(std::max((size_t) 1, (size_t) config->getIntOption("max_concurrent_evals", 4)))
      |                                                        ^~
hydra-evaluator.cc:60:44: error: invalid user-defined conversion from 'std::_MakeUniq<Config>::__single_object' {aka 'std::unique_ptr<Config, std::default_delete<Config> >'} to 'int' [-fpermissive]
   60 |         : config(std::make_unique<::Config>())
      |                  ~~~~~~~~~~~~~~~~~~~~~~~~~~^~
In file included from /nix/store/3krz9s8ni3bqy4hy35ycmq8assrrb4f6-gcc-9.3.0/include/c++/9.3.0/memory:80,
                 from /nix/store/d97d0wixvlprz59z57maqj1pmda55r3b-libpqxx-6.4.5/include/pqxx/binarystring.hxx:17,
                 from /nix/store/d97d0wixvlprz59z57maqj1pmda55r3b-libpqxx-6.4.5/include/pqxx/binarystring:4,
                 from /nix/store/d97d0wixvlprz59z57maqj1pmda55r3b-libpqxx-6.4.5/include/pqxx/pqxx:3,
                 from ../libhydra/db.hh:3,
                 from hydra-evaluator.cc:1:
/nix/store/3krz9s8ni3bqy4hy35ycmq8assrrb4f6-gcc-9.3.0/include/c++/9.3.0/bits/unique_ptr.h:374:16: note: candidate is: 'std::unique_ptr<_Tp, _Dp>::operator bool() const [with _Tp = Config; _Dp = std::default_delete<Config>]' <near match>
  374 |       explicit operator bool() const noexcept
      |                ^~~~~~~~
/nix/store/3krz9s8ni3bqy4hy35ycmq8assrrb4f6-gcc-9.3.0/include/c++/9.3.0/bits/unique_ptr.h:374:16: note:   return type 'bool' of explicit conversion function cannot be converted to 'int' with a qualification conversion
make[3]: *** [Makefile:440: hydra_evaluator-hydra-evaluator.o] Error 1
make[3]: Leaving directory '/build/source/src/hydra-evaluator'
make[2]: *** [Makefile:360: all-recursive] Error 1
make[2]: Leaving directory '/build/source/src'
make[1]: *** [Makefile:414: all-recursive] Error 1
make[1]: Leaving directory '/build/source'
make: *** [Makefile:344: all] Error 2
builder for '/nix/store/g967cc3j6rc3nnpx2s4klpr03ig9zzyp-hydra-2020-06-23.drv' failed with exit code 2
```

Closes #94141

(cherry picked from commit 0d7bdd6d8e)
2020-07-31 00:06:41 +02:00
Maximilian Bosch
3caee59ed9 linuxPackages.wireguard: 1.0.20200712 -> 1.0.20200729
https://lists.zx2c4.com/pipermail/wireguard/2020-July/005720.html
(cherry picked from commit 41f959293b)
2020-07-30 19:32:41 +02:00
Tim Steinbach
326767fd73 linux: 5.7.10 -> 5.7.11 2020-07-29 09:47:12 -04:00
Tim Steinbach
0fabe3d374 linux: 5.4.53 -> 5.4.54 2020-07-29 09:47:12 -04:00
Tim Steinbach
bcade58fcb linux: 4.19.134 -> 4.19.135 2020-07-29 09:47:12 -04:00
Tim Steinbach
5cfd5eb967 linux: 4.14.189 -> 4.14.190 2020-07-29 09:47:12 -04:00
Michael Weiss
b33ff917c6 chromium: 84.0.4147.89 -> 84.0.4147.105
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html

This update includes 8 security fixes.

CVEs:
CVE-2020-6537 CVE-2020-6538 CVE-2020-6532 CVE-2020-6539 CVE-2020-6540
CVE-2020-6541

(cherry picked from commit bf02beb099)
2020-07-28 13:55:03 -05:00
Tim Steinbach
2f3bec63d6 jenkins: 2.235.2 -> 2.235.3
(cherry picked from commit ed0ad5f792)
2020-07-28 10:00:10 -04:00
Maximilian Bosch
7c85b91589 element-desktop: 1.7.1 -> 1.7.2
https://github.com/vector-im/riot-desktop/releases/tag/v1.7.2
(cherry picked from commit ad75463531)
2020-07-28 14:24:23 +02:00
Maximilian Bosch
382dd49f07 element-web: 1.7.1 -> 1.7.2
https://github.com/vector-im/riot-web/releases/tag/v1.7.2
(cherry picked from commit 0da5788b27)
2020-07-28 14:24:22 +02:00
zowoq
eeb91b03a5 youtube-dl: 2020.06.16.1 -> 2020.07.28
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.07.28
(cherry picked from commit 1e2a59ef56)
2020-07-28 01:09:26 +02:00
Maximilian Bosch
274831839c nixUnstable: 2.4pre20200719_a79b6dd -> 2.4pre20200721_ff314f1
Fixes errors like this for me:

```
error: --- Error ------------------------------- nix-build
Nix daemon out of memory
(use '--show-trace' to show detailed location information)
```

(cherry picked from commit 85819d4bbf)
2020-07-27 13:19:14 +02:00
Eelco Dolstra
5e30b3af4f nixUnstable: 2.4pre7805_984e5213 -> 2.4pre20200719_a79b6dd
(cherry picked from commit 38880a5ec2)
2020-07-27 13:19:02 +02:00
Maximilian Bosch
91c9062877 Merge pull request #93773 from Ma27/element-20.03
[20.03] element-{web,desktop}: backport version bump & rename
2020-07-27 12:53:53 +02:00
Martin Weinelt
b50d55871f Merge pull request #93935 from symphorien/ihm-stable-update
[20.03] ihatemoney: fix CVE-2020-15120
2020-07-27 00:16:37 +02:00
Gabor Greif
7537b8b82f fixup for bootstrap GHC 2020-07-26 23:54:21 +02:00
Gabor Greif
94bba81cde [20.03] ghc: add new version 8.8.4
(cherry picked from commit dd6ce8c879)
2020-07-26 23:29:26 +02:00
Martin Weinelt
735df1a641 Merge pull request #93898 from uvNikita/backport/aiohue
[20.03] python: aiohue: 1.10.1 -> 2.1.0
2020-07-26 15:03:36 +02:00
Symphorien Gibol
0c36b32c11 python3Packages.ihatemoney: 4.1.4 -> 4.1.5
fixes CVE-2020-15120
2020-07-26 12:00:00 +00:00
Frederik Rietdijk
6d1823615a [20.03] python: aiohue: 1.10.1 -> 2.1.0
(cherry picked from commit 42abb50911)
2020-07-26 12:11:42 +02:00
Maximilian Bosch
477c36e0c3 element-web: warn about obsolete feature-flags 2020-07-26 11:59:54 +02:00
claudiiii
e75fdf0ac6 nixos/matrix-synapse: update documentation
(cherry picked from commit 2d468be964)
2020-07-26 11:59:54 +02:00
Maximilian Bosch
c7a15c19c7 riot-desktop: switch back to electron_8 for now
It used to work with this version and `electron_9` isn't available on
20.03.
2020-07-26 11:59:53 +02:00
R. RyanTM
076c67fdea tcpreplay: 4.3.2 -> 4.3.3 (security)
(cherry picked from commit 22ae4633c7)
Fixes CVE-2020-12740 and maybe some others are important:
https://github.com/appneta/tcpreplay/blob/4.3.3/docs/CHANGELOG
/cc roundup #90981.
2020-07-25 16:36:12 +02:00
Martin Weinelt
0a40a3999e Merge pull request #93608 from mweinelt/20.03/ansible
[20.03] ansible: v2.9.10 -> v2.9.11; ansible_2_8: v2.8.12 -> v2.8.13
2020-07-24 17:34:01 +02:00
claudiiii
33e2131d4f element-desktop, element-web: 1.7.0 -> 1.7.1
(cherry picked from commit 7c11d007cd)
2020-07-24 11:57:51 +02:00
claudiiii
02188cbd74 element-desktop, element-web: init at 1.7.0
(cherry picked from commit a705201e1d)
2020-07-24 11:57:23 +02:00
Martin Weinelt
afd465f00a Merge pull request #92844 from mmilata/20.03/samba-4.11.11
[20.03] samba: 4.11.9 -> 4.11.11
2020-07-23 23:19:51 +02:00
Jörg Thalheim
69af91469b Merge pull request #93471 from Lassulus/release-20.03 2020-07-23 19:47:19 +01:00
Vladimír Čunát
dfc0b3afdd Merge branch 'staging-20.03' into release-20.03 2020-07-23 16:19:16 +02:00
Domen Kožar
93a38cd098 Merge pull request #93687 from nh2/ghc-no-gold-20.03
[20.03] ghc: do not use ld.gold with musl libc
2020-07-23 06:24:16 +02:00
Adam Sandberg Ericsson
aea667b17b ghc: mention why ld.gold is disabled for musl libc
(cherry picked from commit 08a9d51699)
2020-07-23 03:47:06 +02:00
Adam Sandberg Ericsson
e8e92a8469 ghc: don't use ld.gold with musl libc (fixes #84670)
ld.gold doesn't play well with musl as is documented in #49071 and
https://sourceware.org/bugzilla/show_bug.cgi?id=23856

(cherry picked from commit 4675649d9c)
2020-07-23 03:47:06 +02:00
Yannis Koutras
1975b86874 mattermost-desktop: 4.5.0 -> 4.5.2 (#93668)
(cherry picked from commit 667b4b443c)
2020-07-22 19:52:47 -04:00
worldofpeace
297f3387c6 pantheon.appcenter: fix build
I believe I misunderstood some things greatly 😅️

(cherry picked from commit d74da4fe52)
2020-07-22 16:01:40 -04:00
Tim Steinbach
ac842446ad linux: 5.7.9 -> 5.7.10 2020-07-22 09:20:09 -04:00
Tim Steinbach
c8638d60b0 linux: 5.4.52 -> 5.4.53 2020-07-22 09:20:09 -04:00
Tim Steinbach
e88110c622 linux: 4.9.230 -> 4.9.231 2020-07-22 09:20:09 -04:00
Tim Steinbach
9df0203d41 linux: 4.4.230 -> 4.4.231 2020-07-22 09:20:09 -04:00
Tim Steinbach
dfe391a885 linux: 4.19.133 -> 4.19.134 2020-07-22 09:20:09 -04:00
Tim Steinbach
11167a8e90 linux: 4.14.188 -> 4.14.189 2020-07-22 09:20:09 -04:00
adisbladis
f8f311a42f linux: 5.7.8 -> 5.7.9
(cherry picked from commit 2004b0061b)
2020-07-22 09:20:00 -04:00
Vladimír Čunát
3302c4d841 Merge branch 'release-20.03' into staging-20.03
This merge is bringing really large amount of rebuilds :-/
   1939 x86_64-darwin
   9657 x86_64-linux
2020-07-22 08:45:34 +02:00
Martin Weinelt
29f57d2f81 ansible_2_8: v2.8.12 -> v2.8.13
https://github.com/ansible/ansible/blob/stable-2.8/changelogs/CHANGELOG-v2.8.rst#v2-8-13
(cherry picked from commit a9b3ff660da3e9fbe646f24bbe7caed0d1257ab9)
2020-07-21 21:14:32 +02:00
Martin Weinelt
ee1640dd52 ansible: v2.9.10 -> v2.9.11
https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#v2-9-11
(cherry picked from commit fe81c27f367e5322f79b7f17ed76e363c9913aa4)
2020-07-21 21:14:27 +02:00
Timo Kaufmann
9ea61f7bc4 Merge pull request #91162 from symphorien/backport-btrfs-scrub-success
[20.03] backport: nixos/btrfs autoScrub: don't fail when scrub finishes successfully
2020-07-21 20:51:29 +02:00
Maximilian Bosch
cbf3cb53dc grim: 1.3.0 -> 1.3.1
https://github.com/emersion/grim/releases/tag/v1.3.1
(cherry picked from commit cfcc630954)
2020-07-21 20:26:11 +02:00
Tad Fisher
a90a5c51a7 zoom-us: Link libfaac to fix audio recording (#93374)
Fixes #93341.

Using strace reveals that zoom is attempting to load "libfaac1.so" from
its PATH. As faac provides "libfaac.so.0", solve this by linking from
there to "libfaac1.so" in zoom's output.

This is the same solution as the one we use for libjpeg_turbo.

(cherry picked from commit 903a0cac04)
2020-07-21 12:24:07 -04:00
Maximilian Bosch
190e79d0f3 nextcloud: 19.0.0 -> 19.0.1
https://nextcloud.com/changelog/#19-0-1
(cherry picked from commit 2d543718fb)
2020-07-20 22:47:40 +02:00
Maximilian Bosch
c146535f13 oraclejdk: 8u251 -> 8u261
https://www.oracle.com/java/technologies/javase/8u261-relnotes.html
(cherry picked from commit c5dd1fba89)

Rationale for backport: as described in the release notes, this new
build-version is part of the "Critical Patch Update" of Oracle in July
2020[1]. Also, the zip archive for `8u251` isn't available anymore so users
can't build `oraclejdk` at the moment without having backed up the
`8u251` zipfile somewhere.

[1] https://www.oracle.com/security-alerts/cpujul2020.html#AppendixJAVA
2020-07-20 22:47:18 +02:00
Maximilian Bosch
d0cd75284b weechat*: remove myself as maintainer
I don't use this anymore, so I don't bring any value here.

(cherry picked from commit 309bcc4d09)
2020-07-20 22:44:57 +02:00
Silvan Mosberger
8fa3b978b4 Merge pull request #93550 from erictapen/haskell-streaming-osm-1.0.2
[20.03] haskellPackages.streaming-osm: 1.0.1 -> 1.0.2
2020-07-20 22:18:17 +02:00
Silvan Mosberger
d122741546 Merge pull request #93496 from davidak/backport-fontforge
[staging-20.03] fontforge: 20190413 -> 20200314
2020-07-20 20:58:47 +02:00
Justin Humm
4a9973a017 haskellPackages.streaming-osm: 1.0.1 -> 1.0.2
This fixes a bug in the parser, where member IDs in Openstreetmap files
were not correctly parsed.

This update significantly increases the usability of the package.
2020-07-20 20:41:18 +02:00
Alyssa Ross
99b72d2248 fontforge: 20190801 -> 20200314
This fixes the failing build.

Build system changed to cmake.

(cherry picked from commit e9848d11ad)
Reason: fixes CVE-2019-15785, CVE-2020-5395, CVE-2020-5496
2020-07-20 16:27:02 +02:00
Justin Humm
a7447ffc77 fontforge: 20190413 -> 20190801
- Init libuninameslist at 20190701 as it is a new dependency to fontforge
- Remove gnulib, as it is not used anymore
- Remove a non-applying patch
- Add myself as maintainer

(cherry picked from commit 4496f8f4b8)
2020-07-20 16:27:02 +02:00
aszlig
a674930d15 nixos/wireguard: Fix mismatched XML tag
Build error introduced in fe7053f75a:

  parser error : Opening and ending tag mismatch: commmand line 6139 and command
  escription><para>Base64 preshared key generated by <commmand>wg genpsk</command>
                                                                                 ^
Writing "command" with only two "m" fixes building the NixOS manual.

Signed-off-by: aszlig <aszlig@nix.build>
(cherry picked from commit 4e92b613cc)
2020-07-20 01:38:25 +01:00
Philipp Bartsch
df0e7ad3d6 nixos/wireguard: fix typos and unify formatting
(cherry picked from commit fe7053f75a)
2020-07-19 22:37:48 +01:00
taku0
f6e6a2915b flashplayer: 32.0.0.387 -> 32.0.0.403
(cherry picked from commit 65579d4bf8)
2020-07-19 10:56:51 -05:00
lassulus
5c56247b15 nixos-generators: 1.0.0 -> 1.1.0
(cherry picked from commit 3a47333f9f)
2020-07-19 14:32:22 +02:00
Symphorien Gibol
3cf6501aaa python3.pkgs.ihatemoney: 4.1 -> 4.1.4 2020-07-19 12:00:00 +00:00
worldofpeace
02d1989f8c Merge pull request #93115 from worldofpeace/nm-20.03-update
[20.03] networkmanager: 1.22.10 -> 1.22.14
2020-07-18 17:59:30 -04:00
Michael Weiss
bb8f0cc227 Merge pull request #93186 from primeos/chromium-backport
[20.03] chromium: 83.0.4103.116 -> 84.0.4147.89
2020-07-18 12:24:11 +02:00
Felix Tenley
8a5e6ede39 brave: 1.10.97 -> 1.11.97
(cherry picked from commit 0dd4c644af)
2020-07-17 21:43:21 -05:00
Felix Tenley
78c08f2acc brave: 1.8.95 -> 1.10.97
(cherry picked from commit e09a882e21)
2020-07-17 21:43:20 -05:00
Christian Mainka
f3c04316f6 brave: 1.7.92 -> 1.8.95
(cherry picked from commit e659bf3ce4)
2020-07-17 21:43:19 -05:00
Jeff Labonte
549410138b brave: 1.5.123 -> 1.7.92
(cherry picked from commit 094c35b920)
2020-07-17 21:43:18 -05:00
Jörg Thalheim
e7c435cbbd commitIdFromGitRepo: fix stackoverflow if many branches are used.
If many branches are created than builtins.match stack overflows because
of a bug in libstdc++: see https://github.com/NixOS/nix/issues/2147

(cherry picked from commit d7e89fa661)
2020-07-17 20:23:35 +02:00
Maximilian Bosch
b103b4bc62 matrix-synapse: 1.16.1 -> 1.17.0
https://github.com/matrix-org/synapse/releases/tag/v1.17.0
(cherry picked from commit 91f1d323e8)
2020-07-17 16:39:05 +02:00
Maximilian Bosch
dd78ac78c5 Merge pull request #93279 from tokudan/20.03.nextcloud1807
nextcloud: 18.0.6 -> 18.0.7 [20.03]
2020-07-17 16:34:20 +02:00
Tim Steinbach
360177f444 jenkins: 2.235.1 -> 2.235.2
(cherry picked from commit 223efd7b37)
2020-07-17 10:25:44 -04:00
Tim Steinbach
e8ef507d69 jenkins: 2.222.4 -> 2.235.1
(cherry picked from commit d1966f0860)
2020-07-17 10:25:30 -04:00
Tim Steinbach
2941c141ef jenkins: 2.222.3 -> 2.222.4
(cherry picked from commit f75d62941d)
2020-07-17 10:25:30 -04:00
Tim Steinbach
47aa88c695 jenkins: 2.222.1 -> 2.222.3
(cherry picked from commit f7b417440d)
2020-07-17 10:25:30 -04:00
Tim Steinbach
c423cca722 linux: 5.4.51 -> 5.4.52 2020-07-17 10:23:51 -04:00
Tim Steinbach
82401968ba linux: 4.19.132 -> 4.19.133 2020-07-17 10:23:51 -04:00
Maximilian Bosch
890f7af262 linuxPackages.wireguard: 1.0.20200623 -> 1.0.20200712
https://lists.zx2c4.com/pipermail/wireguard/2020-July/005639.html
(cherry picked from commit 2c275f8513)
2020-07-17 16:03:22 +02:00
Cole Mickens
aaa66d8d88 xdg-desktop-portal-gtk: add gnome-settings-daemon
This fixes "xdg-desktop-portal-gtk breaks font hinting".
Aka, nixos/nixpkgs#93199.

(cherry picked from commit 749418c6b4)
2020-07-16 21:02:55 -04:00
zowoq
76e92625e0 gitAndTools.gh: 0.10.1 -> 0.11.0
https://github.com/cli/cli/releases/tag/v0.11.0
(cherry picked from commit 2a45eea7e3)
2020-07-17 09:58:59 +10:00
zowoq
4cc800b2ba gitAndTools.gh: 0.10.0 -> 0.10.1
https://github.com/cli/cli/releases/tag/v0.10.1
(cherry picked from commit b2c8af46fc)
2020-07-17 09:58:48 +10:00
worldofpeace
619d8c0da0 Merge pull request #93114 from NixOS/gnome-20.03
[20.03] Gnome 3.34 updates (the sequel)
2020-07-16 16:38:32 -04:00
Daniel Frank
4f5fb2b2b3 nextcloud: 18.0.6 -> 18.0.7
(cherry picked from commit 34ec5c7b67)
2020-07-16 17:32:32 +02:00
worldofpeace
e78b7aa126 gtk3: update patches 2020-07-16 08:59:14 -04:00
Jonathan Ringer
2e5c1808b3 libsecret: remove obsolete patch
remove patch that was merged into the 0.20.1 patch.

regression introduced in c6a1e23eb7

(cherry picked from commit 35f00b429b)
2020-07-16 08:59:14 -04:00
worldofpeace
26ef93b868 cogl: drop old patch 2020-07-16 08:59:14 -04:00
worldofpeace
d7a350e27c libsecret: 0.20.0 -> 0.20.3 2020-07-16 08:59:14 -04:00
worldofpeace
3dd742586a gtk3: 3.24.18 -> 3.24.21 2020-07-16 08:59:13 -04:00
worldofpeace
3893b59bc8 glib-networking: 2.62.3 -> 2.62.4 2020-07-16 08:59:13 -04:00
worldofpeace
d769ff6f86 gjs: 1.58.6 -> 1.58.8 2020-07-16 08:59:13 -04:00
Mario Rodas
3e24c3ecc0 Merge pull request #92478 from samrose/fb20_03_update
fluent-bit: 1.3.6 -> 1.4.6
2020-07-16 06:54:21 -05:00
Lancelot SIX
76adfc180c pythonPackages.django: 2.2.13 -> 2.2.14
See https://docs.djangoproject.com/en/2.2/releases/2.2.14/ for release
information

(cherry picked from commit 9db754433c)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2020-07-16 08:27:37 +01:00
Sarah Brofeldt
6c3e37e5d2 Merge pull request #93224 from srhb/k8s-1.17.9
kubernetes: 1.17.8 -> 1.17.9
2020-07-16 09:15:46 +02:00
Sarah Brofeldt
86cbcb3ff2 kubernetes: 1.17.8 -> 1.17.9 2020-07-16 08:14:02 +02:00
worldofpeace
eb95a265d0 gexiv2: 0.12.0 -> 0.12.1 2020-07-15 14:30:03 -04:00
worldofpeace
4548430d37 cogl: 1.22.4 -> 1.22.8 2020-07-15 14:30:03 -04:00
worldofpeace
b299ce2360 clutter: 1.26.2 -> 1.26.4 2020-07-15 14:30:03 -04:00
worldofpeace
9921ec16b3 gnome3.iagno: 3.34.5 -> 3.34.8 2020-07-15 14:30:03 -04:00
worldofpeace
2b617db519 gnome3.gnome-nibbles: 3.34.2 -> 3.34.3 2020-07-15 14:30:02 -04:00
worldofpeace
74c6d7a867 gnome3.simple-scan: 3.34.4 -> 3.34.7 2020-07-15 14:30:02 -04:00
worldofpeace
a9068c92aa gnome3.rygel: 0.38.3 -> 0.38.4 2020-07-15 14:30:02 -04:00
worldofpeace
c5d806df57 gnome3.mutter: 3.34.5 -> 3.34.6 2020-07-15 14:30:02 -04:00
worldofpeace
e099a669a4 gnome3.gnome-initial-setup: 3.34.3 -> 3.34.6 2020-07-15 14:30:02 -04:00
worldofpeace
ef322888e9 gnome3.gnome-desktop: 3.34.5 -> 3.34.7 2020-07-15 14:30:02 -04:00
worldofpeace
2ab643a1db gnome3.gnome-control-center: 3.34.5 -> 3.34.6 2020-07-15 14:30:02 -04:00
worldofpeace
8fe78f8483 gnome3.baobab: 3.34.0 -> 3.34.1 2020-07-15 14:30:02 -04:00
worldofpeace
414c8e5503 gnome3.gnome-music: 3.34.5 -> 3.34.6 2020-07-15 14:30:02 -04:00
worldofpeace
22462acdd9 gnome3.gnome-getting-started-docs: 3.34.1 -> 3.34.2 2020-07-15 14:30:02 -04:00
worldofpeace
fb96add048 gnome3.accerciser: 3.34.5 -> 3.34.6 2020-07-15 14:30:02 -04:00
worldofpeace
551c8f38ef gnome-user-docs: 3.34.1 -> 3.34.2 2020-07-15 14:30:02 -04:00
worldofpeace
c04621c281 shotwell: 0.31.1 -> 0.31.2 2020-07-15 14:30:02 -04:00
worldofpeace
1304fc40c6 gnome-photos: 3.34.1 -> 3.34.2 2020-07-15 14:30:02 -04:00
Jan Tojnar
88d9fd28bc gom: 0.3.3 → 0.4
https://ftp.gnome.org/pub/GNOME/sources/gom/0.4/gom-0.4.news
(cherry picked from commit 2a5292313c)
2020-07-15 14:30:02 -04:00
worldofpeace
8dc1cc4b40 libpeas: 1.24.0 -> 1.24.1
(cherry picked from commit 8bf3b33cf2)
2020-07-15 14:30:02 -04:00
worldofpeace
3d3b1313b0 gtk3: 3.24.13 -> 3.24.18 2020-07-15 14:30:02 -04:00
worldofpeace
e0d46efffb glib: 2.62.4 -> 2.62.6
Final release in the 2.62.x stable series

https://gitlab.gnome.org/GNOME/glib/-/blob/2.62.6/NEWS
2020-07-15 14:30:02 -04:00
worldofpeace
72093330e1 gjs: 1.58.4 -> 1.58.6 2020-07-15 14:30:02 -04:00
worldofpeace
fe069c98e3 grilo: 0.3.11 -> 0.3.12
(cherry picked from commit 0def916454)
2020-07-15 14:30:02 -04:00
worldofpeace
6501ad94ad grilo-plugins: 0.3.10 -> 0.3.11
(cherry picked from commit 1e234806e1)
2020-07-15 14:30:02 -04:00
worldofpeace
8a41149047 libgdata: disable liboauth
See https://gitlab.gnome.org/GNOME/libgdata/issues/1

(cherry picked from commit b6b8a9ded2)
2020-07-15 14:30:02 -04:00
R. RyanTM
014f823beb libgdata: 0.17.11 -> 0.17.12
(cherry picked from commit b001273b59)
2020-07-15 14:30:02 -04:00
worldofpeace
d2d5b0298d libgee: 0.20.2 -> 0.20.3 2020-07-15 14:30:01 -04:00
worldofpeace
f4113b6b74 geocode-glib: 3.26.1 -> 3.26.2 2020-07-15 14:30:01 -04:00
worldofpeace
2fb313472a vte: 0.58.2 -> 0.58.3 2020-07-15 14:30:01 -04:00
worldofpeace
23204c349c libsoup: 2.68.3 -> 2.68.4 2020-07-15 14:30:01 -04:00
worldofpeace
ac62151324 totem-pl-parser: 3.26.4 -> 2.26.5 2020-07-15 14:30:01 -04:00
worldofpeace
da73ececa6 gnome3.tracker: 2.3.1 -> 2.3.4 2020-07-15 14:30:01 -04:00
worldofpeace
b5c93910de gnome3.tracker-miners: 2.3.1 -> 2.3.3 2020-07-15 14:30:01 -04:00
worldofpeace
a8d9ec140b networkmanager-openvpn: 1.8.10 -> 1.8.12 2020-07-15 14:30:01 -04:00
Michael Weiss
a902eddc26 google-chrome: Fix the EGL backend
(cherry picked from commit f05b67ec83)
2020-07-15 16:52:10 +02:00
Michael Weiss
d289c2195f chromium: 83.0.4103.116 -> 84.0.4147.89
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html

This update includes 38 security fixes.

CVEs:
CVE-2020-6510 CVE-2020-6511 CVE-2020-6512 CVE-2020-6513 CVE-2020-6514
CVE-2020-6515 CVE-2020-6516 CVE-2020-6517 CVE-2020-6518 CVE-2020-6519
CVE-2020-6520 CVE-2020-6521 CVE-2020-6522 CVE-2020-6523 CVE-2020-6524
CVE-2020-6525 CVE-2020-6526 CVE-2020-6527 CVE-2020-6528 CVE-2020-6529
CVE-2020-6530 CVE-2020-6531 CVE-2020-6533 CVE-2020-6534 CVE-2020-6535
CVE-2020-6536

(cherry picked from commit 8427eb7044)
2020-07-15 16:50:09 +02:00
Michael Weiss
dabbc5a560 Merge pull request #93172 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.34.3 -> 1.34.4
2020-07-15 13:33:07 +02:00
Michael Weiss
86357b34d8 signal-desktop: 1.34.3 -> 1.34.4
(cherry picked from commit 5d1064a212)
2020-07-15 12:51:56 +02:00
Mario Rodas
e69cfc351b Merge pull request #93123 from rnhmjoj/syncthing-20.03
[20.03] syncthing: 1.3.4 -> 1.6.1
2020-07-14 17:41:26 -05:00
Mario Rodas
dee67adf40 syncthing: 1.5.0 -> 1.6.1
(cherry picked from commit 056089e7b3)
2020-07-14 15:46:30 +02:00
Mario Rodas
ff02971cf0 syncthing: 1.4.2 -> 1.5.0
Changelog: https://github.com/syncthing/syncthing/releases/tag/v1.5.0
(cherry picked from commit 07f093fb35)
2020-07-14 15:19:17 +02:00
Mario Rodas
32498a7bc1 syncthing: 1.4.1 -> 1.4.2
Changelog: https://github.com/syncthing/syncthing/releases/tag/v1.4.2
(cherry picked from commit b3fbd22149)
2020-07-14 15:15:16 +02:00
Mario Rodas
14966af55b syncthing: 1.4.0 -> 1.4.1
Changelog: https://github.com/syncthing/syncthing/releases/tag/v1.4.1
(cherry picked from commit beeb70c857)
2020-07-14 15:14:48 +02:00
Mario Rodas
65eebab118 syncthing: 1.3.4 -> 1.4.0
Changelog: https://github.com/syncthing/syncthing/releases/tag/v1.4.0
(cherry picked from commit d27b2f842c)
2020-07-14 15:14:13 +02:00
worldofpeace
b061622bb5 networkmanager: 1.22.10 -> 1.22.14
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/blob/1.22.14/NEWS
2020-07-14 09:03:13 -04:00
Christian Kauhaus
1a92d0abfc Merge pull request #92890 from ehmry/nixos-20.03
[20.03] trojita: apply patch for CVE-2020-15047
2020-07-14 14:44:54 +02:00
worldofpeace
f43adfa039 gnome3.five-or-more: 3.32.0 -> 3.32.2 2020-07-14 08:24:20 -04:00
worldofpeace
ca3907b93b gnome3.nautilus: 3.34.2 -> 3.34.3 2020-07-14 08:24:19 -04:00
worldofpeace
6a961d5f7a gnome3.gnome-shell: 3.34.4 -> 3.34.5 2020-07-14 08:24:19 -04:00
worldofpeace
9f2f229eda gnome3.gnome-disk-utility: 3.34.4 -> 3.34.5 2020-07-14 08:24:19 -04:00
worldofpeace
b76158233d gnome3.gnome-desktop: 3.34.4 -> 3.34.5 2020-07-14 08:24:19 -04:00
worldofpeace
c1cbbf6f9e gnome3.gnome-control-center: 3.34.4 -> 3.34.5 2020-07-14 08:24:19 -04:00
worldofpeace
41b761ff80 gnome3.gnome-bluetooth: 3.34.0 -> 3.34.1 2020-07-14 08:24:19 -04:00
worldofpeace
7f9b768c68 gnome3.gnome-weather: 3.34.0 -> 3.34.2 2020-07-14 08:24:19 -04:00
worldofpeace
04605a2c82 gnome3.gnome-music: 3.34.4 -> 3.34.5 2020-07-14 08:24:19 -04:00
worldofpeace
c86b30d0b7 gnome3.file-roller: 3.32.4 -> 3.32.5 2020-07-14 08:24:18 -04:00
worldofpeace
cc62e4ac9b gnome3.accerciser: 3.34.4 -> 3.34.5 2020-07-14 08:24:18 -04:00
worldofpeace
55440620d2 shotwell: 0.31.0 -> 0.31.1 2020-07-14 08:24:18 -04:00
worldofpeace
d2ee0247ce Merge pull request #88208 from mmilata/20.03/openconnect-8.10
[20.03] openconnect: patch CVE-2020-12105 & CVE-2020-12823
2020-07-14 07:53:30 -04:00
Daniel Șerbănescu
b7709efc78 nautilus: 3.34.2 -> 3.34.3 2020-07-13 13:31:43 +02:00
Michele Guerini Rocco
add5529b3e Merge pull request #93025 from rnhmjoj/mutt-20.03
[20.03] mutt: 1.13.3 -> 1.14.6
2020-07-13 08:09:50 +02:00
worldofpeace
2f92f28334 Merge pull request #93020 from yurkobb/nixos-20.03-fix-audacity
[20.03] audacity: fix hash for replaced release tarball
2020-07-12 18:25:59 -04:00
rnhmjoj
1ddaf143f0 mutt: 1.13.3 -> 1.14.6 2020-07-12 23:36:20 +02:00
Yury Bulka
38c0a5954b audacity: fix hash for replaced release tarball
Initially the 2.3.3 release was based on the wrong commit by upstream,
later retagged (see [1]). This resulted in resulted in Audacity
complaining it is an alpha release.

This commit changes the hash to the fixed upstream tarball.

[1]: https://github.com/audacity/audacity/issues/421
2020-07-12 22:53:13 +03:00
Dennis Gosnell
674ab2dffa Merge pull request #92963 from srhb/droplambdaoverrides
[20.03]: haskellPackages.lambdabot: Drop broken overrides
2020-07-12 14:22:46 +09:00
Emery Hemingway
5fe4954ffb trojita: apply patch for CVE-2020-15047 2020-07-12 09:39:46 +05:30
Dylan Simon
09b9d4d612 texlive.bin: fix poppler compatibility patch urls (#91890)
(cherry picked from commit 4ab0be845d)
2020-07-11 17:21:08 -04:00
Sarah Brofeldt
cf63841c2c [20.03]: haskellPackages.lambdabot: Drop broken overrides 2020-07-11 23:13:25 +02:00
Federico Rampazzo
009c50976b PerconaToolkit: use shortenPerlShebang (#91921)
(cherry picked from commit ae16459305)
2020-07-11 17:08:29 -04:00
Maximilian Bosch
5ca87e2536 matrix-synapse: 1.15.2 -> 1.16.1
https://github.com/matrix-org/synapse/releases/tag/v1.16.0
https://github.com/matrix-org/synapse/releases/tag/v1.16.1
(cherry picked from commit 9deee36649)
2020-07-11 19:41:26 +02:00
Elis Hirwing
b2459a1510 php74: 7.4.7 -> 7.4.8
Changelog: https://www.php.net/ChangeLog-7.php#7.4.8
(cherry picked from commit 49316cca66)
2020-07-11 19:41:26 +02:00
Elis Hirwing
7c89d08943 php73: 7.3.19 -> 7.3.20
Changelog: https://www.php.net/ChangeLog-7.php#7.3.20
(cherry picked from commit ef4f6dba94)
2020-07-11 19:02:46 +02:00
Elis Hirwing
2dc7ead091 php72: 7.2.31 -> 7.2.32
Changelog: https://www.php.net/ChangeLog-7.php#7.2.32
(cherry picked from commit 86ed3bf578)
2020-07-11 19:02:03 +02:00
maralorn
41f0bae06b Merge pull request #92820 from mweinelt/20.03/wallabag
[20.03] wallabag: apply patches to add missing migrations in initial setup
2020-07-11 01:22:28 +02:00
Martin Milata
58f5c23823 openconnect: patch CVE-2020-12105 & CVE-2020-12823
- https://nvd.nist.gov/vuln/detail/CVE-2020-12105
- https://nvd.nist.gov/vuln/detail/CVE-2020-12823
2020-07-10 22:30:20 +02:00
Silvan Mosberger
68c599acd5 yarn2nix: Don't pass yarnNix to mkDerivation (#92856)
The generated yarnNix file doesn't need to be part of the mkDerivation.
And doing so prevents other platforms from reproducibly instantiating
it. With this change you can e.g. do

  darwinPkgs.yarn2nix.mkYarnPackage {
    # ...
    yarnNix = pkgs.yarn2nix.mkYarnNix {
      yarnLock = ./yarn.lock;
    };
  }

Which is a darwin derivation, but can still be instantiated reproducibly on Linux.

(cherry picked from commit 75ee18766a)
2020-07-10 19:09:42 +02:00
Andreas Rammhold
692c7b3690 Merge pull request #92850 from Mic92/zfs-backport
[20.03] zfs: 0.8.3 -> 0.8.4
2020-07-10 16:35:03 +02:00
Maximilian Bosch
cfde9cecff mautrix-whatsapp: 0.1.2 -> 0.1.3
https://github.com/tulir/mautrix-whatsapp/releases/tag/v0.1.3
(cherry picked from commit e43685ef7d)
2020-07-10 16:08:27 +02:00
Bas van Dijk
537e49eb3c Merge pull request #92845 from knl/ruamel-backport
ruamel: moved from bitbucket to sourceforge
2020-07-10 16:07:03 +02:00
adisbladis
fe0b300488 zfs: 0.8.3 -> 0.8.4
(cherry picked from commit 1b3825ebcb)
2020-07-10 14:57:22 +01:00
Dylan Simon
a8688c7b99 ruamel: quote urls, update ordereddict url
(cherry picked from commit 15a97f8d03)
2020-07-10 13:29:18 +02:00
Dylan Simon
7cc021257a ruamel: moved from bitbucket to sourceforge
(cherry picked from commit c3b5bdaba0)
2020-07-10 13:29:18 +02:00
Martin Milata
65881c6419 samba: 4.11.9 -> 4.11.11
Fixes:
* https://nvd.nist.gov/vuln/detail/CVE-2020-10730
* https://nvd.nist.gov/vuln/detail/CVE-2020-10745
* https://nvd.nist.gov/vuln/detail/CVE-2020-10760
* https://nvd.nist.gov/vuln/detail/CVE-2020-14303

Changes:
* https://www.samba.org/samba/history/samba-4.11.10.html
* https://www.samba.org/samba/history/samba-4.11.11.html
2020-07-10 12:28:09 +02:00
R. RyanTM
d2891652c5 chocolateDoom: 3.0.0 -> 3.0.1
(cherry picked from commit ea7fc409dd)
2020-07-10 03:18:45 -07:00
Alexandre-Xavier Labonté-Lamoureux
af92d300e2 chocolate-doom: 2.3.0 -> 3.0.0
(cherry picked from commit 134f200cef)
2020-07-10 03:18:45 -07:00
Martin Weinelt
15bc9d287e wallabag: apply patches to add missing migrations in initial setup
Fixes: https://github.com/wallabag/wallabag/issues/3662
(cherry picked from commit b07693e718)
2020-07-10 03:03:27 +02:00
Tim Steinbach
ccf92d9702 linux: 5.7.7 -> 5.7.8 2020-07-09 09:40:04 -04:00
Tim Steinbach
4c4b271906 linux: 5.4.50 -> 5.4.51 2020-07-09 09:40:04 -04:00
Tim Steinbach
105b998ec6 linux: 4.9.229 -> 4.9.230 2020-07-09 09:40:04 -04:00
Tim Steinbach
4c749a96ef linux: 4.4.229 -> 4.4.230 2020-07-09 09:40:04 -04:00
Tim Steinbach
a2e7765f1e linux: 4.19.131 -> 4.19.132 2020-07-09 09:40:04 -04:00
Tim Steinbach
89be529783 linux: 4.14.187 -> 4.14.188 2020-07-09 09:40:04 -04:00
Graham Christensen
6a00eba02a libvirtd: don't start libvirtd-tcp.socket by default
Per upstream:

> libvirtd-tcp.socket - the unit file corresponding to the TCP 16509
> port for non-TLS remote access. This socket should not be configured
> to start on boot until the administrator has configured a suitable
> authentication mechanism.

(cherry picked from commit 84ecbc9a19)
2020-07-08 19:52:06 -04:00
Graham Christensen
b1d87641a1 Merge pull request #92744 from flokli/20.03-tdesktop
tdesktop: 1.9.9 -> 2.1.0
2020-07-08 16:06:33 -04:00
Michael Weiss
5d68f77c86 tdesktop: 2.0.1 -> 2.1.0
(cherry picked from commit 03399906ec)
2020-07-08 20:53:25 +02:00
Michael Weiss
4b210ebb30 tdesktop: 1.9.21 -> 2.0.1 (#83790)
* tdesktop: 1.9.21 -> 2.0.0
* tdesktop: 2.0.0 -> 2.0.1

(cherry picked from commit 606baf03ba)
2020-07-08 20:53:25 +02:00
Michael Weiss
a666ff9a56 tdesktop: 1.9.14 -> 1.9.21 (#82806)
(cherry picked from commit 2b25d0e2a9)
2020-07-08 20:53:25 +02:00
Michael Weiss
1cad1b183a tdesktop: 1.9.13 -> 1.9.14
(cherry picked from commit 4af086aa94)
2020-07-08 20:53:25 +02:00
Michael Weiss
46c4d8859d tdesktop: 1.9.12 -> 1.9.13
(cherry picked from commit a59a557cf6)
2020-07-08 20:53:25 +02:00
Michael Weiss
6a322515f6 tdesktop: 1.9.9 -> 1.9.12
Note: I skipped the packaging of mapbox-variant for now.
(cherry picked from commit d0729f8323)
2020-07-08 20:53:25 +02:00
Michael Weiss
abd69cc13a tl-expected: init at 2019-11-11
This version is 5 commits ahead of version 1.0.0 because we need at
least one patch [0] that prevents CMake from trying to use Git to fetch
the already fetched submodule...
Also some files have the wrong formatting (CRLF line endings) which
makes the patching really messy. At this point is seems therefore better
to use the master version instead (1.0.0 is pretty broken regarding
CMake).

[0]: 0ca73ee30e

(cherry picked from commit 818628c53a)
2020-07-08 20:53:25 +02:00
Florian Klink
d57d32e4e1 Merge pull request #92637 from petabyteboy/feature/gitlab-12-10-14
[20.03] gitlab: 12.10.13 -> 12.10.14
2020-07-08 20:16:01 +02:00
worldofpeace
0cfa467f87 Merge pull request #92684 from worldofpeace/pantheon-updates-20.03
[20.03] Pantheon updates 2020-07-07
2020-07-08 02:40:50 -04:00
worldofpeace
579cdb89d9 pantheon.elementary-dock: 2020-02-28 -> 2020-06-11
(cherry picked from commit 420918e8e1)
2020-07-08 01:08:02 -04:00
worldofpeace
d5a4a82303 pantheon.pantheon-agent-polkit: 1.0.2 -> 1.0.3
https://github.com/elementary/pantheon-agent-polkit/releases/tag/1.0.3
(cherry picked from commit 3a23ca569f)
2020-07-08 01:08:02 -04:00
worldofpeace
fdd815515f pantheon.granite: 5.4.0 -> 5.5.0
https://github.com/elementary/granite/releases/tag/5.5.0
(cherry picked from commit 8af5dc509e)
2020-07-08 01:08:01 -04:00
worldofpeace
59d798ec61 pantheon.wingpanel-indicator-datetime: 2.2.4 -> 2.2.5
https://github.com/elementary/wingpanel-indicator-datetime/releases/tag/2.2.5
(cherry picked from commit e15fa82290)
2020-07-08 01:08:01 -04:00
worldofpeace
3e46575106 nixos/pantheon: update greeter whitelist to new wording
This was a simple non fatal deprecation.

https://github.com/elementary/wingpanel/pull/326
(cherry picked from commit eb3c53b4e9)
2020-07-08 01:08:00 -04:00
worldofpeace
93a3d2f188 pantheon.wingpanel: 2.3.1 -> 2.3.2
https://github.com/elementary/wingpanel/releases/tag/2.3.2
(cherry picked from commit 8557cc77ed)
2020-07-08 01:08:00 -04:00
worldofpeace
d7511a6864 pantheon.elementary-videos: 2.7.1 -> 2.7.2
https://github.com/elementary/videos/releases/tag/2.7.2
(cherry picked from commit 3da77587ee)
2020-07-08 01:07:59 -04:00
worldofpeace
e2a3caa678 pantheon.elementary-calendar: 5.0.5 -> 5.0.6
https://github.com/elementary/calendar/releases/tag/5.0.6
(cherry picked from commit efb60ca5cc)
2020-07-08 01:07:59 -04:00
worldofpeace
d622da56d7 pantheon.elementary-session-settings: 2019-11-12 -> 2020-06-11
(cherry picked from commit 0a392fa7c2)
2020-07-08 01:07:58 -04:00
worldofpeace
1919b1f310 pantheon.wingpanel-indicator-datetime: 2.2.2 -> 2.2.4
This release fixed the issue with the event dots, so we drop the patch from https://github.com/Dirli/wingpanel-indicator-datetime.
This is difficult because not all issues are fixed.

(cherry picked from commit 6bc80d599a)
2020-07-08 01:07:52 -04:00
worldofpeace
68264dc20e pantheon.elementary-session-settings: add g-s-d version mappings
Needed to have a correct pantheon.session gnome-session file.

(cherry picked from commit 53bea3717f)
2020-07-08 01:07:01 -04:00
worldofpeace
c90edd394b pantheon.elementary-session-settings: 5.0.3 -> 2019-11-12
So we can drop the meson.patch intree.

(cherry picked from commit 741313d01b)
2020-07-08 01:07:00 -04:00
worldofpeace
1f0e4434a9 pantheon.wingpanel-indicator-datetime: drop downstream patch 2020-07-08 01:05:27 -04:00
worldofpeace
dce17f4997 Merge pull request #92614 from oxalica/backport-20.03/typora
[20.03] typora: 0.9.73 -> 0.9.89
2020-07-07 17:08:48 -04:00
worldofpeace
7ce93dd3d2 Merge pull request #92610 from samuelgrf/fix-backport/plasma5-noto-rename
[20.03] nixos/plasma5: Noto Mono -> Noto Sans Mono
2020-07-07 17:04:02 -04:00
Milan Pässler
6be388625f gitlab: 12.10.13 -> 12.10.14
Security release: https://about.gitlab.com/releases/2020/07/06/critical-security-release-gitlab-13-1-3-released/
2020-07-07 22:15:07 +02:00
Jörg Thalheim
e0e2e4f2bc Merge pull request #92615 from matklad/backport 2020-07-07 20:33:04 +01:00
oxalica
39f0831d33 typora: 0.9.73 -> 0.9.89
(cherry picked from commit c886cb026c)
2020-07-08 02:05:29 +08:00
Jade Harley
7fb99d675a (rustup): (add zlib to rpath in rustup libraries)
(Rust now has a dynamic library dependence on zlib. (see https://github.com/rust-lang/rust/pull/72696))
2020-07-07 20:00:36 +02:00
Samuel Gräfenstein
a47a25d1ca nixos/plasma5: Noto Mono -> Noto Sans Mono
The font has been renamed.
See https://github.com/googlefonts/noto-fonts/pull/1029

(cherry picked from commit 82cf1d9dcd)
2020-07-07 19:46:14 +02:00
Shea Levy
6f7e39c768 setupcfg2nix: Bump to 2.0.1.
Fixes #83814

(cherry picked from commit 0a7c10f701)
2020-07-07 09:29:04 -04:00
Florian Klink
c9d124e39d Merge pull request #92514 from petabyteboy/feature/gitlab-12-10-13-backport
[20.03] gitlab: 12.10.11 -> 12.10.13
2020-07-07 12:32:11 +02:00
Domen Kožar
0b0ab14a07 nix-linter: keep the closure small
(cherry picked from commit 3734ac9160)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-07-07 10:59:03 +02:00
Christian Kauhaus
02a83b10c6 Merge pull request #92160 from ckauhaus/sqlite-cves-20.03
[20.03] sqlite: 3.32.2 -> 3.32.3
2020-07-07 09:34:37 +02:00
Milan Pässler
add2c229c8 gitlab: 12.10.11 -> 12.10.13 2020-07-07 00:11:39 +02:00
samrose
023042cd26 fluent-bit: 1.3.6 -> 1.4.6 2020-07-06 13:05:13 -04:00
Dennis Gosnell
02203c1954 Merge pull request #91999 from circuithub/support-ghc-8.10-on-nixos-20.03
haskellPackages.ghcWithPackages: fix for GHC 8.10
2020-07-06 21:54:32 +09:00
Guillaume Bouchard
a078182158 haskellPackages.ghcWithPackages: fix for GHC 8.10
This closes #79441.

ghcWithPackages is using `ghc-pkg recache` to build its package
database. By doing so, it overrides the `package.cache[.lock]` files.

Details are unclear, but GHC 8.10 changed a bit the behavior.
Previously, it was unconditionally replacing the files by new ones. Now
it tries to open (for modification) the files. These files are symlinks
to another nix derivation, which is hence read-only.

This commit removes the files before running `ghc-pkg recache`, hence it
will just write the new files.

Tested with `haskellPackages.ghcWithPackages` (i.e. GHC 8.8) and
`haskell.packages.ghc8101.ghcWithPackages` (i.e GHC 8.10) with the
following nix file, at the root of the nixpkgs repository:

```
with import ./. {
  overlays = [
    (
      self: super: {
        haskellPackages = super.haskell.packages.ghc8101.override {
          overrides = selfh: superh: {
             th-lift-instances = super.haskell.lib.doJailbreak superh.th-lift-instances;
             th-expand-syns    = super.haskell.lib.doJailbreak superh.th-expand-syns;
             th-reify-many     = super.haskell.lib.doJailbreak superh.th-reify-many;
             th-orphans        = super.haskell.lib.doJailbreak superh.th-orphans;
             haskell-src-meta  = super.haskell.lib.doJailbreak superh.haskell-src-meta;
          };
        };
      }
  )
  ];
};
haskellPackages.ghcWithPackages(p:[p.PyF])
```

This will test with GHC 8.10. Comment out the `overlays` to test with
GHC 8.8.

(cherry picked from commit abc4f961b4)
2020-07-06 12:57:11 +01:00
Benjamin Hipple
41aa2272fe Merge pull request #91041 from alexfmpe/backport-tendermint-0.32.10
[20.03] tendermint: 0.32.3 -> 0.32.10 for security fixes
2020-07-05 19:44:05 -04:00
Maximilian Bosch
1d56d73aec roundcube: 1.4.6 -> 1.4.7
https://github.com/roundcube/roundcubemail/releases/tag/1.4.7
(cherry picked from commit d4cf52c414)
2020-07-05 23:39:15 +02:00
Daniël de Kok
74f2559a69 crispyDoom: fixed CVE-2020-14983 (#92358)
(cherry picked from commit 2d24b8b187)

Co-authored-by: Sage Raflik <neonfuz@gmail.com>
2020-07-05 16:24:35 -04:00
ajs124
b008a0505a firefox-esr-68: 68.9.0esr -> 68.10.0esr (PR #92043)
(cherry picked from commit 1f02e09a2c)
Briefly re-tested also on 20.03.
2020-07-05 17:53:59 +02:00
ajs124
be00753838 firefox-beta-bin: 76.0b8 -> 79.0b2 (PR #92043)
(cherry picked from commit 84cb46a37b)
Briefly re-tested also on 20.03; not sure if people use this combination.
2020-07-05 16:41:28 +02:00
ajs124
b705ed44a3 firefox-bin: 77.0.1 -> 78.0.1 (PR #92043)
(cherry picked from commit 48a2ea4d39)
Briefly re-tested also on 20.03.
2020-07-05 16:30:47 +02:00
Maximilian Bosch
afa9ca6192 iwd: 1.7 -> 1.8
https://git.kernel.org/pub/scm/network/wireless/iwd.git/tree/ChangeLog?h=1.8
(cherry picked from commit 77ffd8d5e0)
2020-07-05 02:33:58 +02:00
Maximilian Bosch
88b7aeddbf ell: 0.31 -> 0.32
https://git.kernel.org/pub/scm/libs/ell/ell.git/tree/ChangeLog?h=0.32
(cherry picked from commit 8683ac07d6)
2020-07-05 02:33:57 +02:00
Ioannis Koutras
75e0bd3a6e mattermost-desktop: 4.3.1 -> 4.5.0
(cherry picked from commit a2cdd1464b)
2020-07-04 16:42:07 -04:00
Maximilian Bosch
519151fda0 mautrix-whatsapp: 0.1.1 -> 0.1.2
https://github.com/tulir/mautrix-whatsapp/releases/tag/v0.1.2
(cherry picked from commit 8842a387ef)
2020-07-04 18:40:15 +02:00
Jörg Thalheim
9f48aa9aed Merge pull request #92230 from Mic92/teams-backport 2020-07-04 08:37:00 +01:00
devhell
97f8181843 teams: 1.3.00.5152 -> 1.3.00.16851
Microsoft finally released a new version for Linux.

(cherry picked from commit 6450f9e162)
2020-07-03 23:00:11 +01:00
Olli Helenius
5f739b6131 teams: 1.3.00.958 -> 1.3.00.5153
(cherry picked from commit 898a3bf006)
2020-07-03 23:00:08 +01:00
Chuck
f761c14fd2 nixos/test-driver: Specify /bin/sh shell when running a bourne shell script as the user
(cherry picked from commit 751a27020e)

Reason: Back-porting this straight-forward fix is the best way to
allow tests affected by this user-shell problem to run in 20.03.
There isn't a great override point to apply just this fix.  Copy/pasting
testing-python.nix just to specify a new test-driver.py isn't great --
it would cut off receiving any other fixes in the testing infrastructure
until 20.09.  A 20.03 system using testing-python.nix from the unstable
branch and then passing 20.03's pkgs in to avoid getting unstable's
pkgs is quite a bit of configuration to expect from clients and seems
fragile against future changes in the unstable branch that expect pkgs
to be mostly in-sync with the test driver.  Both of these not-great
options leave a bunch of "TODO: Remove after 20.09" junk in clients'
configs & make that upgrade harder.
2020-07-03 12:42:38 -07:00
R. RyanTM
c2eca91005 graylog: 3.3.1 -> 3.3.2
(cherry picked from commit dcf20331cf)
2020-07-03 19:34:34 +02:00
Robert Schütz
e497cff1c5 postfix: 3.4.13 -> 3.4.14 (#91772) 2020-07-03 12:57:07 +02:00
Christian Kauhaus
a7ce72418b sqlite: 3.32.2 -> 3.32.3
Fixes:

CVE-2019-19242
CVE-2019-19244
CVE-2019-19317
CVE-2019-19603
CVE-2019-19645
CVE-2019-19646
CVE-2019-19880
CVE-2019-19923
CVE-2019-19924
CVE-2019-19925
CVE-2019-19926
CVE-2019-19959
CVE-2019-20218
CVE-2020-9327
CVE-2020-11655
CVE-2020-11656
CVE-2020-13434
CVE-2020-13435
CVE-2020-13630
CVE-2020-13631
CVE-2020-13632
CVE-2020-13871
CVE-2020-15358

Re #92072, #90989, #88403, #88401, #88400, #77944, #92063, #90990
2020-07-03 12:24:53 +02:00
Christian Kauhaus
d6260a33e4 Merge pull request #91099 from xfix/vulnix-unbreak
[20.03] Unbreak zconfig and zodb
2020-07-03 12:13:31 +02:00
Maximilian Bosch
de02ce9dde Merge pull request #92101 from tokudan/2003-synapse-1152
matrix-synapse: 1.15.1 -> 1.15.2 [security]
2020-07-03 01:00:55 +02:00
Daniel Frank
8365941177 matrix-synapse: 1.15.1 -> 1.15.2 [security]
(cherry picked from commit e5c4f3777f)
2020-07-03 00:20:48 +02:00
Fabian Hauser
4d9dcce84d owncloud-client: add libsecret dependency
The libsecret dependency is required to access secrets from the gnome keychain.

(cherry picked from commit cf0552de9b)
2020-07-02 23:14:47 +02:00
R. RyanTM
ba7a81a0f3 freerdp: 2.1.1 -> 2.1.2
(cherry picked from commit b30ecf06de)
2020-07-02 19:40:05 +02:00
Linus Heckemann
d695d9bd0f freerdp: 2.1.0 -> 2.1.1
(cherry picked from commit ed73bb8d80)
2020-07-02 19:39:59 +02:00
Sarah Brofeldt
1af265513b Merge pull request #91989 from srhb/backport-ceph-14.2.10
[20.03] ceph: 14.2.9 -> 14.2.10
2020-07-02 17:56:54 +02:00
Martin Milata
e1afc39b48 libreswan: 3.31 -> 3.32
Changes: https://github.com/libreswan/libreswan/releases/tag/v3.32

Fixes: https://nvd.nist.gov/vuln/detail/CVE-2020-1763
(cherry picked from commit d0cb57b10c)
2020-07-02 16:38:37 +02:00
Philipp Riegger
b5120fe6a0 sane-backends: 1.0.28 -> 1.0.30
(cherry picked from commit 03690ba290)
2020-07-02 15:50:04 +02:00
Sarah Brofeldt
b1a39c0e84 [20.03] ceph: 14.2.9 -> 14.2.10
Add new dependency on rdkafka
Also removed now-obsolete cve patch as it's integrated already

(cherry picked from commit a1f6898192)
Backport of #91919
2020-07-02 07:21:00 +02:00
Tim Steinbach
9a3e34ae60 linux: 5.7.6 -> 5.7.7 2020-07-01 16:37:48 -04:00
Tim Steinbach
bf59e15204 linux: 5.4.49 -> 5.4.50 2020-07-01 16:37:47 -04:00
Tim Steinbach
ead3c71b11 linux: 4.9.228 -> 4.9.229 2020-07-01 16:37:46 -04:00
Tim Steinbach
17d2195b35 linux: 4.4.228 -> 4.4.229 2020-07-01 16:37:45 -04:00
Tim Steinbach
b91ee380bb linux: 4.19.130 -> 4.19.131 2020-07-01 16:37:44 -04:00
Tim Steinbach
065fd73de9 linux: 4.14.186 -> 4.14.187 2020-07-01 16:37:43 -04:00
Jan Tojnar
6e560f80fc Merge pull request #91901 from lourkeur/fix_91710 2020-07-01 16:53:48 +02:00
Michael Raitza
21f176a8b2 openafs: 1.6.23 -> 1.6.24
Security fixes.

Ref #90927
2020-07-01 15:06:53 +02:00
Jörg Thalheim
f1a79c8635 Merge pull request #91867 from andersk/openafs-20.03
[20.03] openafs_1_8: 1.8.5 -> 1.8.6
2020-07-01 09:17:07 +01:00
Mario Rodas
038a87ee11 Merge pull request #91898 from maxeaubrey/vault_20.03_1.3.6
[20.03] vault: 1.3.2 -> 1.3.6
2020-06-30 22:30:22 -05:00
R. RyanTM
630c219e9b targetcli: 2.1.51 -> 2.1.53
(cherry picked from commit cf47dc9f7b)
2020-06-30 19:50:23 -05:00
Louis Bettens
214d063d1a yaru-theme: fix #91710 2020-07-01 01:12:37 +02:00
Profpatsch
0023aaef48 lorri: 1.0 -> 1.1 2020-07-01 01:12:29 +02:00
Maxine E. Aubrey
a1a8e7b021 vault: 1.3.2 -> 1.3.6
Fixes CVE-202-10661, CVE-2020-13223, CVE-2020-10660
Closes #91022
2020-07-01 00:43:20 +02:00
Tim Steinbach
30fb4e1e20 linux: 5.8-rc1 -> 5.8-rc2
(cherry picked from commit 467fdc71e5)
2020-06-30 17:29:02 -04:00
Anders Kaseorg
ec3103e3f3 openafs_1_8: 1.8.5 -> 1.8.6
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
2020-06-30 10:29:44 -07:00
Sarah Brofeldt
244286efbc Merge pull request #91769 from maxeaubrey/nomad_20.03_0.10.5
[20.03] nomad: 0.10.2 -> 0.10.5
2020-06-29 23:24:28 +02:00
Maxine E. Aubrey
9e30519c58 nomad: 0.10.2 -> 0.10.5 2020-06-29 23:08:13 +02:00
Sarah Brofeldt
17e83aaa58 Merge pull request #91093 from ckauhaus/88387-fix-qemu-CVE-2020-1711
[20.03] qemu: patch CVE-2020-1711
2020-06-29 22:11:05 +02:00
Maximilian Bosch
560e3b7d9d riot-web: 1.6.6 -> 1.6.7
https://github.com/vector-im/riot-web/releases/tag/v1.6.7
(cherry picked from commit 260003b26c)
2020-06-29 19:51:40 +02:00
Maximilian Bosch
11b5bde1d9 riot-desktop: 1.6.6 -> 1.6.7
https://github.com/vector-im/riot-desktop/releases/tag/v1.6.7
(cherry picked from commit 27362a6a66)
2020-06-29 19:51:40 +02:00
Maximilian Bosch
062362bdc6 epson-escpr2: 1.1.12 -> 1.1.13
(cherry picked from commit 9884165283)
2020-06-29 19:51:39 +02:00
Niklas Hambüchen
1cf3affc16 Merge pull request #91522 from wamserma/libtomcrypt-cve-2019-17362-backport
[20.03] libtomcrypt: fix CVE-2019-17362 (security, backport)
2020-06-29 13:46:11 +02:00
Tim Steinbach
c5299e9d5b linux_latest-libre: 17402 -> 17537
(cherry picked from commit 3cf2f4d6a3)
I didn't bother to reference each small update on master (just the last).
2020-06-28 18:10:52 +02:00
Vladimír Čunát
ff1b66eaea Merge branch 'staging-20.03' into release-20.03 2020-06-28 11:04:18 +02:00
Aaron Andersen
f82e9b88c9 Merge pull request #91280 from aanderse/moodle
moodle: 3.8.2 -> 3.8.3 [20.03 backport]
2020-06-27 21:08:25 -04:00
Niklas Hambüchen
b82f8b3a71 Merge pull request #91664 from wamserma/bump-libvncserver-20.03
[20.03] libvncserver: 0.9.12 -> 0.9.13 (security, backport)
2020-06-28 02:26:04 +02:00
Dmitry Kalinkin
d69aa0cccb Merge pull request #91633 from txt-file/release-20.03
[20.03] backport nvidia driver updates
2020-06-27 16:48:10 -04:00
Mario Rodas
d2eeac149d Merge pull request #91470 from nomeata/release-20.03
openssh: don’t include fido2 on musl
2020-06-27 13:36:42 -05:00
Sarah Brofeldt
b28be19c9a Merge pull request #91669 from johanot/kubernetes-1.17.8
kubernetes: 1.17.5 -> 1.17.8
2020-06-27 18:36:37 +02:00
Johan Thomsen
0c74b2f470 kubernetes: 1.17.5 -> 1.17.8 2020-06-27 17:29:31 +02:00
Sergey Lukjanov
b3d20c3d50 docker: use git tags instead of revs
(cherry picked from commit afc8bd6a7b)
2020-06-27 16:02:19 +02:00
Sergey Lukjanov
0c486cfadc docker: 19.03.11 -> 19.03.12
(cherry picked from commit fcede31c25)
2020-06-27 16:02:18 +02:00
Pavol Rusnak
63bd666c8f keepassxc: 2.5.2 -> 2.5.4
+ disabled testcli flaky test

(cherry picked from commit e353fe89db)
2020-06-27 14:00:48 +02:00
Jörg Thalheim
20c4330038 linuxPackages.sysdig: 0.26.6 -> 0.26.7
(cherry picked from commit 330693c502)
2020-06-27 14:00:48 +02:00
Jörg Thalheim
40eaa8fb8d sysdig: 0.26.5 -> 0.26.6
(cherry picked from commit 748f8b725c)
2020-06-27 14:00:48 +02:00
Markus S. Wamser
8fbacd2c89 libvncserver: 0.9.12 -> 0.9.13 (security)
(cherry picked from commit 74c27221dd)
2020-06-27 13:20:00 +02:00
Michael Weiss
fb35d792b8 Merge pull request #91590 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.34.2 -> 1.34.3
2020-06-27 00:11:51 +02:00
Sarah Brofeldt
67d0406c5e Merge pull request #91610 from mweinelt/20.03/ceph
[20.03] ceph: apply patch for CVE-2020-10753
2020-06-27 00:01:03 +02:00
Edmund Wu
69cce691ac nvidia_x11: 440.82 -> 440.100
(cherry picked from commit 3077af4fe6)
2020-06-26 22:13:25 +02:00
Edmund Wu
f23eee9c7a nvidia_x11.legacy_390: 390.132 -> 390.138
(cherry picked from commit 7664689009)
2020-06-26 22:13:12 +02:00
Edmund Wu
ae6ebbec4a nvidia_x11.legacy_340: 340.107 -> 340.108
(cherry picked from commit 34f19eacb3)
2020-06-26 22:12:59 +02:00
Maximilian Bosch
5b5b3176a0 linuxPackages.wireguard: 1.0.20200611 -> 1.0.20200623
https://lists.zx2c4.com/pipermail/wireguard/2020-June/005597.html
(cherry picked from commit 053db07ba7)
2020-06-26 18:58:58 +02:00
Maximilian Bosch
43b480d8a9 cargo-make: 0.31.0 -> 0.31.1
https://github.com/sagiegurari/cargo-make/releases/tag/0.31.1
(cherry picked from commit 2101f7361c)
2020-06-26 17:13:57 +02:00
Maximilian Bosch
0dde2ec15b neomutt: 20200619 -> 20200626
https://github.com/neomutt/neomutt/releases/tag/20200626
(cherry picked from commit da1b17fd35)
2020-06-26 15:49:44 +02:00
Martin Weinelt
bf210d8076 ceph: apply patch for CVE-2020-10753
Fixes: CVE-2020-10753
(cherry picked from commit f76a83c2c6)
2020-06-26 15:40:50 +02:00
Tim Steinbach
cce092c123 linux: 4.19.129 -> 4.19.130 2020-06-26 08:37:01 -04:00
Tim Steinbach
ee774dba86 linux: 4.14.185 -> 4.14.186 2020-06-26 08:37:01 -04:00
Michael Weiss
81ddbc4109 signal-desktop: 1.34.2 -> 1.34.3
(cherry picked from commit fdfa609ae9)
2020-06-26 12:52:18 +02:00
regnat
3354468085 termdown: Add a simple test
Just ensures that the program starts correctly with sensible parameters
2020-06-26 09:27:53 +02:00
regnat
94ae3f10f3 termdown: Add a missing dependency on setuptools 2020-06-26 09:17:33 +02:00
Harsh Shandilya
0ba9fdc1e8 rtl8821ce: 5.2.5_1.26055.20180108 -> 5.5.2_34066.20200325
The rtl8821ce repository was updated to address for ABI changes to
Linux but our package was too far behind, resulting in breakages
as reported in #88068

Fixes: #88068
(cherry picked from commit 6cbbe4dbba)
2020-06-25 21:40:06 -05:00
Martin Weinelt
4c8a1df380 wordpress: add passthru.tests
(cherry picked from commit f422d6582d)
2020-06-25 18:09:37 -07:00
Martin Weinelt
3c24d54831 wordpress: 5.3.3 -> 5.3.4
Fixes: CVE-2020-4049
Closes: #91304
2020-06-25 18:09:37 -07:00
Markus S. Wamser
05c444144b libtomcrypt: fix CVE-2019-17362 (security)
(cherry picked from commit 5f16eca72b)
2020-06-26 00:05:32 +02:00
Maximilian Bosch
1517b764c2 Merge pull request #91496 from ckauhaus/secfix-php-20.03
[20.03] php: 7.2.29 -> 7.2.31, 7.3.16 -> 7.3.19, 7.4.6 -> 7.4.7
2020-06-25 18:21:18 +02:00
Tim Steinbach
46c4fbd607 linux: 5.7.5 -> 5.7.6
(cherry picked from commit 06f0a0fc27)
2020-06-25 10:32:13 -04:00
Tim Steinbach
c1f9fb3edc linux: 5.7.4 -> 5.7.5
(cherry picked from commit c4a784bbf4)
2020-06-25 10:32:13 -04:00
Tim Steinbach
b879e5a05a linux: 5.4.48 -> 5.4.49
(cherry picked from commit 5d807cc8d7)
2020-06-25 10:31:14 -04:00
Christian Kauhaus
6da23f1071 php: 7.2.29 -> 7.2.31, 7.3.16 -> 7.3.19, 7.4.6 -> 7.4.7
Security and bugfix updates for PHP.

Fixes #88380, #88379, #90939, #90921, #90924, #88382

See #91495 for PR against master.
2020-06-25 16:24:00 +02:00
Christian Kauhaus
3dbed6106d Merge pull request #91402 from danieldk/mp4v2
[20.03] mp4v2: 2.0.0 -> 4.1.3
2020-06-25 15:57:50 +02:00
Michael Weiss
41add65fb9 Merge pull request #91427 from primeos/chromium-backport
[20.03] chromium: 83.0.4103.106 -> 83.0.4103.116 (backport)
2020-06-25 15:07:07 +02:00
Martin Weinelt
f31e60277a pythonPackages.django2_2: 2.2.11 -> 2.2.13
Fixes: CVE-2020-13254, CVE-2020-13596
(cherry picked from commit b2da714180)
2020-06-25 13:08:28 +01:00
Peter Simons
4f0e402328 django: update version 2.2.10 to 2.2.11
(cherry picked from commit abd30ff776)
2020-06-25 13:08:18 +01:00
Matthew Bauer
ec75f82587 openssh: don’t include fido2 on musl
libselinux pulls in openssh transitively, so can’t use fido here

Fixes #89246

(cherry picked from commit 59616b291d)
2020-06-25 09:45:28 +02:00
Jörg Thalheim
3f21f10818 Merge pull request #86999 from mweinelt/20.03/pr/wolfssl 2020-06-25 06:23:26 +01:00
Martin Weinelt
29f44d005e wolfssl: v4.3.0 -> v4.4.0
Fixes: CVE-2020-11713
(cherry picked from commit 6baa4e74bf)
2020-06-25 00:24:25 +02:00
Maximilian Bosch
f8248ab6d9 hydra-unstable: 2020-06-01 -> 2020-06-23
Fixes the build the changes from b505bf202b.

(cherry picked from commit 39e3c15706)
2020-06-24 23:29:06 +02:00
Dmitry Kalinkin
f2cdade6c8 texlive: fix build for scheme-infraonly
(cherry picked from commit 8852a81022)
2020-06-24 16:55:20 -04:00
Andrew Childs
1b9ed4ff24 chromium: 83.0.4103.106 -> 83.0.4103.116
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_22.html

This update includes 2 security fixes.

CVEs: CVE-2020-6509
(cherry picked from commit 46f11f53c9)
2020-06-24 19:49:00 +02:00
Atemu
6460602eec gns3-gui: Add the missing qt5Full runtime dependency
qt5Full may not be installed on users' systems and the gns3-gui depends
on it explicitly.
Note: This also fixes e.g. "nix-shell -p gns3-gui --pure" (at the cost
of an increased closure size).

(cherry picked from commit 0eaec4dee2)
Reason: This is a fix for possible runtime crashes.
2020-06-24 19:32:57 +02:00
Vladimír Čunát
5e6916fbfe Merge branch 'release-20.03' into staging-20.03 2020-06-24 17:37:05 +02:00
Vladimír Čunát
aa5c7269e5 Merge #91408: curl: 7.68.0 -> 7.70.0 + patches
... into staging-20.03.  CVE-2020-8169 and CVE-2020-8177.
2020-06-24 17:29:49 +02:00
Martin Weinelt
039c3c9ea7 curl: apply patches for CVE-2020-8169 and CVE-2020-8177 2020-06-24 17:17:35 +02:00
zowoq
2599ba387f pcre: 8.43 -> 8.44
https://lists.exim.org/lurker/message/20200212.174850.6edd8277.en.html
(cherry picked from commit 4f97819812)

Fixes: CVE-2020-14155
Closes: #91311
2020-06-24 16:34:44 +02:00
Peter Hoeg
f1693d6cd5 curl: 7.69.1 -> 7.70.0
(cherry picked from commit 9efd23e64d)
2020-06-24 15:45:57 +02:00
R. RyanTM
9188171584 curl: 7.68.0 -> 7.69.1
(cherry picked from commit e4df9d6b54)
2020-06-24 15:45:19 +02:00
Anton-Latukha
78e2687dec mp4v2: 2.0.0 -> 4.1.3
Switch into maintanable fork. It is the community central fork.

Remove old patch, use new minor upstream patch to compile.

I weighted-in on the patch reasoning to be merged.

Strictify hardening.

Documentation update

M  pkgs/development/libraries/mp4v2/default.nix

(cherry picked from commit c281c84a1e)
2020-06-24 13:06:19 +02:00
Lancelot SIX
390742eb13 qgis: 3.10.4 -> 3.10.7
(cherry picked from commit 3bdefc8802)
2020-06-24 08:36:00 +01:00
Vladimír Čunát
4143654d6e Merge branch 'staging-20.03' into release-20.03
Most has been rebuilt already.  More waiting would increase the total
number of rebuilds done.
2020-06-23 23:10:41 +02:00
Kim Lindberger
a6b53aea79 Merge pull request #91355 from talyz/release-20.03
[20.03] nomachine-client: 6.10.12 -> 6.11.2
2020-06-23 22:55:44 +02:00
Tim Steinbach
b3dcc2bfea linux: 5.4.47 -> 5.4.48 2020-06-23 11:41:43 -04:00
Tim Steinbach
907e1ae756 linux: 4.9.227 -> 4.9.228 2020-06-23 11:41:43 -04:00
Tim Steinbach
de5c1423f9 linux: 4.4.227 -> 4.4.228 2020-06-23 11:41:43 -04:00
Tim Steinbach
779f70185d linux: 4.19.128 -> 4.19.129 2020-06-23 11:41:43 -04:00
Tim Steinbach
abd7eb8536 linux: 4.14.184 -> 4.14.185 2020-06-23 11:41:43 -04:00
Tim Steinbach
4a38da5092 linux: 5.4.46 -> 5.4.47
(cherry picked from commit 5af8ad3e6d)
2020-06-23 11:40:49 -04:00
Maximilian Bosch
39da424060 riot-desktop: 1.6.5 -> 1.6.6
https://github.com/vector-im/riot-desktop/releases/tag/v1.6.6
(cherry picked from commit ea13f90b5f)
2020-06-23 17:18:55 +02:00
Maximilian Bosch
1fb5b2ccdd riot-web: 1.6.5 -> 1.6.6
https://github.com/vector-im/riot-web/releases/tag/v1.6.6
(cherry picked from commit c1e8f5c825)
2020-06-23 17:18:55 +02:00
José Romildo Malaquias
ae4f0cf8a2 Merge pull request #87625 from wamserma/lxqt-fix-wallpaper-backport
[20.03] lxqt.pcmanfm-qt: fix default wallpaper
2020-06-23 10:58:59 -03:00
Austin Butler
c078dab38e nomachine-client: 6.10.12 -> 6.11.2
(cherry picked from commit d0cdf0c528)
2020-06-23 14:17:28 +02:00
Markus S. Wamser
df3bafff20 lxqt.pcmanfm-qt: fix default wallpaper
(cherry picked from commit f805871a51)
2020-06-23 12:47:04 +02:00
Eelco Dolstra
348503b634 Update nixUnstable and nixFlakes
(cherry picked from commit b505bf202b)
2020-06-23 11:54:53 +02:00
Christian Kauhaus
f9fd435ad4 qemu: patch CVE-2020-1711 2020-06-23 11:15:42 +02:00
Mario Rodas
fb6c3a6831 Merge pull request #91012 from nixy/chromedriver-backport
[20.03] chromedriver: 81.0.4044.69 -> 83.0.4103.39
2020-06-23 00:03:28 -05:00
Martin Weinelt
7d1c0e7059 ansible: add myself as maintainer
(cherry picked from commit 9f98f41854)
2020-06-22 15:27:41 -07:00
Martin Weinelt
86810c468d ansible: v2.9.9 -> v2.9.10
(cherry picked from commit 11e5ca3caac59de44674056e90f6c5d7dbdcb795)
2020-06-22 15:27:41 -07:00
Christian Kauhaus
0e22213ac3 Merge pull request #91053 from veprbl/pr/root5_CVE-2017-1000203
[20.03] root5: fix CVE-2017-1000203
2020-06-22 22:37:24 +02:00
Vladimír Čunát
b154eba40a Merge #91226: linux latest and testing updates 2020-06-22 14:22:09 +02:00
Vladimír Čunát
acaa673123 Merge #86447: re2c: 1.2.1 -> 1.3 + patch
...into staging-20.03
2020-06-22 14:17:54 +02:00
Vladimír Čunát
4e3c943810 Merge #90559: mesa: 19.3.3 -> 19.3.5 (into staging-20.03) 2020-06-22 14:13:28 +02:00
Florian Klink
c43d66f032 Merge pull request #91048 from flokli/20.03-systemd-243.7-CVE-2020-13776
[20.03] systemd: apply patch for CVE-2020-13776
2020-06-22 12:53:27 +02:00
R. RyanTM
d30ddfda10 moodle: 3.8.2 -> 3.8.3
(cherry picked from commit 865f214e33)
2020-06-22 06:48:11 -04:00
Maximilian Bosch
9c42eb70cf gitea: 1.11.6 -> 1.11.8
Rationale for update: on `master`, `gitea` has been updated to `1.12.0`
in #91069 which contains a few breaking changes. The latest
1.11-releases contain a few bugfixes backported from 1.12.

https://github.com/go-gitea/gitea/releases/tag/v1.11.7
https://github.com/go-gitea/gitea/releases/tag/v1.11.8
2020-06-22 11:44:54 +02:00
zowoq
13c15f26d4 buildGoModule: remove strictDeps 2020-06-22 10:16:35 +10:00
Artemis Tosini
210d7a173a lepton: 1.2.1 → 2019-08-20
(cherry picked from commit b48a4514ca)
2020-06-21 12:53:22 -05:00
Tim Steinbach
58f3e7b88f linux: 5.7.3 -> 5.7.4
(cherry picked from commit 41bd44e05d)
2020-06-21 14:34:54 +02:00
Tim Steinbach
979b757b2a linux: 5.7.2 -> 5.7.3
(cherry picked from commit 4f7e011f87)
2020-06-21 14:34:54 +02:00
Tim Steinbach
18253518e1 linux: 5.7-rc6 -> 5.8-rc1
(cherry picked from commit 5953625fa5)
2020-06-21 14:34:54 +02:00
Tim Steinbach
1bc943ec83 linux: 5.7.1 -> 5.7.2
(cherry picked from commit fa736e19a6)
2020-06-21 14:34:54 +02:00
Vladimír Čunát
e268676f58 linux: fix kernel config options for 5.7
(cherry picked from commit bbe71613b6)
2020-06-21 14:34:54 +02:00
Michael Weiss
86a9689852 linux_5_7: init at 5.7.1
Changes:
- Copied linux-5.7.nix from linux-5.6.nix
- Add linux_5_7 and linuxPackages_5_7
- Update linux_latest to 5.7

Note:
The kernel patch 'kernelPatches.export_kernel_fpu_functions."5.3"' is
still applied as I copied the list from linux_5_7 (vs. linux_testing).
This patch is probably still required for the ZFS performance.

(cherry picked from commit 19b2efbc39)
2020-06-21 14:34:53 +02:00
Tim Steinbach
62c2df452f linux: 5.7-rc4 -> 5.7-rc6
(cherry picked from commit 8b5a3127b3)
2020-06-21 14:34:53 +02:00
Tim Steinbach
392f8e1282 linux: 5.7-rc3 -> 5.7-rc4
(cherry picked from commit b6456e528e)
2020-06-21 14:34:49 +02:00
Tim Steinbach
760436a022 linux: 5.7-rc2 -> 5.7-rc3
(cherry picked from commit 61b97c17d6)
2020-06-21 14:34:26 +02:00
Austin Seipp
48c7203ebe linux_testing: 5.6-rc7 -> 5.7-rc2
Signed-off-by: Austin Seipp <aseipp@pobox.com>
(cherry picked from commit d403911451)
2020-06-20 22:44:40 +02:00
Tim Steinbach
61e1b66b9a linux: 5.6-rc5 -> 5.6-rc7
(cherry picked from commit c76bad0ec0)
2020-06-20 22:37:04 +02:00
Tim Steinbach
3328c69d35 linux: 5.6-rc3 -> 5.6-rc5
(cherry picked from commit cd167a02b8)
2020-06-20 22:36:52 +02:00
Tim Steinbach
7dabe08aa5 linux: 5.6-rc2 -> 5.6-rc3
(cherry picked from commit 1e41aa8030)
2020-06-20 22:36:43 +02:00
Tim Steinbach
87a110ff23 linux: 5.6-rc1 -> 5.6-rc2
(cherry picked from commit 3f448f08aa)
2020-06-20 22:36:37 +02:00
Tim Steinbach
5bc40483e5 linux: 5.5-rc7 -> 5.6-rc1
(cherry picked from commit 25f706b26c)
2020-06-20 22:36:22 +02:00
Antoine Eiche
6a99d5d648 nixos/nextcloud: add occ internal option
This option exposes the prefconfigured nextcloud-occ
program. nextcloud-occ can then be used in other systemd services or
added in environment.systemPackages.

The nextcloud test shows how it can be add in
environment.systemPackages.

(cherry picked from commit 7d994ad445)
2020-06-20 19:31:38 +02:00
Maximilian Bosch
cdd1ecea80 nextcloud19: init at 19.0.0
https://nextcloud.com/blog/nextcloud-hub-brings-productivity-to-home-office/
(cherry picked from commit a2a5aa2634)
2020-06-20 15:06:18 +02:00
zowoq
fea8c13075 Merge pull request #90217 from zowoq/golang
[20.03] golang backports
2020-06-20 21:47:15 +10:00
Symphorien Gibol
154c3f3013 nixos/btrfs autoScrub: don't fail when scrub finishes successfully
(cherry picked from commit 55d16d5334)
2020-06-20 12:15:12 +02:00
taku0
a4a203e995 flashplayer: 32.0.0.371 -> 32.0.0.387
(cherry picked from commit 0a146054bd)
2020-06-20 08:19:42 +02:00
taku0
694939b0fc flashplayer: 32.0.0.363 -> 32.0.0.371
(cherry picked from commit d8fa222ca2)
2020-06-20 08:19:42 +02:00
Maximilian Bosch
c9ad46815a neomutt: 20200501 -> 20200619
https://github.com/neomutt/neomutt/releases/tag/20200619
(cherry picked from commit 499d18849f)
2020-06-19 23:48:43 +02:00
Doron Behar
657aa0bf0e neomutt: Remove old fixes for failing tests
Includes both rfc2047 tests workarounds and locale workarounds.
Fixes #86896. See https://github.com/neomutt/neomutt/pull/2314 .

(cherry picked from commit b58227a4c0)
2020-06-19 23:48:42 +02:00
Doron Behar
5ca29c7a9f neomutt: make manual.txt not empty
Without elinks / w3m / lynx in the nativeBuildInputs, there are these
errors in the build:

LC_ALL=C w3m -dump -O UTF8 docs/manual.html > docs/manual.txt || \
LC_ALL=C lynx -dump -nolist -with_backspaces \
        -display_charset=us-ascii docs/manual.html > docs/manual.txt || \
LC_ALL=C elinks -dump -no-numbering -no-references \
        docs/manual.html | sed -e 's,\\001, ,g' > docs/manual.txt
/nix/store/xfbmj7sl2ikicym9x3yq7cms5qx1w39k-bash-4.4-p23/bin/bash: w3m: command not found
/nix/store/xfbmj7sl2ikicym9x3yq7cms5qx1w39k-bash-4.4-p23/bin/bash: line 1: lynx: command not found
/nix/store/xfbmj7sl2ikicym9x3yq7cms5qx1w39k-bash-4.4-p23/bin/bash: line 3: elinks: command not found

(cherry picked from commit b8f65212ec)
2020-06-19 23:48:42 +02:00
Doron Behar
2a0c129447 neomutt: Make it not reference .dev outputs.
(cherry picked from commit 3b9a8f5426)
2020-06-19 23:48:41 +02:00
Robert Helgesson
8b38149d61 jhead: 3.03 -> 3.04
(cherry picked from commit 7395b11cd4)
2020-06-19 22:04:18 +02:00
Tony O
48a6a8b97c sv-kalendar: fix meta 2020-06-19 20:01:19 +02:00
Konrad Borowski
f499b39f4a python3Packages.zodb: unmark as broken 2020-06-19 14:28:19 +02:00
Konrad Borowski
e5959057b1 python3Packages.zconfig: unmark as broken 2020-06-19 14:28:11 +02:00
Michele Guerini Rocco
c684d8c77d Merge pull request #91076 from rnhmjoj/monero-20.03
[20.03] monero: 0.15 -> 0.16
2020-06-19 09:13:00 +02:00
Michele Guerini Rocco
0bc134c62f Merge pull request #91072 from rnhmjoj/mutt-20.03
[20.03] mutt: patch for CVE-2020-14093
2020-06-19 09:09:29 +02:00
Vladimír Čunát
b2540c79ef Merge branch 'staging-20.03' into release-20.03
A bunch of CVE fixes.  The libexif change has not been rebuilt on Hydra,
but it's only about a thousand rebuilds (when summed over all platforms).
2020-06-19 08:17:57 +02:00
Phil Wetzel
199de04688 mwprocapture: 1.2.4054 -> 1.2.4177
(cherry picked from commit 9a57b0bbd5f4ed5f2c89008745f155962814e63f)

Reason: mwprocapture build is broken on 20.03, 1.2.4054 does not
compile with Linux 5.4.
2020-06-18 18:07:55 -07:00
rnhmjoj
7587e07944 monero-gui: 0.15.0.4 -> 0.16.0.0
(cherry picked from commit 7c041738c8)
2020-06-19 02:35:52 +02:00
rnhmjoj
0a29dda8f8 monero: 0.15.0.1 -> 0.16.0.0
(cherry picked from commit a31103196e)
2020-06-19 01:26:41 +02:00
rnhmjoj
fd8bbb8ba3 mutt: patch for CVE-2020-14093 2020-06-19 00:42:19 +02:00
Jörg Thalheim
07e29369a1 Merge pull request #90269 from tokudan/2003nextcloud1806
nextcloud: 18.0.4 -> 18.0.6 [20.03]
2020-06-18 23:15:32 +01:00
Florian Klink
00e7d8757f Merge pull request #90978 from erictapen/20.03-libexif-0.6.22
[20.03] libexif: 0.6.21 -> 0.6.22 for security fixes
2020-06-19 00:10:11 +02:00
Dmitry Kalinkin
7e37d805dd root5: fix CVE-2017-1000203
Fixes: https://nvd.nist.gov/vuln/detail/CVE-2017-1000203
2020-06-18 13:15:15 -04:00
Florian Klink
dbfb40efdd systemd: apply patch for CVE-2020-13776
Fixes #90982.
2020-06-18 18:38:39 +02:00
Eelco Dolstra
2b417708c2 Remove Google Talk Plugin
This plugin is no longer necessary anyway, but having it enabled can
cause Firefox and KDE to malfunction, e.g. by hanging for a few
seconds frequently. This is caused by the broken LD_PRELOAD library
that doesn't handle O_TMPFILE properly, so ~/.cache/ksycoca5_* is
created with 0000 permissions. As a result Firefox will constantly
regenerate the ksycoca database.
2020-06-18 17:46:44 +02:00
Vladimír Čunát
788764b193 transmission: patch CVE-2018-10756
nixpkgs master is not vulnerable to this.  We use Fedora patch,
as the upstream one does not apply to this version.
Fixes #91026 (roundup issue).
2020-06-18 16:40:49 +02:00
R. RyanTM
7ccfe75bcc tendermint: 0.32.3 -> 0.32.10
(cherry picked from commit ce4e6b8a75)
2020-06-18 15:17:45 +01:00
Vladimír Čunát
0ba08838bd libjpeg(-turbo): patch CVE-2020-13790
Fixes #90864 on 20.03 (roundup issue).
(cherry picked from commit d5fd2edb1f)
2020-06-18 15:48:44 +02:00
Vladimír Čunát
4e48231cee luajit*: patch CVE-2019-19391
- upstream argues that this kind of problems can't be called
  vulnerabilities
- the upstream patch is trivial, so why not fix the bug
- nixpkgs master uses git versions already containing that commit
Fixes #90875 (roundup ticket).
2020-06-18 15:16:54 +02:00
Benjamin Andresen
4ac4a236eb chromedriver: 81.0.4044.69 -> 83.0.4103.39 2020-06-18 08:48:11 -04:00
Justin Humm
e3ca027fa5 libexif: 0.6.21 -> 0.6.22
Also:
- build from git
- enable cross compilation

(cherry picked from commit e761cfe50a)
2020-06-18 14:40:55 +02:00
Vladimír Čunát
799a3b4024 Merge branch 'release-20.03' into staging-20.03 2020-06-18 12:17:10 +02:00
worldofpeace
e69158b43b Merge pull request #90700 from mmilata/20.03/json-c-cve-2020-12762
[20.03] json_c: add patch for CVE-2020-12762
2020-06-18 06:09:01 -04:00
Colin L Rice
124d70cc9d go-modules: Add in old modsha256 w/ warning
(removed warning for 20.03)
(cherry picked from commit a0ddea1d6a)
2020-06-18 19:55:36 +10:00
Colin L Rice
470d55587f go-modules: Augment builds w/ vendor src
This is done in response to complaints that the module format is not
human readable. The vendor source blob is flat files and should be
extremely readable.

(cherry picked from commit 9761128d2d)
2020-06-18 19:55:36 +10:00
Benjamin Hipple
9ae22e3409 buildGoModule: passthru the modSha256 (#82027)
The builder does not technically need the modSha256 of the vendor dir, and even
though we pass it the entire vendor dir it makes sense not to risk having an
accidental dependency on that variable.

However, tools like [nixpkgs-update](https://github.com/ryantm/nixpkgs-update)
need to inspect the `modSha256` of a package in order to be able to update them,
and since this is a real part of the package (describes info about its
dependencies) let's add it to `passthru`.

Specifically, this allows us to run a cmd like `nix eval -f . tflint.modSha256`
to get the current value, which is how the bot finds it to replace with the new
version in the Rust ecosystem.

(cherry picked from commit 5f77ff6384)
2020-06-18 19:55:36 +10:00
zowoq
4094b363c3 go: fix TestDontCacheBrokenHTTP2Conn failure
(cherry picked from commit aae680cd5d)
2020-06-18 19:55:36 +10:00
zowoq
16a461d147 go: 1.14.3 -> 1.14.4
https://golang.org/doc/devel/release.html#go1.14.minor
(cherry picked from commit 9f978147f8)
2020-06-18 19:55:36 +10:00
zowoq
b1cbd08703 go_1_13: 1.13.11 -> 1.13.12
https://golang.org/doc/devel/release.html#go1.13.minor
(cherry picked from commit 7da08afd27)
2020-06-18 19:55:36 +10:00
zowoq
203fcbada9 go_1_13: 1.13.8 -> 1.13.11
(cherry picked from commit d1e7b0049c)
2020-06-18 19:55:35 +10:00
zowoq
2a1c67cb2d go: 1.14.2 -> 1.14.3
https://golang.org/doc/devel/release.html#go1.14.minor
(cherry picked from commit 8d41f9f281)
2020-06-18 19:55:35 +10:00
Jörg Thalheim
382b2dbad7 go: 1.14.1 -> 1.14.2
(cherry picked from commit 416caeb6db)
2020-06-18 19:55:35 +10:00
zowoq
c9965e2df7 go_1_12: stop setting GOPATH 2020-06-18 19:55:35 +10:00
zowoq
296e584a00 go_1_13: stop setting GOPATH
a1e13f6140

(cherry picked from commit 469f14ceec)
2020-06-18 19:55:35 +10:00
Manuel Mendez
6cd67ec48f go: stop setting GOPATH
The compiler does not need it anymore, has not needed it for many years
iirc. This just goes in and pollutes the environment overriding the
users GOPATH and causing grief.

Go even warns about it itself, without vs with this commit:

```sh
~> go env GOPATH
/home/manny/go
~> nix-shell -p go
~> go env GOPATH
warning: GOPATH set to GOROOT (/nix/store/gvw1mfpdrk7i82884yhxf9lf5j3c12zm-go-1.14.1/share/go) has no effect
/nix/store/gvw1mfpdrk7i82884yhxf9lf5j3c12zm-go-1.14.1/share/go
~> exit
~> nix-shell -I nixpkgs=cloned/NixOS/nixpkgs -p go
~> go env GOPATH
/home/manny/go
~> exit
```

(cherry picked from commit a1e13f6140)
2020-06-18 19:55:34 +10:00
Martin Milata
5e1de952b0 json_c: add patch for CVE-2020-12762
Fixes: https://nvd.nist.gov/vuln/detail/CVE-2020-12762

(cherry picked from commit d3e1b77ac3)
2020-06-18 03:20:57 +02:00
worldofpeace
7bb2e7e0f6 Merge pull request #90699 from cole-h/sudo
[20.03] nixos/sudo: default rule should be first
2020-06-17 21:20:25 -04:00
Cole Helbling
30c703cb45 nixos/sudo: default rule should be first
In /etc/sudoers, the last-matched rule will override all
previously-matched rules. Thus, make the default rule show up first (but
still allow some wiggle room for a user to `mkBefore` it), before any
user-defined rules.

(cherry picked from commit 13e2c75c93)
2020-06-17 18:01:34 -07:00
R. RyanTM
87cde1cfd3 pantheon.elementary-code: 3.4.0 -> 3.4.1
(cherry picked from commit 7003d6ebf3)
2020-06-17 20:18:22 -04:00
worldofpeace
8442ba48cd Merge pull request #89756 from hax404/20.03_jool
[20.03] jool: 4.0.5 -> 4.0.9
2020-06-17 20:11:23 -04:00
worldofpeace
52ff653235 Merge pull request #86567 from mmilata/20.03/encrypted-devices-loaof-warning
[20.03] silence warning from #63103 in encrypted-devices.nix
2020-06-17 20:10:57 -04:00
worldofpeace
4b5ed67853 Merge pull request #87249 from martinbaillie/backport-ssm-session-manager-plugin-release-20.03
[20.03] ssm-session-manager-plugin: init at 1.1.61.0
2020-06-17 20:10:15 -04:00
worldofpeace
7ea8a468fa Merge pull request #87807 from mmilata/20.03/samba-4.11.9
[20.03] samba: 4.11.5 -> 4.11.9
2020-06-17 20:04:06 -04:00
worldofpeace
50fc2215e4 Merge pull request #88581 from lourkeur/backport_xpra
[20.03] xpra: fix #41106 #85694
2020-06-17 20:03:29 -04:00
worldofpeace
f9b261cd6a Merge pull request #89311 from jsravn/backport-firmware-linux-nonfree
[20.03] firmwareLinuxNonfree: 2020-01-22 -> 2020-05-19
2020-06-17 20:01:39 -04:00
worldofpeace
1a11b5e57b Merge pull request #89801 from mmilata/20.03/sympa-6.2.56
[20.03] sympa: 6.2.54 -> 6.2.56
2020-06-17 19:59:52 -04:00
worldofpeace
e429855e3d Merge pull request #90213 from OPNA2608/backport-update-palemoon-28.10.0
[20.03] palemoon: 28.9.3 -> 28.10.0
2020-06-17 19:59:08 -04:00
worldofpeace
a99fd4578c Merge pull request #90222 from volth/cental.maven.org-20.03
[20.03] treewide: central.maven.org -> repo1.maven.org
2020-06-17 19:58:58 -04:00
worldofpeace
55ddbd2186 Merge pull request #90677 from erictapen/haskell-geojson-unmark-as-broken
[20.03] haskellPackages.geojson: unmark as broken
2020-06-17 19:57:17 -04:00
worldofpeace
efe40ce364 Merge pull request #89763 from worldofpeace/backport-86163-
[20.03] Gnome and Pantheon: install nixos wallpapers
2020-06-17 18:47:26 -04:00
zowoq
f70a599287 nixos/gnome3: nixos-artwork -> pkgs.nixos-artwork
(cherry picked from commit fa607bc939)
2020-06-17 18:26:12 -04:00
worldofpeace
993d0b39bc Merge pull request #89830 from worldofpeace/pantheon-updates-20.03
[20.03] Pantheon updates
2020-06-17 18:24:39 -04:00
Maximilian Bosch
73d7516c25 matrix-synapse: 1.14.0 -> 1.15.1
https://github.com/matrix-org/synapse/releases/tag/v1.15.0
https://github.com/matrix-org/synapse/releases/tag/v1.15.1
(cherry picked from commit 9fc60b36cb)
2020-06-17 23:48:35 +02:00
Graham Christensen
9e379117c4 xdg_utils: xdg-open: add $out to PATH
Otherwise, xdg-open cannot call xdg-mime and this does not work:

    "${pkgs.xdg_utils}/bin/xdg-open"

(cherry picked from commit 4b5880f015)
2020-06-17 13:50:43 -04:00
Graham Christensen
725c4fdbdb google-chrome: add coreutils to PATH
google-chrome-stable can't run without coreutils in PATH

(cherry picked from commit e8ddc0cfa7)
2020-06-17 13:50:43 -04:00
Jan Tojnar
92f1c50dab Merge pull request #90679 from mmilata/20.03/fwupd-cve-2020-10759
[20.03] fwupd: add patch for CVE-2020-10759
2020-06-17 18:33:13 +02:00
Martin Milata
80b50f32ea fwupd: add patch for CVE-2020-10759
Fixes: https://nvd.nist.gov/vuln/detail/CVE-2020-10759
See also: https://github.com/justinsteven/advisories/blob/master/2020_fwupd_dangling_s3_bucket_and_CVE-2020-10759_signature_verification_bypass.md
2020-06-17 18:09:36 +02:00
Eelco Dolstra
583ccf8c63 Don't enable nix-bash-completions when using Nix 2.4
2.4 has its own completion script which collides with
nix-bash-completions.

(cherry picked from commit bbfc47326b)
2020-06-17 18:08:23 +02:00
Justin Humm
bb4fd7eb9e haskellPackages.geojson: Unmark as broken 2020-06-17 16:32:43 +02:00
Valentin Lorentz
c5fd298d67 vlc: 3.0.8 -> 3.0.11 (security)
Includes a security fix for CVE-2020-13428.

improved security for stored passwords (from 3.0.9)
multiple security fixes, including microdns (from 3.0.9.1)

(cherry picked from commit 745245a62a)
2020-06-17 14:57:37 +02:00
Michael Weiss
8056c50062 Merge pull request #90603 from primeos/chromium-backport
[20.03] chromium: 83.0.4103.97 -> 83.0.4103.106 + VA-API (backport)
2020-06-17 11:35:37 +02:00
Maximilian Bosch
243f698ac2 vagrant: 2.2.8 -> 2.2.9
https://github.com/hashicorp/vagrant/blob/v2.2.9/CHANGELOG.md#229-may-07-2020
(cherry picked from commit cf810b54e0)
2020-06-17 02:40:22 +02:00
Maximilian Bosch
b2a6d2fa15 linuxPackages.wireguard: 1.0.20200520 -> 1.0.20200611
https://lists.zx2c4.com/pipermail/wireguard/2020-June/005480.html
(cherry picked from commit 52633ca14b)
2020-06-17 02:40:21 +02:00
Maximilian Bosch
8ab112eb24 riot-desktop: 1.6.4 -> 1.6.5
https://github.com/vector-im/riot-desktop/releases/tag/v1.6.5
(cherry picked from commit dcf36b65c3)
2020-06-16 23:21:24 +02:00
Maximilian Bosch
724d123a31 riot-web: 1.6.4 -> 1.6.5
https://github.com/vector-im/riot-web/releases/tag/v1.6.5
(cherry picked from commit 59678c1152)
2020-06-16 23:21:23 +02:00
Andreas Rammhold
564db6b6f9 Merge pull request #90007 from mweinelt/20.03/microcode-intel
[20.03] microcodeIntel: 20200508 -> 20200520 -> 20200609
2020-06-16 22:46:53 +02:00
Martin Weinelt
c27866c855 microcodeIntel: 20200609 -> 20200616
(cherry picked from commit 77730556e0)
2020-06-16 22:45:25 +02:00
Luflosi
dce9ef5105 youtube-dl: 2020.06.06 -> 2020.06.16.1
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.06.16.1
(cherry picked from commit 1ab1a027d5)
2020-06-16 20:39:42 +02:00
Maximilian Bosch
33e9bc833d Merge pull request #90611 from omniitgmbh/graylog_3.3.1_with_plugins_backport
[20.03] graylog: 3.3.0 -> 3.3.1 (with plugins)
2020-06-16 20:00:09 +02:00
hlolli
02b95cf5ed strace-graph: fix strace-graph shebang which points to perl
(cherry picked from commit 38b7aff170)
2020-06-16 19:13:03 +02:00
fadenb
60da5edb97 graylogPlugins: Update plugins
graylog-enterprise-integrations: 3.3.0 -> 3.3.1
graylog-integrations: 3.3.0 -> 3.3.1
(cherry picked from commit 0181c1bd2b)

Reason: Companion commit to 70ecf772b9
to ensure that packaged plugin versions are compatible
2020-06-16 14:18:55 +00:00
R. RyanTM
70ecf772b9 graylog: 3.3.0 -> 3.3.1
(cherry picked from commit cb053733b5)

Reason: 3.3.1 contains bugfix for potential dataloss when Elasticsearch
index is read-only due to disk space problems
2020-06-16 14:17:36 +00:00
Michael Weiss
0d8250ae18 chromium: 83.0.4103.97 -> 83.0.4103.106
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html

This update includes 4 security fixes.

CVEs: CVE-2020-6505 CVE-2020-6506 CVE-2020-6507
(cherry picked from commit 1a5df8f680)
2020-06-16 13:57:39 +02:00
Michael Weiss
b0bfe9b508 chromium: Build with VA-API but disable it by default
This makes it possible to enable VA-API without having to rebuild
Chromium: `chromium.override { enableVaapi = true; }`

(cherry picked from commit 267eefcdb7)
2020-06-16 13:56:41 +02:00
Phil Wetzel
580abb251d mesa: 19.3.3 -> 19.3.5 2020-06-15 21:03:00 -04:00
Niklas Hambüchen
a84b797b28 pycurl: Exclude flaky multi_timer_test. Fixes #77304
(cherry picked from commit a6df4a98911e0cf1be889d5e7641494f9f4dad55)
2020-06-15 16:22:34 -07:00
Niklas Hambüchen
ae27952d7f pycurl: Exclude another flaky test. Fixes #77304
(cherry picked from commit d29a4e46156b994b00461f8f36233691a26b72ba)
2020-06-15 16:22:34 -07:00
Malte Brandy
db0200e52c system-config-printer: Fix ABRT: free(): invalid pointer
Apply patches picked from upstream as done on debian.
Will be included in next upstream release.

(cherry picked from commit fcecf15dc4)
2020-06-16 00:24:25 +02:00
Robert Schütz
d46e037692 Merge pull request #90498 from dotlambda/postfix-3.4.13
postfix: 3.4.9 -> 3.4.13
2020-06-15 19:11:44 +02:00
Robert Schütz
4351ace9d0 postfix: 3.4.12 -> 3.4.13 2020-06-15 16:27:37 +02:00
Benjamin Asbach
41268a30d8 postfix: 3.4.10 -> 3.4.12
`0001-Fix-build-with-glibx-2.30` was removed since the patch is already applied to upstream source.

(cherry picked from commit ae7b57c8ca)
2020-06-15 16:24:44 +02:00
R. RyanTM
1594eb937c postfix: 3.4.9 -> 3.4.10
(cherry picked from commit 5c207933b7)
2020-06-15 16:24:29 +02:00
Florian Klink
927d4e6850 Merge pull request #90064 from aszlig/nixpart0-glibc-fixes
[20.03] Backport of nixpart0 fixes against glibc >= 2.28
2020-06-15 12:01:02 +02:00
Mario Rodas
ddeb47cce2 Merge pull request #89320 from zaninime/sane-airscan-update-20.03
[20.03] sane-airscan: 0.99.0 -> 0.99.3
2020-06-15 04:24:30 -05:00
Peter Simons
5376727cc3 Merge pull request #90407 from thiagokokada/release-20.03
bbswitch: fix build with Linux kernel version >= 5.6.0
2020-06-15 08:14:22 +02:00
Dmitry Kalinkin
10e5f1f87a intltool: add a backup url for a patch
Fixes:

  Failed to connect to sources.debian.org port 443: Connection timed out

(cherry picked from commit df4c3b06f4)
cc #86523
2020-06-14 21:22:00 -04:00
Peter Simons
126fb3aeb8 bbswitch: fix build with Linux kernel version >= 5.6.0
Fixes https://github.com/NixOS/nixpkgs/issues/85564.

(cherry picked from commit 00222db)
2020-06-14 18:51:00 -03:00
Piotr Bogdan
daace8a647 python2Packages.nixpart0/multipath_tools: fixup path to internal libraries
(cherry picked from commit 05f1bcce49)
2020-06-14 23:03:44 +02:00
Piotr Bogdan
4fa1d54d4c python2Packages.nixpart0/pyblock: patch for glibc >= 2.28
(cherry picked from commit 912e1e87c0)
2020-06-14 23:03:41 +02:00
Piotr Bogdan
1ecfb2cc51 python2Packages.nixpart0/parted: patch for glibc >= 2.28
(cherry picked from commit 64f4073f8d)
2020-06-14 23:03:39 +02:00
Piotr Bogdan
497b2153a7 python2Packages.nixpart0/multipath_tools: patch for glibc >= 2.28
(cherry picked from commit eb696ef672)
2020-06-14 23:03:36 +02:00
Piotr Bogdan
5858bc2642 python2Packages.nixpart0/lvm2: patch for glibc >= 2.28
(cherry picked from commit 0776d9043c)
2020-06-14 23:03:34 +02:00
Piotr Bogdan
573b24ee9b python2Packages.nixpart0/cryptsetup: patch for glibc >= 2.28
(cherry picked from commit c494fc51dc)
2020-06-14 23:03:31 +02:00
Daniel Frank
f6faec26e3 nextcloud: 18.0.4 -> 18.0.6
(cherry picked from commit 660973d823)
2020-06-14 01:56:17 +02:00
volth
098fdc6baf treewide: central.maven.org -> repo1.maven.org 2020-06-13 06:07:32 +00:00
Christoph Neidahl
807d383ce0 palemoon: 28.9.3 -> 28.10.0
(cherry picked from commit 7c65275595)
2020-06-13 00:44:40 +02:00
Frederik Rietdijk
db31e48c5c python.pkgs.apsw: 3.30.1-r1 -> 3.32.2-r1
(cherry picked from commit 2f72c426e1)
2020-06-12 22:30:20 +02:00
Michael Weiss
a6e8ffb7f5 Merge pull request #90165 from primeos/signal-desktop-backport
signal-desktop: 1.34.1 -> 1.34.2
2020-06-12 20:41:15 +02:00
Florian Klink
ec7fdd68e5 Merge pull request #89920 from mweinelt/20.03/hostapd
[20.03] hostapd: apply patches for CVE-2020-12695
2020-06-12 14:40:16 +02:00
Lancelot SIX
b6cda510fa poezio: add missing setuptools dependency
(cherry picked from commit 0fa981bfbe)
2020-06-12 08:28:19 +01:00
Mario Rodas
158cfa6b2b Merge pull request #90167 from zowoq/backport-gh
[20.03] gitAndTools.gh: 0.9.0 -> 0.10.0
2020-06-11 22:46:35 -05:00
zowoq
10ceb8f543 gitAndTools.gh: 0.9.0 -> 0.10.0
https://github.com/cli/cli/releases/tag/v0.10.0
(cherry picked from commit b479619da8)
2020-06-12 10:23:18 +10:00
zowoq
f5e3447302 gitAndTools.gh: add github-cli alias
(cherry picked from commit d332426add)
2020-06-12 10:16:55 +10:00
Michael Weiss
e2f9675ed1 signal-desktop: 1.34.1 -> 1.34.2
(cherry picked from commit 8ee8a22e35)
2020-06-12 01:06:18 +02:00
Tim Steinbach
f09d743409 linux: 5.6.17 -> 5.6.18 2020-06-11 17:59:26 -04:00
Tim Steinbach
adeb94a537 linux: 5.4.45 -> 5.4.46 2020-06-11 17:59:25 -04:00
Tim Steinbach
5bcdf9001d linux: 4.9.226 -> 4.9.227 2020-06-11 17:59:24 -04:00
Tim Steinbach
ff24b8ade3 linux: 4.4.226 -> 4.4.227 2020-06-11 17:59:23 -04:00
Tim Steinbach
d8a5c62233 linux: 4.19.127 -> 4.19.128 2020-06-11 17:59:22 -04:00
Tim Steinbach
a8086278c7 linux: 4.14.183 -> 4.14.184 2020-06-11 17:59:21 -04:00
Florian Klink
8b071be751 Merge pull request #90102 from flokli/20.03-gitlab-12.10.11
[20.03] gitlab: 12.10.9 -> 12.10.11
2020-06-11 20:52:19 +02:00
Eelco Dolstra
8c521cb815 Merge pull request #89800 from andir/20.03/firefox
[20.03] firefox: 76.0.1 -> 77.0.1
2020-06-11 16:47:35 +02:00
Florian Klink
3748b5f204 gitlab: 12.10.9 -> 12.10.11
CI Token Access Control

An authorization issue discovered in the mirroring logic allowed read access to private repositories. This issue is now mitigated in the latest release and is waiting for a CVE ID to be assigned.

https://about.gitlab.com/releases/2020/06/10/critical-security-release-13-0-6-released/
2020-06-11 00:34:48 +02:00
Martin Weinelt
0094820f68 hostapd: add hexa as maintainer
(cherry picked from commit c898b5c057)
2020-06-10 21:17:54 +02:00
Martin Milata
3f31c0d2a3 nixos/sympa: fix PATH_INFO splitting for sympa-6.2.56
Our regex for splitting HTTP path into SCRIPT_NAME and PATH_INFO was
incorrect when webLocation was set to "/". Since Sympa 6.2.56 this has
caused the web interface to return "421 Misdirected Request".

Since 6.2.56 Sympa can do the splitting on its own so we can simply
remove it from nginx configuration.

See also:
- https://github.com/sympa-community/sympa/issues/879
- https://github.com/sympa-community/sympa/pull/910
- https://github.com/sympa-community/sympa-community.github.io/pull/53

(cherry picked from commit bd4e4dddff)
2020-06-10 17:54:23 +02:00
Markus Kowalewski
8946799e07 slurm: bugifx, add su/echo paths
slurmd requires su and echo to work with "--get-user-env". If slurmd
does not find /bin/su or /bin/echo, it crashes.

(cherry picked from commit 5d8f61f3bf)
2020-06-10 16:48:02 +02:00
Markus Kowalewski
118e07c361 slurm: 19.05.5.1 -> 19.05.7.1
(cherry picked from commit af4491f26c)
2020-06-10 16:44:36 +02:00
Maximilian Bosch
d3bfabe7b5 Merge pull request #89838 from omniitgmbh/20.03_graylog_3.3.0_with_plugins
[20.03] [backport] graylog: 3.2.5 -> 3.3.0 (with plugins)
2020-06-10 14:32:16 +02:00
Michael Weiss
e0c7e1fd05 chromium{Beta,Dev}: Fix the builds
Fix #89615.

(cherry picked from commit e466ea721c)
2020-06-10 11:27:09 +02:00
Michael Weiss
48f3b97420 chromiumBeta: Fix the configuration phase
The changes from chromiumDev (see 029a5de083) are required for
chromiumBeta as well.

(cherry picked from commit 1d38f6bcb2)
2020-06-10 11:27:08 +02:00
Michael Weiss
159c6a7316 chromiumDev: Fix the configuration phase
Relevant changes in M85:
- Upstream switched from YASM to NASM [0].
- third_party/binutils was removed [1].

Note: The gn and dev channel updates are optional.
cc #89615.

[0]: https://bugs.chromium.org/p/chromium/issues/detail?id=766721
[1]: 9869e86fd9

(cherry picked from commit 029a5de083)
2020-06-10 11:27:08 +02:00
Martin Weinelt
57f7f17513 microcodeIntel: 20200520 -> 20200609
(cherry picked from commit 08815104f5)
2020-06-10 04:07:14 +02:00
Martin Weinelt
1763fe3fbd microcodeIntel: 20200508 → 20200520
(cherry picked from commit f49defc85f)
2020-06-10 04:06:48 +02:00
Daniel Løvbrøtte Olsen
123d83148f mumble: 1.3.0 -> 1.3.1 (#89988)
(cherry-picked from commit ac44b7f958)
2020-06-10 01:05:41 +02:00
Michael Weiss
d6c8902ca4 Merge pull request #89560 from primeos/chromium-backport
[20.03] chromium: 83.0.4103.61 -> 83.0.4103.97 (backport)
2020-06-09 21:56:33 +02:00
Vladimír Čunát
fd516cba77 Merge branch 'staging-20.03' into release-20.03
A severe gnutls security fix is contained.
2020-06-09 20:53:51 +02:00
Florian Klink
304183d9a2 Merge pull request #89808 from lourkeur/backport_89570
[20.03] pyxdg: fix missing class field Type
2020-06-09 18:56:39 +02:00
Martin Weinelt
fc382da491 hostapd: apply patches for CVE-2020-12695
https://w1.fi/security/2020-1/upnp-subscribe-misbehavior-wps-ap.txt

Fixes: CVE-2020-12695
(cherry picked from commit 1c14b52e18)
2020-06-09 15:03:26 +02:00
Maximilian Bosch
92d5b1b55f hydra-unstable: 2020-04-16 -> 2020-06-01
Fixes #89305
(cherry picked from commit c18016cfbf)
2020-06-09 13:22:02 +02:00
Vladimír Čunát
d68215db6f Merge #89029: sqlite: 3.30.1 -> 3.32.2 (security)
https://www.sqlite.org/cves.html#status_of_recent_sqlite_cves
(cherry picked from commit b10932369e)
2020-06-09 10:26:45 +02:00
Cole Helbling
03da8782e1 gnutls: 3.6.13 -> 3.6.14
Fixes CVE-2020-13777 [1].

Changes: https://lists.gnupg.org/pipermail/gnutls-help/2020-June/004648.html

[1] https://nvd.nist.gov/vuln/detail/CVE-2020-13777

(cherry picked from commit 1dba117541, PR #89884)
2020-06-09 10:24:04 +02:00
Vincent Laporte
ca6e453feb coq_8_11: 8.11.1 → 8.11.2
(cherry picked from commit 48f0d8b3c8)
2020-06-09 09:53:22 +02:00
Anderson Torres
72245392fa Merge pull request #89702 from OPNA2608/backport-update-palemoon
[20.03] palemoon: 28.9.1 -> 28.9.3
2020-06-08 23:39:18 -03:00
Tim Steinbach
f6f6d50748 linux: 5.6.16 -> 5.6.17
(cherry picked from commit aa1479c5be)
2020-06-08 20:24:03 -04:00
Tim Steinbach
a91a07a002 linux: 5.4.44 -> 5.4.45
(cherry picked from commit 505e54f340)
2020-06-08 20:24:01 -04:00
Tim Steinbach
a83164c2be linux: 4.19.126 -> 4.19.127
(cherry picked from commit 4c11426c3f)
2020-06-08 20:24:00 -04:00
Tristan Helmich (omniIT)
974353b2d6 graylogPlugins: Update and add plugins
* graylog-auth-sso: 3.1.0 -> 3.3.0
* graylog-enterprise-integrations: init at 3.3.0
* graylog-integrations: init at 3.3.0
* graylog-pagerduty: 1.3.0 -> 2.0.0
* graylog-snmp: init at 0.3.0

(cherry picked from commit a265cd27b0)

Backport of #89617 for security and bugfixes (and plugin updates to stay
compatible with Graylog 3.3.0)
2020-06-08 19:48:59 +00:00
Tristan Helmich (omniIT)
b845898cb9 graylog: 3.2.5 -> 3.3.0
(cherry picked from commit b48ad9b33d)

Backport of #89617 for security and bugfixes
2020-06-08 19:48:59 +00:00
Moritz Angermann
06e882b0ec gcc: Clean up configure flags
No reason to have two conditional lists with the same condition.

(cherry picked from commit f2a33e4486)
2020-06-08 15:33:30 -04:00
Michael Bishop
bf57132888 gcc: Fix MinGW exception handling so Rust works
reasoning:
sjlj (short jump long jump) exception handling makes no sense on x86_64, it's forcably slowing programs down as it produces a constant overhead. On x86_64 we have SEH (Structured Exception Handling) and we should use that. On i686, we do not have SEH, and have to use sjlj with dwarf2. Hence it's now conditional on x86_32

(cherry picked from commit e27e475f0d)
(cherry picked from commit 58ffaee5d7)
2020-06-08 15:31:42 -04:00
Michael Lingelbach
034c9b1e3b pyxdg: fix missing class field Type
Fixes #88593 by replacing call to missing Type field with getType()

(cherry picked from commit 1968f115b5)
2020-06-08 21:31:00 +02:00
worldofpeace
b3a580266e pantheon.switchboard-plug-sound: 2.2.3 -> 2.2.4
(cherry picked from commit cf675b75c3)
2020-06-08 15:06:34 -04:00
worldofpeace
003af9cac8 pantheon.switchboard-plug-security-privacy: 2.2.3 -> 2.2.4
(cherry picked from commit a8800e6b82)
2020-06-08 15:06:34 -04:00
worldofpeace
5421f401c1 pantheon.switchboard-plug-printers: 2.1.8 -> 2.1.9
(cherry picked from commit 2a48d9fa2c)
2020-06-08 15:06:34 -04:00
worldofpeace
d8cac26492 pantheon.switchboard-plug-power: 2.4.1 -> 2.4.2
https://github.com/elementary/switchboard-plug-power/releases/tag/2.4.2
(cherry picked from commit 766478e2be)
2020-06-08 15:06:34 -04:00
worldofpeace
e40d5b5f63 pantheon.switchboard-plug-notifications: 2.1.6 -> 2.1.7
(cherry picked from commit 9de4f5447e)
2020-06-08 15:06:34 -04:00
worldofpeace
68d7569d28 pantheon.switchboard-plug-network: 2.3.0 -> 2.3.1
https://github.com/elementary/switchboard-plug-network/releases/tag/2.3.1
(cherry picked from commit f8d35d8b7e)
2020-06-08 15:06:34 -04:00
worldofpeace
489245ed9b pantheon.switchboard-plug-mouse-touchpad: 2.4.1 -> 2.4.2
(cherry picked from commit 6e53391394)
2020-06-08 15:06:34 -04:00
worldofpeace
d3805ad595 pantheon.switchboard-plug-display: 2.2.1 -> 2.2.2
(cherry picked from commit ac1294c3db)
2020-06-08 15:06:34 -04:00
worldofpeace
34ce39524b pantheon.switchboard-plug-datetime: 2.1.7 -> 2.1.9
https://github.com/elementary/switchboard-plug-datetime/releases/tag/2.1.9
https://github.com/elementary/switchboard-plug-datetime/releases/tag/2.1.8
(cherry picked from commit 462abd5701)
2020-06-08 15:06:34 -04:00
worldofpeace
77804794ff pantheon.switchboard-plug-bluetooth: 2.3.1 -> 2.3.2
(cherry picked from commit 1d759d4786)
2020-06-08 15:06:34 -04:00
worldofpeace
df72656b88 pantheon.switchboard-plug-about: 2.6.2 -> 2.6.3
(cherry picked from commit 96a44e01de)
2020-06-08 15:06:34 -04:00
worldofpeace
ac21fd75f5 pantheon.elementary-onboarding: 1.2.0 -> 1.2.1
https://github.com/elementary/onboarding/releases/tag/1.2.1
(cherry picked from commit 65c47f614b)
2020-06-08 15:06:34 -04:00
worldofpeace
ae8c62cbc9 pantheon.elementary-shortcut-overlay: 1.1.1 -> 1.1.2
(cherry picked from commit babac73225)
2020-06-08 15:06:34 -04:00
worldofpeace
4a25ae59ab pantheon.wingpanel-applications-menu: 2.7.0 -> 2.7.1
(cherry picked from commit 3282639568)
2020-06-08 15:06:34 -04:00
worldofpeace
0d8445d0ce pantheon.wingpanel-indicator-network: 2.2.3 -> 2.2.4
(cherry picked from commit 5f88c646d6)
2020-06-08 15:06:34 -04:00
worldofpeace
8f24062fbf pantheon.pantheon-agent-polkit: 1.0.1 -> 1.0.2
(cherry picked from commit 2ce928c741)
2020-06-08 15:06:33 -04:00
worldofpeace
85146f0f63 pantheon.elementary-greeter: 5.0.3 -> 5.0.4
(cherry picked from commit 10dcf337ec)
2020-06-08 15:06:33 -04:00
worldofpeace
adca4a374f pantheon.sideload: 1.1.0 -> 1.1.1
https://github.com/elementary/sideload/releases/tag/1.1.1
(cherry picked from commit 05d5406fd8)
2020-06-08 15:02:58 -04:00
worldofpeace
d71bdb2e26 pantheon.elementary-files: 4.4.2 -> 4.4.3
https://github.com/elementary/files/releases/tag/4.4.3
(cherry picked from commit 5b5081f52d)
2020-06-08 15:02:57 -04:00
worldofpeace
adacfd0251 pantheon.elementary-calendar: 5.0.4 -> 5.0.5
(cherry picked from commit 758619551b)
2020-06-08 15:02:57 -04:00
worldofpeace
3c96a131c9 pantheon.elementary-icon-theme: 5.3.0 -> 5.3.1
Now uses librsvg's rsvg-convert instead of inkscape.

(cherry picked from commit e3be875b70)
2020-06-08 15:02:56 -04:00
worldofpeace
044c9a43d4 pantheon.appcenter: 3.3.0 -> 3.4.0
(cherry picked from commit 6c3b7923f0)
2020-06-08 15:02:56 -04:00
worldofpeace
c0c768b6d9 pantheon.gala: 3.3.1 -> 3.3.2
https://github.com/elementary/gala/releases/tag/3.3.2
(cherry picked from commit d02f75afbb)
2020-06-08 15:02:56 -04:00
worldofpeace
c064cd054f pantheon.wingpanel-applications-menu: 2.6.0 -> 2.7.0
https://github.com/elementary/applications-menu/releases/tag/2.7.0
(cherry picked from commit 7707830b40)
2020-06-08 15:02:55 -04:00
worldofpeace
3b4dbf3439 pantheon.granite: 5.3.1 -> 5.4.0
https://github.com/elementary/granite/releases/tag/5.4.0
(cherry picked from commit 5c7019dbbd)
2020-06-08 15:02:55 -04:00
worldofpeace
016f42b323 pantheon.elementary-icon-theme: 5.2.0 -> 5.3.0
https://github.com/elementary/icons/releases/tag/5.3.0
(cherry picked from commit 7bd2c2ae3a)
2020-06-08 15:02:54 -04:00
worldofpeace
9fdefdc958 pantheon.switchboard: 2.3.9 -> 2.4.0
https://github.com/elementary/switchboard/releases/tag/2.4.0
(cherry picked from commit 3fe608a274)
2020-06-08 15:02:54 -04:00
worldofpeace
2678e4fcb1 pantheon.appcenter: 3.2.4 -> 3.3.0
https://github.com/elementary/appcenter/releases/tag/3.3.0
(cherry picked from commit e22f36ecc0)
2020-06-08 15:02:53 -04:00
Eelco Dolstra
70717a337f nix: 2.3.6 -> 2.3.6
(cherry picked from commit aef2bc1330)
2020-06-08 18:22:16 +02:00
Martin Milata
4a644cc7e6 sympa: 6.2.54 -> 6.2.56
Fixes: https://nvd.nist.gov/vuln/detail/CVE-2020-10936
       https://sympa-community.github.io/security/2020-002.html

ChangeLog: https://github.com/sympa-community/sympa/blob/6.2.56/NEWS.md
(cherry picked from commit 31789d15c8)
2020-06-08 14:29:59 +02:00
ajs124
fb9329960e firefox-bin: 76.0 -> 77.0.1
(cherry picked from commit 303f8d1da4)
2020-06-08 14:16:17 +02:00
ajs124
f7446a59de firefox-esr-68: 68.8.0esr -> 68.9.0esr
(cherry picked from commit 7fc793091b)
2020-06-08 14:16:17 +02:00
ajs124
03be5f3dd2 firefox: 76.0.1 -> 77.0.1
(cherry picked from commit dd334ebabb)
2020-06-08 14:16:17 +02:00
Andreas Rammhold
e3e66c8054 rust-cbindgen_0_14_1: init
This is requires for newer Firefox releases that have a dependency on
at least this version of rust-cbindgen.
2020-06-08 14:16:17 +02:00
Andreas Rammhold
582b4bb439 nss_3_52: 3.52.0 -> 3.52.1 2020-06-08 14:16:17 +02:00
Eelco Dolstra
b119c09397 flake.nix: Remove edition field
(cherry picked from commit 97fc8af29b)
2020-06-08 12:46:30 +02:00
Francesco Zanini
8759f46c66 sane-airscan: 0.99.0 -> 0.99.3
(cherry picked from commit 07d3ca8112)
2020-06-08 11:48:54 +02:00
Antoine Eiche
4340dd7225 nixos/nextcloud: preserve OC_PASS env variable in the occ wrapper
The OC_PASS environment variable can be used to create a user with
`occ user:add --password-from-env`. It is currently not possible to
use the `nextcloud-occ` to "non-interactively" create a user since
this variable is ignored by sudo.

(cherry picked from commit cb682317b0)
2020-06-08 11:01:02 +02:00
Markus Kowalewski
b6042f56ab moosefs: fix datapath for mfscgiserv
The datapath in mfscgisrv is hardcoded and pointed to
the nix store, which made the program fail on startup.

(cherry picked from commit 69a601c627)
2020-06-08 09:50:23 +02:00
WilliButz
82dc55e234 atlassian-crowd: 3.4.5 -> 4.0.2
(cherry picked from commit dc0f741db0)
2020-06-08 09:38:54 +02:00
Mica Semrick
f956d09dde displaycal: 3.5 -> 3.8.9.3
displaycal verison 3.5 built correctly but could not perform a calibration. This update fixes that.

(cherry picked from commit 009284cd4c)
2020-06-07 19:53:13 -07:00
Maximilian Bosch
e2bb73ce5f Merge pull request #89681 from mweinelt/20.03/borgbackup
[20.03] borgbackup: 1.1.11 -> 1.1.13
2020-06-07 23:11:12 +02:00
worldofpeace
b2bd93768c nixos/pantheon: install nixos wallpaper
Fixes  #86146

(cherry picked from commit 5100e4f250)
2020-06-07 14:49:10 -04:00
worldofpeace
489ebe4512 nixos/gnome3: install nixos wallpapers
(cherry picked from commit 7f3bc5b8fa)
2020-06-07 14:49:01 -04:00
Jan Tojnar
20bfce5060 nixos/lightdm: change background type to path
(cherry picked from commit 3d1706c28d)
2020-06-07 14:48:54 -04:00
worldofpeace
392b8bc9f9 nixos-artwork: add file path attributes
This makes things so much easier, and we install to
the path that both gnome-backgrounds and
elementary-wallpapers install to.

(cherry picked from commit 62587f43dd)
2020-06-07 14:48:45 -04:00
Georg Haas
90057c5be0 jool: 4.0.5 -> 4.0.9
(cherry picked from commit a8ee561b0f)
2020-06-07 20:05:55 +02:00
Maximilian Bosch
f8463ef800 cargo-make: 0.30.8 -> 0.31.0
https://github.com/sagiegurari/cargo-make/releases/tag/0.31.0
(cherry picked from commit 0558bb9f64)
2020-06-07 20:03:38 +02:00
Maximilian Bosch
7a7fcac4d6 dlib: 19.19 -> 19.20
https://github.com/davisking/dlib/releases/tag/v19.20
(cherry picked from commit 3fec30cb95)
2020-06-07 20:03:38 +02:00
Maximilian Bosch
cc28f9cea3 i3status-rust: 0.13.1 -> 0.14.0
https://github.com/greshake/i3status-rust/releases/tag/v0.14.0
(cherry picked from commit 8454ef7b29)
2020-06-07 20:03:38 +02:00
Maximilian Bosch
3154bb9be1 roundcube: 1.4.5 -> 1.4.6
https://github.com/roundcube/roundcubemail/releases/tag/1.4.6
(cherry picked from commit fbf25a9308)
2020-06-07 20:03:38 +02:00
Nadrieril
11c84a902e boot: fix order of arguments for hasPrefix (#89751)
(cherry picked from commit e4f445008e)
2020-06-07 18:44:05 +02:00
symphorien
0c2ddc1d4a epkowa: fix parsing of interpreters (#82909) (#89506)
Building with -std=c99 breaks the obsolete "%as" format string, which
completely breaks the parsing of epkowa interpreters. This means that
no scanner requiring plugins worked.

(cherry picked from commit e22eb2d7b5)

Co-authored-by: Dominik Honnef <dominik@honnef.co>
2020-06-07 18:40:37 +02:00
Graham Christensen
a53ed231d2 Merge pull request #89692 from grahamc/fwupd-backport
[r20.03] fwupd: 1.3.7 -> 1.3.9
2020-06-06 21:06:35 -04:00
Martin Weinelt
6956305a51 borgbackup: 1.1.11 -> 1.1.13
(cherry picked from commit 7fb84ea2f6)
2020-06-07 01:21:33 +02:00
Christoph Neidahl
af29475a52 palemoon: 28.9.1 -> 28.9.3
(cherry picked from commit 5262ada436)
2020-06-06 23:13:26 +02:00
Jan Tojnar
a2add30b7f fwupd: 1.3.8 → 1.3.9
https://github.com/fwupd/fwupd/blob/1.3.9/data/org.freedesktop.fwupd.metainfo.xml#L38-L63
2020-06-06 15:45:01 -04:00
Jan Tojnar
83b5900a3d fwupd: 1.3.7 → 1.3.8
https://github.com/fwupd/fwupd/compare/1.3.7...1.3.8
2020-06-06 15:44:48 -04:00
Lassulus
1aa5271117 Merge pull request #89260 from schmittlauch/cawbird1.1.0-backport
[backport] cawbird: 1.0.5 -> 1.1.0
2020-06-06 16:25:30 +02:00
Michael Weiss
e33969c1f7 chromiumBeta: Fix the source hash
For some reason the hash from 9ec139b672 became invalid, see #89615.
The update script does now produce the correct hash.

(cherry picked from commit 19e939d98e)
2020-06-06 13:37:18 +02:00
Florian Klink
c136fd3429 Merge pull request #89370 from toonn/release-20.03
wire-desktop: linux 3.17.2924 -> 3.18.2925, mac 3.17.3666 -> 3.18.3728
2020-06-06 11:56:13 +02:00
Maximilian Bosch
f277096c4c riot-desktop: 1.6.3 -> 1.6.4
https://github.com/vector-im/riot-desktop/releases/tag/v1.6.4
(cherry picked from commit 877d65bae3)
2020-06-05 23:38:23 +02:00
Maximilian Bosch
33d51b7d82 riot-web: 1.6.3 -> 1.6.4
https://github.com/vector-im/riot-web/releases/tag/v1.6.4
(cherry picked from commit 3351a81afd)
2020-06-05 23:38:22 +02:00
Maximilian Bosch
a0466d5dfb mautrix-whatsapp: 2020-06-01 -> 0.1.1
https://github.com/tulir/mautrix-whatsapp/releases/tag/v0.1.1
https://github.com/tulir/mautrix-whatsapp/releases/tag/v0.1.0
(cherry picked from commit 0402df6a58)
2020-06-05 23:38:17 +02:00
Vladimír Čunát
29c0151c82 Merge #89474: thunderbird*: 68.8.1 -> 68.9.0 (security)
(cherry picked from commit 5a8cdcc278)
Re-tested both briefly on 20.03.
2020-06-05 22:28:35 +02:00
Luflosi
e1ff9d389d youtube-dl: 2020.05.29 -> 2020.06.06
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.06.06
(cherry picked from commit dfe8770872)
2020-06-05 22:16:28 +02:00
Louis Bettens
82ef74d010 xpra: adjust patches 2020-06-05 22:04:42 +02:00
Louis Bettens
79ac3258c9 xpra: fix #41106
(cherry picked from commit 4459844e79)
2020-06-05 22:02:46 +02:00
Louis Bettens
cd6ea1dfd7 xpra: fix #85694
(cherry picked from commit 8b92f678f9)
2020-06-05 22:02:46 +02:00
Michael Weiss
b96198c90c chromium: 83.0.4103.61 -> 83.0.4103.97
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop.html

This update includes 5 security fixes.

CVEs: CVE-2020-6493 CVE-2020-6494 CVE-2020-6495 CVE-2020-6496
(cherry picked from commit 9ec139b672)
2020-06-05 20:43:33 +02:00
Tim Steinbach
fdfd5ab054 linux: 5.6.15 -> 5.6.16 2020-06-05 09:51:40 -04:00
Tim Steinbach
114bc19e96 linux: 5.4.43 -> 5.4.44 2020-06-05 09:51:40 -04:00
Tim Steinbach
e8f06879fe linux: 4.9.225 -> 4.9.226 2020-06-05 09:51:40 -04:00
Tim Steinbach
9ecbc8d270 linux: 4.4.225 -> 4.4.226 2020-06-05 09:51:40 -04:00
Tim Steinbach
1f96786d0e linux: 4.19.125 -> 4.19.126 2020-06-05 09:51:40 -04:00
Tim Steinbach
652407987a linux: 4.14.182 -> 4.14.183 2020-06-05 09:51:40 -04:00
WilliButz
1f54141da1 atlassian-confluence: 7.5.0 -> 7.5.1
(cherry picked from commit 0f2d9bbd25)
2020-06-05 14:53:29 +02:00
Meghea Iulian
67970814b0 atlassian-jira: 8.8.0 -> 8.9.0
(cherry picked from commit 9b5df08902)
2020-06-05 14:47:07 +02:00
Florian Klink
58f884cd3d Merge pull request #89435 from flokli/20.03/gitlab-12.10.9
[20.03] gitlab: 12.8.10 -> 12.10.9
2020-06-05 01:32:12 +02:00
Frederik Rietdijk
6939378871 Merge staging-20.03 into release-20.03 2020-06-04 19:04:16 +02:00
Maximilian Bosch
ea2d173ead riot-desktop: 1.6.2 -> 1.6.3
https://github.com/vector-im/riot-desktop/releases/tag/v1.6.3
(cherry picked from commit 91099c1426)
2020-06-04 18:11:15 +02:00
Maximilian Bosch
bad756a2c9 riot-web: 1.6.2 -> 1.6.3
https://github.com/vector-im/riot-web/releases/tag/v1.6.3
(cherry picked from commit c51202ffa0)
2020-06-04 18:11:14 +02:00
Peter Hoeg
7ec663fca9 Merge pull request #89458 from peterhoeg/bp/qqc2-desktop-style
kdeFrameworks.qqc2-desktop-style: init at 5.68 (backport to stable)
2020-06-04 20:57:29 +08:00
Peter Hoeg
1ce9a006d1 kdeFrameworks.qqc2-desktop-style: init at 5.68
(cherry picked from commit 9cc24aa9f0)
2020-06-04 13:32:17 +08:00
Florian Klink
2947a53a1b gitlab: 12.10.8 -> 12.10.9
(cherry picked from commit d7b09d36955f5319f58b20df304a06947324ecfb)
2020-06-03 21:33:08 +02:00
Robin Gloster
0610639809 gitlab: 12.10.6 -> 12.10.8
(cherry picked from commit af05325f10)
2020-06-03 21:32:54 +02:00
Robin Gloster
6bd20ee2ce gitaly: fix gitlab-shell-config path patching
(cherry picked from commit 7060927382)
2020-06-03 21:32:54 +02:00
Milan Pässler
d181fdf818 gitaly: revert a commit that broke config loading
(cherry picked from commit e32bf64da0)
2020-06-03 21:32:53 +02:00
Milan Pässler
3069def979 nixos/gitlab: use new structure.sql
According to https://gitlab.com/gitlab-org/gitlab/-/issues/211487

(cherry picked from commit 47c8e52a22)
2020-06-03 21:32:53 +02:00
Milan Pässler
2968e6fd54 gitlab: increase webpack memory limit
(cherry picked from commit 755554808f)
2020-06-03 21:32:53 +02:00
Milan Pässler
3a0a5e54e6 gitlab: 12.8.10 -> 12.10.6
(cherry picked from commit f61370214c)
2020-06-03 21:32:52 +02:00
WilliButz
05a32d8e77 Merge pull request #89422 from Frostman/20.03-grafana-6.7.4
[20.03] grafana: 6.7.1 -> 6.7.4
2020-06-03 18:05:41 +02:00
Sergey Lukjanov
ca7a4d1c3e grafana: 6.7.1 -> 6.7.4 2020-06-03 08:48:57 -07:00
Maximilian Bosch
08c346a724 Merge pull request #89398 from ehmry/tor-browser
tor-browser-bundle-bin: 9.0.9 -> 9.5
2020-06-03 14:12:44 +02:00
Simon Lackerbauer
5c5e386903 atlassian-confluence: 7.4.0 -> 7.5.0
(cherry picked from commit ca59421dcd)
2020-06-03 13:44:57 +02:00
R. RyanTM
28d19fada3 atlassian-confluence: 7.3.4 -> 7.4.0
(cherry picked from commit cace963fc1)
2020-06-03 13:44:54 +02:00
Emery Hemingway
75322687a2 tor-browser-bundle-bin: 9.0.9 -> 9.5 2020-06-03 17:10:41 +05:30
Lucas Abel
ede11844d6 jetbrains: update
fixed missing zlib path to rpath in the clion bundled clangd binary

(cherry picked from commit 3b605eaee6)
2020-06-03 11:24:01 +01:00
Maximilian Bosch
619787790a roundcube: 1.4.4 -> 1.4.5
https://github.com/roundcube/roundcubemail/releases/tag/1.4.5
(cherry picked from commit b236a58b27)
2020-06-03 09:14:42 +02:00
Mario Rodas
be20f1eb3d Merge pull request #89148 from zowoq/backport-gh
[20.03]  gitAndTools.gh: 0.8.0 -> 0.9.0
2020-06-02 20:10:37 -05:00
toonn
4606ae3e4d wire-desktop: mac 3.17.3666 -> 3.18.3728
(cherry picked from commit 9535a4370b08175947ea06871c3f548dbb6aa94b)
2020-06-02 20:18:52 +02:00
toonn
bf8b946429 wire-desktop: linux 3.17.2924 -> 3.18.2925
(cherry picked from commit 3e2b6b99bff59aac7e2c961802583d350106192e)
2020-06-02 20:18:39 +02:00
Maximilian Bosch
79d7841ecf mautrix-whatsapp: 2020-05-29 -> 2020-06-01
(cherry picked from commit 7cae204ed9)
2020-06-02 18:22:46 +02:00
Maximilian Bosch
20fcae3cd5 Merge pull request #89336 from Frostman/docker-backport-19.03.11
[20.03] docker: 19.03.5 -> 19.03.11
2020-06-02 16:36:11 +02:00
Benjamin Hipple
17a610645a go-bindata: use fetchFromGitHub
Cleaned up expression as well. Verified sha256 is reproducible and unchanged.

(cherry picked from commit 55143290ba)
2020-06-02 10:11:02 -04:00
Benjamin Hipple
6567ff5ac4 colormake: use fetchFromGitHub
Verified the sha256 does not change.

(cherry picked from commit a25bdf1742)
2020-06-02 10:09:19 -04:00
Sergey Lukjanov
4aad3f5422 docker: 19.03.10 -> 19.03.11
(cherry picked from commit a4ea8abae6)
2020-06-01 17:10:24 -07:00
Sergey Lukjanov
33973b7fc0 docker: 19.03.9 -> 19.03.10
(cherry picked from commit c8dddcb1a9)
2020-06-01 17:10:24 -07:00
Sergey Lukjanov
1e1b0acd28 docker: 19.03.8 -> 19.03.9
(cherry picked from commit fb3039d91b)
2020-06-01 17:10:23 -07:00
zowoq
52cc587778 docker: use installShellFiles
(cherry picked from commit 764dd5c875)
2020-06-01 17:10:23 -07:00
Milan Pässler
7bf0d1cbaf docker: add git to extraPath
When building a docker container from git, docker was missing the git
binary in $PATH.

(cherry picked from commit 08d83c1641)
2020-06-01 17:10:23 -07:00
Sander van der Burg
45bfb96ecd dblatex: add pdflscape as a dependency
Without it, building a document fails with the following error:

pdflatex failed
index.tex: File `pdflscape.sty' not found.
index.tex:47: Emergency stop.

(cherry picked from commit 75b0777831)
2020-06-01 23:15:18 +02:00
James Ravn
5cd1d38344 firmwareLinuxNonfree: 2020-01-22 -> 2020-05-19
(cherry picked from commit 46f2bf63a4)
2020-06-01 19:55:30 +01:00
Marek Mahut
4a2da01389 Merge pull request #88550 from prusnak/electron-20.03
[20.03] Update Electron 6,7,8
2020-06-01 18:10:05 +02:00
Maximilian Bosch
bdee06778f alacritty: 0.4.2 -> 0.4.3
https://github.com/alacritty/alacritty/releases/tag/v0.4.3
(cherry picked from commit 043ecdbe96)
2020-06-01 10:03:21 +02:00
Maximilian Bosch
7a21e9fd96 mautrix-whatsapp: 2020-05-27 -> 2020-05-29
(cherry picked from commit 55fea6d252)
2020-06-01 09:52:37 +02:00
Vladimír Čunát
d6d6a8772c Merge branch 'staging-20.03' into release-20.03 2020-06-01 08:01:24 +02:00
aszlig
36641b25e7 ip2unix: 2.1.2 -> 2.1.3
Upstream fixes:

  - Pass linker version script to the linker instead of the compiler.
  - Compile with `-fPIC` again (regression from version 2.1.2).
  - Out of bounds array access in `globpath`.
  - Handling of `epoll_ctl` calls (they're now replayed after replacing
    socket).
  - GCC 10 build errors and Clang warnings.

While most of these fixes are more relevant for other distros, the
linker script fix is actually a regression existing since a long time
(version 1.x) and caused libip2unix to expose way too many symbols.

Built and tested on i686-linux and x86_64-linux.

Signed-off-by: aszlig <aszlig@nix.build>
(cherry picked from commit 67325b12c6)
2020-06-01 05:51:31 +02:00
Maximilian Bosch
4a7821a1d3 linuxPackages.wireguard: 1.0.20200506 -> 1.0.20200520
https://lists.zx2c4.com/pipermail/wireguard/2020-May/005450.html
(cherry picked from commit e90c5fe0ec)
2020-05-31 21:30:24 +02:00
Trolli Schmittlauch
44c1be57f6 cawbird: 1.0.5 -> 1.1.0
(cherry picked from commit 4e455343e7)
2020-05-31 19:50:23 +02:00
Robin Gloster
aca160ea22 docker-compose: fix zsh completion
(cherry picked from commit f7056dca74)
2020-05-31 16:05:59 +02:00
Maximilian Bosch
dc2683422e matrix-synapse: 1.13.0 -> 1.14.0
https://github.com/matrix-org/synapse/releases/tag/v1.14.0
(cherry picked from commit d11dcafe93)
2020-05-31 13:27:26 +02:00
R. RyanTM
79076235eb python27Packages.authlib: 0.13 -> 0.14.3
Rationale for backport: only used by `matrix-synapse` atm which requires
0.14 to work.

(cherry picked from commit c37b4466c0)
(cherry picked from commit 7c6a40c812)
2020-05-31 13:26:04 +02:00
Maximilian Bosch
3c90d4c6db gitea: 1.11.5 -> 1.11.6
https://github.com/go-gitea/gitea/releases/tag/v1.11.6
(cherry picked from commit 69d71eb2a3)
2020-05-31 11:45:59 +02:00
Vladimír Čunát
5fc6f8c19b glibc: patch CVE-2020-1752
/cc roundup #88306; the issue seems quite serious to me.

I also made two other patches non-conditional, as we rebuild
all platforms anyway.

(cherry picked from commit 3f08d642fe)
2020-05-31 11:02:29 +02:00
Frederik Rietdijk
5150040540 python38: 3.8.2 -> 3.8.3
(cherry picked from commit 0367fa630d)
2020-05-31 08:31:34 +02:00
Jonathan Ringer
c570247bad python38: 3.8.1 -> 3.8.2
(cherry picked from commit 2a019cc48c)
2020-05-31 08:31:31 +02:00
Frederik Rietdijk
7b1fab74f5 Merge release-20.03 into staging-20.03 2020-05-31 08:30:32 +02:00
Michael Howell
5a462920ca buildRustCrate: Replace hyphen with underscore in env variables (#88054)
* Add test case for include dir
* buildRustCrate: replace hyphen with underscore in env

This fixes a bug that prevents encoding_c from building.

(cherry picked from commit c21cbf22d0)
2020-05-30 21:49:36 +02:00
Léo Gaspard
acba0f12f8 nix-daemon module: do not rely on the daemon being running (#89191) 2020-05-30 21:47:37 +02:00
Mario Rodas
d124852591 Merge pull request #89149 from zowoq/backport-ffmpeg
[20.03] ffmpeg{_4,-full}, ffmpeg_2_8
2020-05-30 09:55:55 -05:00
Lassulus
adad0021b7 Merge pull request #88878 from mweinelt/20.03/activemq
[20.03] activemq: 5.14.5 -> 5.15.12
2020-05-30 09:39:41 +02:00
Jethro Kuan
e7752db2fb mkdocs: default to Python 3
(cherry picked from commit ee17a6a837)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-05-29 14:39:09 +02:00
Luflosi
6fe8bd0255 youtube-dl: 2020.05.08 -> 2020.05.29
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.05.29
(cherry picked from commit cd0b121d4b)
2020-05-29 12:02:47 +02:00
zowoq
e478626346 gitAndTools.gh: 0.8.0 -> 0.9.0
https://github.com/cli/cli/releases/tag/v0.9.0
(cherry picked from commit ad77631a6a)
2020-05-29 15:38:56 +10:00
zowoq
1a1018d076 ffmpeg-full: 4.2.2 -> 4.2.3
(cherry picked from commit f7c914e96e)
2020-05-29 15:38:02 +10:00
zowoq
0fbd5804b7 ffmpeg_4: 4.2.2 -> 4.2.3
(cherry picked from commit 0e384147f9)
2020-05-29 15:37:53 +10:00
zowoq
e696f114ee ffmpeg_2_8: 2.8.15 -> 2.8.16
(cherry picked from commit cfaa8035d7)
2020-05-29 15:37:35 +10:00
Martin Milata
e985ffea2d pokerth: use mkDerivation from Qt
(cherry picked from commit 75bb71bc70)
2020-05-28 17:39:41 +02:00
Tim Steinbach
71c059d12a linux: 5.6.14 -> 5.6.15 2020-05-28 09:37:43 -04:00
Tim Steinbach
3c14fbe1f1 linux: 5.4.42 -> 5.4.43 2020-05-28 09:37:43 -04:00
Tim Steinbach
4a30f484a2 linux: 4.9.224 -> 4.9.225 2020-05-28 09:37:43 -04:00
Tim Steinbach
aa561d2e55 linux: 4.4.224 -> 4.4.225 2020-05-28 09:37:43 -04:00
Tim Steinbach
eb2a7b298b linux: 4.19.124 -> 4.19.125 2020-05-28 09:37:43 -04:00
Tim Steinbach
3c2e8afd7a linux: 4.14.181 -> 4.14.182 2020-05-28 09:37:43 -04:00
rnhmjoj
49d31fd37c pirate-get: 0.3.7 -> 0.4.0
(cherry picked from commit ffa3b2b459)
2020-05-28 15:20:47 +02:00
R. RyanTM
d2a329ff38 pirate-get: 0.3.5 -> 0.3.7
(cherry picked from commit 2dde5ffe4a)
2020-05-28 15:20:40 +02:00
Dennis Gosnell
d55a904271 Merge pull request #89092 from maralorn/fix-shh-stable
[20.03] haskellPackages.shh: Disable tests
2020-05-28 21:06:08 +09:00
Domen Kožar
0f04d94746 Merge pull request #89094 from Mic92/backport-nix-build-uncached
[backport] nix-build-uncached: init at 0.1.1
2020-05-28 12:43:22 +02:00
Cole Mickens
777b80ff26 nix-build-uncached: init at 0.1.1
(cherry picked from commit 021662cf13)
2020-05-28 11:33:41 +01:00
Malte Brandy
3b3082aa4b haskellPackages.shh: Disable tests
(cherry picked from commit feb3b2d55bc7d47ff1647119dd9f837e98608d66)
2020-05-28 11:40:57 +02:00
Mario Rodas
64a59a5b30 Merge pull request #88798 from NinjaTrappeur/nin-backport-prosody-bump
[20.03] prosody: 0.11.3 -> 0.11.5
2020-05-27 23:55:34 -05:00
rnhmjoj
93b68c7cc5 nixos/dnscrypt-wrapper: use dnscrypt-proxy1
(cherry picked from commit fd3727a313)

This commit fixes the currently broken dnscrypt-wrapper module.
2020-05-27 21:19:56 +02:00
Eelco Dolstra
711890f131 nix: 2.3.4 -> 2.3.5
(cherry picked from commit e8896deced)
2020-05-27 16:49:27 +02:00
Maximilian Bosch
fc60ed1fff mautrix-whatsapp: 2020-05-21 -> 2020-05-27
(cherry picked from commit 1b5925f218)
2020-05-27 16:16:15 +02:00
Maximilian Bosch
7fe32e74f1 cargo-make: 0.30.7 -> 0.30.8
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.8
(cherry picked from commit 45e53a7658)
2020-05-27 16:16:15 +02:00
Sebastien Bourdeauducq
0aa5f60434 python: svgwrite: disable on Python 3.8 2020-05-26 22:44:26 -07:00
aszlig
4cdf2a57d6 ip2unix: 2.1.1 -> 2.1.2
This fixes the issues with glibc 2.30, which were caused because glibc
no longer allows to dlopen/LD_PRELOAD a PIE executable.

So this release is essentially just a hotfix release which addresses
this issue by splitting the executable and library.

Signed-off-by: aszlig <aszlig@nix.build>
Reported-by: @zimbatm
(cherry picked from commit b51d39fbe4)
2020-05-27 06:02:26 +02:00
Eelco Dolstra
29cc418d94 nixFlakes: 2.4pre20200501_941f952 -> 2.4pre20200521_00b562c
(cherry picked from commit fdecd9eeda)
2020-05-26 11:20:32 +02:00
Antoine Eiche
dfb8c3bb10 nixUnstable: pre7346_5e7ccdc9 -> pre7534_b92f58f6
(cherry picked from commit 15d1011615)
2020-05-26 11:20:20 +02:00
Edmund Wu
c613175fc9 nixFlakes: 2.4pre20200403_3473b19 -> 2.4pre20200501_941f952
(cherry picked from commit f1e3278849)
2020-05-26 11:19:40 +02:00
Pavol Rusnak
9ffb853d51 treewide: use https for nixos.org and hydra.nixos.org
tarballs.nixos.org is omitted from the change because urls from there
are always hashed and checked

(cherry picked from commit 7b0167204d)
2020-05-26 11:18:53 +02:00
Michele Guerini Rocco
556b6f35f6 Merge pull request #88884 from woffs/pr-fix-86540
[20.03] nixos/i2pd: address #63103
2020-05-26 08:49:02 +02:00
Edward Tjörnhammar
ef573a2665 nixos/i2pd: address #63103
As a comment to 1d61efb7f1
Note that collect returns a list from a set

(cherry picked from commit 9bab9e2ec6)
2020-05-25 19:50:04 +02:00
Martin Weinelt
3f4ce0886d activemq: 5.14.5 -> 5.15.12
Fixes: CVE-2020-1941
(cherry picked from commit 6011b231a7)
2020-05-25 17:38:35 +02:00
Vladimír Čunát
136e4c1fb0 knot-dns: 2.9.4 -> 2.9.5
There's a bugfix important for some auto-signer setups.
https://gitlab.labs.nic.cz/knot/knot-dns/-/tags/v2.9.5

(cherry picked from commit da752902c1)
$ nix build -f nixos/release-combined.nix nixos.tests.knot.x86_64-linux
2020-05-25 11:08:38 +02:00
Florian Klink
4068ae5e48 Merge pull request #88829 from emilazy/acme-use-ec256-20.03
[20.03] nixos/acme: change default keyType to ec256
2020-05-25 11:05:21 +02:00
Emily
8cc8fa19d9 nixos/acme: change default keyType to ec256
Previously, the NixOS ACME module defaulted to using P-384 for
TLS certificates. I believe that this is a mistake, and that we
should use P-256 instead, despite it being theoretically
cryptographically weaker.

The security margin of a 256-bit elliptic curve cipher is substantial;
beyond a certain level, more bits in the key serve more to slow things
down than add meaningful protection. It's much more likely that ECDSA
will be broken entirely, or some fatal flaw will be found in the NIST
curves that makes them all insecure, than that the security margin
will be reduced enough to put P-256 at risk but not P-384. It's also
inconsistent to target a curve with a 192-bit security margin when our
recommended nginx TLS configuration allows 128-bit AES. [This Stack
Exchange answer][pornin] by cryptographer Thomas Pornin conveys the
general attitude among experts:

> Use P-256 to minimize trouble. If you feel that your manhood is
> threatened by using a 256-bit curve where a 384-bit curve is
> available, then use P-384: it will increases your computational and
> network costs (a factor of about 3 for CPU, a few extra dozen bytes
> on the network) but this is likely to be negligible in practice (in a
> SSL-powered Web server, the heavy cost is in "Web", not "SSL").

[pornin]: https://security.stackexchange.com/a/78624

While the NIST curves have many flaws (see [SafeCurves][safecurves]),
P-256 and P-384 are no different in this respect; SafeCurves gives
them the same rating. The only NIST curve Bernstein [thinks better of,
P-521][bernstein] (see "Other standard primes"), isn't usable for Web
PKI (it's [not supported by BoringSSL by default][boringssl] and hence
[doesn't work in Chromium/Chrome][chromium], and Let's Encrypt [don't
support it either][letsencrypt]).

[safecurves]: https://safecurves.cr.yp.to/
[bernstein]: https://blog.cr.yp.to/20140323-ecdsa.html
[boringssl]: https://boringssl.googlesource.com/boringssl/+/e9fc3e547e557492316932b62881c3386973ceb2
[chromium]: https://bugs.chromium.org/p/chromium/issues/detail?id=478225
[letsencrypt]: https://letsencrypt.org/docs/integration-guide/#supported-key-algorithms

So there's no real benefit to using P-384; what's the cost? In the
Stack Exchange answer I linked, Pornin estimates a factor of 3×
CPU usage, which wouldn't be so bad; unfortunately, this is wildly
optimistic in practice, as P-256 is much more common and therefore
much better optimized. [This GitHub comment][openssl] measures the
performance differential for raw Diffie-Hellman operations with OpenSSL
1.1.1 at a whopping 14× (even P-521 fares better!); [Caddy disables
P-384 by default][caddy] due to Go's [lack of accelerated assembly
implementations][crypto/elliptic] for it, and the difference there seems
even more extreme: [this golang-nuts post][golang-nuts] measures the key
generation performance differential at 275×. It's unlikely to be the
bottleneck for anyone, but I still feel kind of bad for anyone having
lego generate hundreds of certificates and sign challenges with them
with performance like that...

[openssl]: https://github.com/mozilla/server-side-tls/issues/190#issuecomment-421831599
[caddy]: 2cab475ba5/modules/caddytls/values.go (L113-L124)
[crypto/elliptic]: 2910c5b4a0/src/crypto/elliptic
[golang-nuts]: https://groups.google.com/forum/#!topic/golang-nuts/nlnJkBMMyzk

In conclusion, there's no real reason to use P-384 in general: if you
don't care about Web PKI compatibility and want to use a nicer curve,
then Ed25519 or P-521 are better options; if you're a NIST-fearing
paranoiac, you should use good old RSA; but if you're a normal person
running a web server, then you're best served by just using P-256. Right
now, NixOS makes an arbitrary decision between two equally-mediocre
curves that just so happens to slow down ECDH key agreement for every
TLS connection by over an order of magnitude; this commit fixes that.

Unfortunately, it seems like existing P-384 certificates won't get
migrated automatically on renewal without manual intervention, but
that's a more general problem with the existing ACME module (see #81634;
I know @yegortimoshenko is working on this). To migrate your
certificates manually, run:

    $ sudo find /var/lib/acme/.lego/certificates -type f -delete
    $ sudo find /var/lib/acme -name '*.pem' -delete
    $ sudo systemctl restart 'acme-*.service' nginx.service

(No warranty. If it breaks, you get to keep both pieces. But it worked
for me.)

(cherry picked from commit 62e34d1c87)
2020-05-24 23:51:26 +01:00
Martin Milata
178be92955 prosody: 0.11.3 -> 0.11.5
- https://prosody.im/doc/release/0.11.4
- https://prosody.im/doc/release/0.11.5

(cherry picked from commit ce2a2afac7)
2020-05-24 20:45:17 +02:00
Vladimír Čunát
81b7dad9c5 Merge #87237: gcc10, gfortran10: init at 10.1.0
(cherry picked from commit 2e192dc5db)
It's just adding new packages; they might be useful on 20.03 as well.
We didn't have gnat backported to 20.03, so I didn't touch that.
2020-05-24 10:35:53 +02:00
Vladimír Čunát
37d4e29f33 Merge #88657: thunderbird*: 68.8.0 -> 68.8.1
(cherry picked from commit fa4e5b505f)
I re-tested both briefly on 20.03.
2020-05-24 10:26:33 +02:00
Silvan Mosberger
df35e70903 Merge pull request #88719 from maralorn/fix-shh-stable 2020-05-24 02:25:16 +02:00
Maximilian Bosch
198cac07cf epson-escpr2: 1.1.11 -> 1.1.12
(cherry picked from commit 3ddc56ca14)
2020-05-24 01:37:20 +02:00
Maximilian Bosch
675bf76c3d bandwhich: 0.14.0 -> 0.15.0
https://github.com/imsnif/bandwhich/releases/tag/0.15.0
(cherry picked from commit 26d670c101)
2020-05-24 01:37:20 +02:00
Aaron Andersen
c0f19a3abf Merge pull request #87180 from aanderse/zabbix-backport
zabbix: 3.0.29 -> 3.0.31 [20.03]
2020-05-23 18:57:41 -04:00
Maximilian Bosch
404041b20b wireguard-go: keep $bin/bin/wireguard for backwards-compat
As proposed in https://github.com/NixOS/nixpkgs/pull/88610#issuecomment-633145335
2020-05-24 00:08:12 +02:00
Malte Brandy
de2e5c4029 haskellPackages.shh: Mark unbroken 2020-05-23 23:51:10 +02:00
Maximilian Bosch
88b93513c1 wireguard-go: fix executable name
It's supposed to be `wireguard-go` instead of `wireguard`. Upstream does
this right in their Makefile, however we use our own build-script which
creates a wrong file in $out, so it has to be fixed in the
`postInstall`-hook.

Closes #88567

(cherry picked from commit 0f65693e6b)
2020-05-23 23:31:44 +02:00
Markus Kowalewski
b13ffa2aef welle-io: add qtgraphicaleffects to inputs
programm fails to start without this package

(cherry picked from commit 68160d7b78)
2020-05-23 13:51:38 +02:00
Vladimír Čunát
1a02977427 pdns-recursor: 4.2.1 -> 4.2.2 (security)
https://blog.powerdns.com/2020/05/19/powerdns-recursor-4-3-1-4-2-2-and-4-1-16-released/
$ nix build -f nixos/release.nix tests.pdns-recursor.x86_64-linux
NixPkgs master is on 4.3.x already; /cc that PR #88159
2020-05-23 11:11:10 +02:00
Vladimír Čunát
9712027d46 knot-resolver: 5.1.0 -> 5.1.1 (security, PR #88159)
https://en.blog.nic.cz/2020/05/19/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack/
(cherry picked from commit d0d90908c8)
2020-05-23 10:46:15 +02:00
Vladimír Čunát
05fe963339 knot-resolver: 5.0.1 -> 5.1.0
https://gitlab.labs.nic.cz/knot/knot-resolver/-/tags/v5.1.0

The upcoming major version will contain reworked
hints/policy/prefill/rebinding/view modules and related functionalities.
Please participate in the following survey to ensure we do not forget
about your particular use-case:
https://www.knot-resolver.cz/survey/
It will help us to improve Knot Resolver. Thank you!

(cherry picked from commit 26d3ae2f24)
This is needed for the followup security bump.
2020-05-23 10:45:23 +02:00
Vladimír Čunát
0b473aaca6 bind: 9.14.11 -> 9.14.12 (security, PR #88159)
https://www.isc.org/blogs/bind9-vulnerabilities-2020-05/
$ nix build -f nixos/release.nix tests.bind.x86_64-linux

(cherry picked from commit 13c485d63d)
2020-05-23 10:43:03 +02:00
Jörg Thalheim
b5d622a7cd Merge pull request #88553 from Mic92/openafs-backport 2020-05-23 08:19:58 +01:00
adisbladis
a808fe4fcd Merge pull request #88619 from pacien/20.03-revert-containers-pkgs
[20.03] revert containers pkgs
2020-05-23 00:11:21 +02:00
pacien
8d22d0f43a Revert "nixos-containers: Add support for custom nixpkgs argument"
The referred changeset broke overlays inside NixOS containers.
See nixos/tests/containers-nixpkgs-overlays.nix.

This reverts commit aa72037b06.
2020-05-22 20:08:46 +02:00
pacien
0eec48c89a nixos-containers: add test checking that overlays work in containers 2020-05-22 20:07:39 +02:00
Maximilian Bosch
8ada044ed4 riot-desktop: 1.6.1 -> 1.6.2
https://github.com/vector-im/riot-web/releases/tag/v1.6.2
(cherry picked from commit 84ede87458)
2020-05-22 17:20:40 +02:00
Maximilian Bosch
2816f9e501 riot-web: 1.6.1 -> 1.6.2
https://github.com/vector-im/riot-web/releases/tag/v1.6.2
(cherry picked from commit 7dcff0dab5)
2020-05-22 17:20:39 +02:00
Maximilian Bosch
d91569ab1a mautrix-whatsapp: 2020-04-21-1 -> 2020-05-21
(cherry picked from commit 5cdc8f4818)
2020-05-22 17:20:34 +02:00
Maximilian Bosch
926c211abf documize-community: 3.7.0 -> 3.8.0
https://github.com/documize/community/releases/tag/v3.8.0
(cherry picked from commit 7857634d3f)
2020-05-22 16:50:14 +02:00
Robert Hensing
6a5e279ab7 Merge pull request #88077 from NixOS/staging-20.03
Staging 20.03
2020-05-22 14:55:04 +02:00
Yannis Koutras
48723f48ab Merge pull request #88501 from jokogr/u/fritzconnection-1.2.1-20.03
[20.03] pythonPackages.fritzconnection: 0.8.4 -> 1.2.1
2020-05-22 11:40:20 +02:00
Jörg Thalheim
10a5f5a46b Merge pull request #88437 from Atemu/anbox-lxc-fix
lxc: backport cpuset initialisation fix
2020-05-22 10:22:20 +01:00
Florian Klink
b075410ba8 Merge pull request #88563 from peterhoeg/f/obs_2003
obs-studio: show the actual version instead of 0.0.1
2020-05-22 11:17:34 +02:00
Peter Hoeg
b60e37dc05 obs-studio: show the actual version instead of 0.0.1
(cherry picked from commit 23e40675eb)
2020-05-22 08:57:31 +08:00
R. RyanTM
de493bd749 graylog: 3.2.4 -> 3.2.5
(cherry picked from commit 878e720ba4)
2020-05-22 00:53:49 +02:00
Jörg Thalheim
ae901c4cf9 openafs_1_8: include 5.6 fixes
(cherry picked from commit 027908357f)
2020-05-21 23:12:19 +01:00
Pavol Rusnak
a99bb404cf electron_8: 8.0.0 -> 8.3.0
(cherry picked from commit 72aebd3423)
2020-05-21 23:35:27 +02:00
Pavol Rusnak
b3c5bba058 electron_7: 7.1.10 -> 7.3.0
(cherry picked from commit eee7e5bd3a)
2020-05-21 23:35:13 +02:00
Pavol Rusnak
9a5239fa5f electron_6: 6.1.7 -> 6.1.12
(cherry picked from commit 77cade8175)
2020-05-21 23:35:03 +02:00
Bjørn Forsman
6d68b920eb gnomeExtensions: add 'uuid' attr to all extensions
Some already have it, this adds it to the rest.

With all extensions having an 'uuid' attr we can do cool things like
declaratively enable extensions on NixOS.

(cherry picked from commit eb12149979)
2020-05-21 14:47:28 +02:00
Vladimír Čunát
6681b0c1e3 Merge branch 'release-20.03' into staging-20.03 2020-05-21 13:34:48 +02:00
Vladimír Čunát
f9cf6f3cb6 unbound: 1.9.5 -> 1.10.1 (security)
https://www.nlnetlabs.nl/news/2020/May/19/unbound-1.10.1-released/
It fixes DoS CVEs; details e.g. on http://www.nxnsattack.com/

On each Linux platform this should be around 8k rebuilds,
so as a compromise I'm pushing to staging-next.

(cherry picked from commit 73390e3349)
The change from 1.9.5 to 1.10.0 also seems basically without backwards
incompatibilities; so I took it whole.  Perhaps just this minor thing:
- Renamed statistic `num.zero_ttl` to `num.expired` as expired replies
  come with a configurable TTL value (`serve-expired-reply-ttl`).
https://lists.nlnetlabs.nl/pipermail/unbound-users/2020-February/006711.html
2020-05-21 13:31:48 +02:00
Vincent Breitmoser
0edf164f94 pythonPackages.fritzconnection: 0.8.4 -> 1.2.1 2020-05-21 12:14:10 +02:00
Vincent Breitmoser
99be6166a4 maintainers: add valodim
(cherry picked from commit 52ac65c027)
2020-05-21 12:14:10 +02:00
Michael Weiss
a18eaa7b93 Merge pull request #88364 from primeos/chromium-backport
[20.03] chromium: 81.0.4044.138 -> 83.0.4103.61 (backport)
2020-05-20 22:11:45 +02:00
Maximilian Bosch
17fba7a504 Merge pull request #88423 from Ma27/backport-matrix-synapse
[20.03] matrix-synapse: 1.12.4 -> 1.13.0
2020-05-20 20:49:04 +02:00
Atemu
7a556b3393 lxc: backport cpuset initialisation fix
Fixes #88430
2020-05-20 16:21:41 +02:00
adisbladis
52e6737d0d Merge pull request #88402 from adisbladis/nixos-containers-pkgs-2003
nixos-containers: Add support for custom nixpkgs argument (20.03 backport)
2020-05-20 15:15:26 +02:00
Maximilian Bosch
3247b10fa3 matrix-synapse: 1.12.4 -> 1.13.0
https://github.com/matrix-org/synapse/releases/tag/v1.13.0
(cherry picked from commit 2a5b0bc813)
2020-05-20 14:33:04 +02:00
Maximilian Bosch
5d12be83a6 riot-desktop: 1.6.0 -> 1.6.1
https://github.com/vector-im/riot-desktop/releases/tag/v1.6.1

Also updated the package since `riot-desktop` has been moved to its own
repository (`github.com/vector-im/riot-desktop`).

(cherry picked from commit 307dfd90dc)
2020-05-20 14:32:14 +02:00
Maximilian Bosch
0436b0d8a2 riot-web: 1.6.0 -> 1.6.1
https://github.com/vector-im/riot-web/releases/tag/v1.6.1
(cherry picked from commit 0db36eaab9)
2020-05-20 14:32:14 +02:00
Tim Steinbach
9131abd1bf linux: 5.6.13 -> 5.6.14 2020-05-20 08:31:25 -04:00
Tim Steinbach
dd9136744f linux: 5.4.41 -> 5.4.42 2020-05-20 08:31:25 -04:00
Tim Steinbach
f0e8db1128 linux: 4.9.223 -> 4.9.224 2020-05-20 08:31:25 -04:00
Tim Steinbach
cfbfd2b4d5 linux: 4.4.223 -> 4.4.224 2020-05-20 08:31:25 -04:00
Tim Steinbach
7a29263e0a linux: 4.19.123 -> 4.19.124 2020-05-20 08:31:25 -04:00
Tim Steinbach
906f7fb0d1 linux: 4.14.180 -> 4.14.181 2020-05-20 08:31:25 -04:00
adisbladis
aa72037b06 nixos-containers: Add support for custom nixpkgs argument
(cherry picked from commit ab37d7e7ea)
2020-05-20 12:13:44 +01:00
Michael Weiss
2de75cabe7 chromium: 81.0.4044.138 -> 83.0.4103.61
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html

This update includes 38 security fixes.

CVEs:
CVE-2020-6465 CVE-2020-6466 CVE-2020-6467 CVE-2020-6468 CVE-2020-6469
CVE-2020-6470 CVE-2020-6471 CVE-2020-6472 CVE-2020-6473 CVE-2020-6474
CVE-2020-6475 CVE-2020-6476 CVE-2020-6477 CVE-2020-6478 CVE-2020-6479
CVE-2020-6480 CVE-2020-6481 CVE-2020-6482 CVE-2020-6483 CVE-2020-6484
CVE-2020-6485 CVE-2020-6486 CVE-2020-6487 CVE-2020-6488 CVE-2020-6489
CVE-2020-6490 CVE-2020-6491

(cherry picked from commit cdd95a9625)
2020-05-20 12:01:14 +02:00
Matthias Beyer
7063fb7f64 timewarrior: Fix homepage
Thanks to repology.org

Signed-off-by: Matthias Beyer <mail@beyermatthias.de>
(cherry picked from commit 1b5ae92f0f)
2020-05-20 11:47:36 +02:00
Andreas Rammhold
f45ccd9d20 Merge pull request #88081 from mweinelt/20.03/dovecot
[20.03] dovecot: v2.3.9.3 → v2.3.10.1
2020-05-20 11:42:56 +02:00
Benjamin Hipple
942ce73038 Merge pull request #88240 from kthielen/hobbes/20200519
[20.03] hobbes: 2020-03-10 -> 2020-05-19
2020-05-19 23:37:07 -04:00
Kalani Thielen
81d9be3e8e [20.03] hobbes: 2020-03-10 -> 2020-05-19 2020-05-19 23:25:23 -04:00
TQ Hirsch
afb1e7216e boost: Fix library and include paths in generated cmake files
Boost generates its installed cmake configuration using custom logic
in its own build system; while this logic *knows* where it should be
installed, the generated config overrides the correct information with
new paths based on the location of the cmake configuration file in an
attempt to let the package be relocated after installation.

This patch simply undoes that.

(cherry picked from commit 777df0b4a5)
2020-05-19 20:42:45 -04:00
TQ Hirsch
015ac0cb6a aws-sdk-cpp: Fix library and include paths in generated cmake files
AWS's SDK by default tries to prepend its install root to each of the
library paths; this obviously fails with the absolute paths that Nix
gives it. Worse, it computes the installation root by walking up the
filesystem from its cmake file, so even if the AWSSDK_ROOT_DIR is
explicitly set to the root directory, it gets replaced with the path
to the derivation's dev output.

This is all fixed with a patch to the cmake files that generate the
installed configuration.

Once this is fixed, it *still* doesn't work because the export
generator built into cmake insists on adding `$out/include` to the
header search path; when importing this configuration in another
package, cmake will fail because `$out/include` doesn't exist (After
all, it was relocated by a fixup hook). A small postFixupHook will
recreate the directory and make cmake happy.

(cherry picked from commit 9d7885276a)
2020-05-19 20:42:45 -04:00
Lancelot SIX
1f80b4d15e skypeforlinux: 8.59.0.77 -> 8.60.0.76
(cherry picked from commit f44e3d4501)
2020-05-19 22:38:06 +02:00
Seabass-Chan
42b96df6bd bcompare - 4.3.2.24472 -> 4.3.4.24657 (#84521)
Co-authored-by: Milan Pässler <mil@nyantec.com>
(cherry picked from commit 92688a1ed7)
2020-05-19 21:44:33 +02:00
Maximilian Bosch
82b5f87fcc wireguard-tools: 1.0.20200510 -> 1.0.20200513
https://lists.zx2c4.com/pipermail/wireguard/2020-May/005431.html
(cherry picked from commit 07a46f3b9b)
2020-05-19 09:19:41 +02:00
Martin Milata
57e9220f1b nextcloud18: 18.0.3 -> 18.0.4
Changes: https://nextcloud.com/changelog/#latest18
(cherry picked from commit ed301e7158)
2020-05-18 23:28:44 +02:00
Martin Milata
4166e368e9 nextcloud17: 17.0.4 -> 17.0.6
Changes: https://nextcloud.com/changelog/#latest17

Fixes: https://nvd.nist.gov/vuln/detail/CVE-2020-8154
(cherry picked from commit cd2a208bdb)
2020-05-18 23:28:44 +02:00
Louis Bettens
9659dbd518 oraclejdk8: 8u241 -> 8u251
(cherry picked from commit c3b743a692)
2020-05-18 22:28:52 +02:00
Martin Weinelt
9293520d9e dovecot: v2.3.10 → v2.3.10.1
Fixes: CVE-2020-10957, CVE-2020-10958, CVE-2020-10967
(cherry picked from commit 6cf48856d2)
2020-05-18 20:24:40 +02:00
R. RyanTM
9e7813354c dovecot: 2.3.9.3 -> 2.3.10
(cherry picked from commit 8d08f45368)
2020-05-18 20:24:37 +02:00
Pavel Goran
94492e861a gitea: fix wiki template incompatibility with go 1.14
Related to #87115.

(cherry picked from commit 64decd9de6)
2020-05-18 15:25:21 +02:00
Florian Klink
66901f0818 Merge pull request #88038 from mweinelt/20.03/ansible
[20.03] ansible: v2.9.2 → v2.9.9, v2.8.11 → v2.8.12, v2.7.17 → v2.7.18, mark v2.6 as insecure
2020-05-18 13:50:20 +02:00
Martin Weinelt
905b027331 ansible_2_6: mark as insecure
Ansible 2.6 went EOL in 2019/11/06 and several CVEs have since come up.
2020-05-18 13:11:48 +02:00
Martin Weinelt
b403f32223 ansible_2_7: v2.7.17 → v2.7.18
(cherry picked from commit 25233a5db7)
2020-05-18 13:11:48 +02:00
Martin Weinelt
3a1771d609 ansible_2_8: v2.8.11 → v2.8.12
(cherry picked from commit c0e6848ad7)
2020-05-18 13:11:48 +02:00
Martin Weinelt
92fd2e5e0b ansible: v2.9.7 → v2.9.9
(cherry picked from commit 0dea984634)
2020-05-18 13:11:48 +02:00
Martin Weinelt
46ee7806ca ansible: v2.9.2 → v2.9.7
Fixes: CVE-2020-10684, CVE-2020-1733, CVE-2020-1735, CVE-2020-1739, CVE-2020-1740
(cherry picked from commit dde157780c)
2020-05-18 13:11:48 +02:00
datafoo
ad96acbc09 nixos/zfs: add missing dependendy nettools
Fix #87823

(cherry picked from commit aa9a88d7bd649c56e35a6577d64eec687aa9f87c)
2020-05-18 12:09:03 +01:00
Aaron Andersen
216c101104 zabbix: 3.0.30 -> 3.0.31
(cherry picked from commit c2d3f26d1f)
2020-05-17 20:27:28 -04:00
Aaron Andersen
a1b16d3634 zabbix: 3.0.29 -> 3.0.30
(cherry picked from commit cc81ca7ee2)
2020-05-17 20:26:59 -04:00
Aaron Andersen
38e88e7f69 zabbix: update source url
(cherry picked from commit c85f02ca4e)
2020-05-17 20:26:33 -04:00
Jörg Thalheim
4d20bbc360 Merge pull request #87988 from phunehehe/sof-20.03 2020-05-17 20:35:47 +01:00
Michael Weiss
2eb0da8e5a Merge pull request #88018 from Elyhaka/fix-sway-wrapper-20.03
[20.03] sway: fix gtk wrapper
2020-05-17 20:29:45 +02:00
Ely
83cffb9505 sway: Fix the GTK wrapper (#86960)
Fixes #67704.

(cherry picked from commit cdfad5ad84)
2020-05-17 20:11:56 +02:00
Luka Blaskovic
2e1c5ded91 linux config: enable Sound Open Firmware support
(cherry picked from commit 6fc9fd53db)
2020-05-17 09:36:33 -04:00
Luka Blaskovic
c837ae911b sof-firmware: init at 1.4.2
(cherry picked from commit fe7f770666)
2020-05-17 09:36:33 -04:00
Robert Hensing
190080c121 Merge branch 'release-20.03' into staging-20.03 2020-05-17 13:37:27 +02:00
Elis Hirwing
7ca97fcde8 Merge pull request #87977 from talyz/composer-1.10.6-20.03
[20.03] phpPackages.composer: 1.9.1 -> 1.10.6
2020-05-17 13:36:04 +02:00
Elis Hirwing
a1fe90977e Merge pull request #87980 from talyz/phpstan-0.12.25-20.03
[20.03] phpPackages.phpstan: 0.12.4 -> 0.12.25
2020-05-17 13:34:35 +02:00
Robert Hensing
710c339b4d Merge pull request #88017 from hercules-ci/backport-20.03-fix-haskell-darwin-c-lib-links
[20.03] backport haskell/generic-builder.nix: Fix C lib multiple inclusions
2020-05-17 13:30:15 +02:00
Robert Hensing
233cec301c haskell/generic-builder.nix: Fix C lib multiple inclusions
Allow the darwin links code to overwrite libs that were already
copied, because C dependencies can occur multiple times.

Solves errors like

    ln: failed to create symbolic link '/nix/store/higpc9xavwcjjzdipz7m9ly03bh7iy2z-hercules-ci-agent-source-0.7.0/lib/links/libboost_context.dylib': File exists

(cherry picked from commit a9373cdb0aeca1bef291d74be1cecdca8e0c3c27)
2020-05-17 13:07:56 +02:00
Mario Rodas
025deb80b2 Merge pull request #87961 from eadwu/vscode/05-2020
vscode: 02/2020 backports
2020-05-16 19:50:48 -05:00
Kim Lindberger
bfa2cd0884 Merge pull request #87937 from etu/20.03-php74-update
[20.03] php74: 7.4.4 -> 7.4.6
2020-05-17 00:24:59 +02:00
talyz
b48b5133d2 phpPackages.phpstan: 0.12.4 -> 0.12.25 2020-05-16 22:40:58 +02:00
talyz
22c1ab0b8c phpPackages.composer: 1.9.1 -> 1.10.6 2020-05-16 22:24:50 +02:00
Michael Weiss
c999d2b68d Merge pull request #87964 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.34.0 -> 1.34.1 (backport)
2020-05-16 22:12:08 +02:00
Enno Lohmeier
fc12091888 ffmpeg: extend addOpenGLRunpath to handle libcuda referencing libraries
(cherry picked from commit 78987e2af0)
2020-05-16 21:51:47 +02:00
Enno Lohmeier
885a665807 ffmpeg-full: setup addOpenGLRunpath
(cherry picked from commit 96638775aa)
2020-05-16 21:24:27 +02:00
Michael Weiss
9f0c972d21 signal-desktop: 1.34.0 -> 1.34.1
(cherry picked from commit 347882f36a)
2020-05-16 19:28:26 +02:00
Manuel Bärenz
9624df4bc6 vscodium: Fix .desktop file
(cherry picked from commit 91f58ec9cc)
2020-05-16 13:15:30 -04:00
Joe
8396a9f828 vscode: remove unused option
The option "--skip-getting-started" no longer exists in vscode and causes files in "$@" to not be opened.
Message from stdout: "Warning: 'skip-getting-started' is not in the list of known options, but still passed to Electron/Chromium."
"--skip-getting-started" being removed: 6a8b201c8a

(cherry picked from commit f1e6d96a7831c7c9ea8243ea6d632ac604bbfe3a)
2020-05-16 13:15:28 -04:00
Edmund Wu
b33349c607 vscodium: 1.44.2 -> 1.45.0
(cherry picked from commit 36fb04be08)
2020-05-16 13:15:25 -04:00
Edmund Wu
44f95f4b55 vscode: 1.44.2 -> 1.45.0
(cherry picked from commit 301905d813)
2020-05-16 13:15:23 -04:00
Roman Kuznetsov
78a2877a9b vscode, vscodium: 1.44.1 -> 1.44.2
(cherry picked from commit ba774d4179)
2020-05-16 13:15:21 -04:00
Elis Hirwing
99f7c26f3f php74: 7.4.5 -> 7.4.6
Changelog: https://www.php.net/ChangeLog-7.php#7.4.6
(cherry picked from commit a779efcaa0)
2020-05-16 14:23:22 +02:00
Elis Hirwing
0cf13dd97d php74: 7.4.4 -> 7.4.5
Changelog: https://www.php.net/ChangeLog-7.php#7.4.5
(cherry picked from commit 52d2e99182)
2020-05-16 14:21:51 +02:00
Mario Rodas
8c1977c54a Merge pull request #87901 from lunik1/backport-megasync-4.3.0.8
[20.03] megasync 4.2.3.0 -> 4.3.0.9 (backport)
2020-05-16 06:58:39 -05:00
Jan Tojnar
729a3011c4 pytrainer: fix missing pkg_resources
(cherry picked from commit 04d6123309)
2020-05-16 13:13:52 +02:00
Andreas Rammhold
91cdcf3135 Merge pull request #87834 from andir/20.03/firefox
[20.03] firefox: 76.0 -> 76.0.1
2020-05-15 20:21:39 +02:00
Michael Weiss
39b049ee90 Merge pull request #87888 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.33.4 -> 1.34.0 (backport)
2020-05-15 19:53:26 +02:00
Michael Weiss
9faab3a3cb signal-desktop: Add passthru.tests
(cherry picked from commit facfa00202)
2020-05-15 19:28:10 +02:00
Kim Lindberger
2ad09a0811 Merge pull request #87844 from talyz/nomachine-6.10.12-archive-20.03
[20.03] nomachine-client: 6.9.2 -> 6.10.12, add archive.org to source urls
2020-05-15 18:53:39 +02:00
Alexander Tomokhov
81423b20f7 youtube-viewer: 3.3.0 -> 3.7.5
(cherry picked from commit 52ad14bbee)
2020-05-15 09:48:28 -07:00
Lila
a8650ff909 treewide: fix broken AlpineLinux repo links (#87892)
(cherry picked from commit 7517299146)
2020-05-15 17:00:45 +01:00
Patrick Hilhorst
2a83fa476a megasync: 4.2.5.0 -> 4.3.0.8
(cherry picked from commit 8565dcf7bc)
2020-05-15 16:51:50 +01:00
Patrick Hilhorst
79160c7ed3 megasync: 4.2.3.0 -> 4.2.5.0
Also pull in an (as of yet unmerged) upstream patch to fix
the build, it was failing on both .3 and .5

(cherry picked from commit 080a6b0dab)
2020-05-15 16:51:36 +01:00
Patrick Hilhorst
fd6368a88a megasync: format with nixfmt
(cherry picked from commit 5e55ebb2b4)
2020-05-15 16:51:36 +01:00
Michael Weiss
2215dff093 signal-desktop: 1.33.4 -> 1.34.0
(cherry picked from commit b0df5a6816)
2020-05-15 14:13:15 +02:00
adisbladis
ba86df0060 Merge pull request #87808 from mmilata/20.03/slirp4netns-0.4.5
[20.03] slirp4netns 0.4.3 -> 0.4.5
2020-05-15 12:05:15 +02:00
talyz
2fbd484867 nomachine-client: Add archive.org to source urls
NoMachine removes each old release as soon as a new one is available,
resulting in failed downloads. Thankfully, the Internet Archive
provides backups of old downloads, so we can use it as a fallback.

(cherry picked from commit 022f2cc02f)
2020-05-14 23:19:28 +02:00
Meghea Iulian
c497f5caf2 nomachine-client: 6.9.2 -> 6.10.12
(cherry picked from commit 46213cf4d6)
2020-05-14 23:18:49 +02:00
Benjamin Hipple
a7c70f2e10 Merge pull request #87836 from danieldk/mkl-pkgconfig-20.03
[20.03] mkl: fix expectation of MKLROOT being set in pkg-config files
2020-05-14 15:52:50 -04:00
Sarah Brofeldt
5256f59147 Merge pull request #87749 from johanot/kubernetes-1.17.5
kubernetes: 1.17.3 -> 1.17.5
2020-05-14 20:46:00 +02:00
Daniël de Kok
2dd4f2a004 mkl: fix expectation of MKLROOT being set in pkg-config files
The Intel MKL pkg-config files did not work, because they expect that
the MKLROOT environment variable is set. This change replaces
occurences by the actual path of MKL in the Nix store.

Since the pkg-config files seem to break quite frequently after
upgrades, add a post-install check to validate the pkg-config files.

(cherry picked from commit e88673aa27)
2020-05-14 20:44:15 +02:00
Andreas Rammhold
0ec56df9d1 firefox: 76.0 -> 76.0.1
(cherry picked from commit b70435e43c)
2020-05-14 20:27:23 +02:00
rnhmjoj
e3e62d66ca vapoursynth: R48 -> R49
(cherry picked from commit c339130b80)
This update should fix several bugs introduced in R48.
2020-05-14 16:55:34 +02:00
R. RyanTM
8830bd8ffe zimg: 2.9.2 -> 2.9.3
(cherry picked from commit 2c9cc36b39)
2020-05-14 16:55:34 +02:00
Vladimír Čunát
d2b0a72360 Merge #87773: firefox: patch AES GCM IV bit size
...into release-20.03
2020-05-14 16:44:47 +02:00
Tim Steinbach
1dff0476d9 linux: 5.6.12 -> 5.6.13
(cherry picked from commit 7ef8639163)
2020-05-14 09:31:41 -04:00
Tim Steinbach
cb59d52151 linux: 5.4.40 -> 5.4.41
(cherry picked from commit e3ba43b826)
2020-05-14 09:31:41 -04:00
Tim Steinbach
1f994089ea linux: 4.19.122 -> 4.19.123
(cherry picked from commit e9dbf2e508)
2020-05-14 09:31:41 -04:00
Mario Rodas
38ac9ed13a Merge pull request #87746 from zaninime/sane-update-20.03
backport: sane-airscan: 0.9.17 -> 0.99.0
2020-05-14 08:04:37 -05:00
Martin Milata
def173f8ff slirp4netns: 0.4.4 -> 0.4.5
https://github.com/rootless-containers/slirp4netns/releases/tag/v0.4.5

Fixes: https://nvd.nist.gov/vuln/detail/CVE-2020-1983
2020-05-14 12:31:55 +02:00
zowoq
6de57b4148 slirp4netns: 0.4.3 -> 0.4.4
https://github.com/rootless-containers/slirp4netns/releases/tag/v0.4.4

(cherry picked from commit b4cf1c96fa)
2020-05-14 12:28:49 +02:00
Martin Milata
8830690924 samba: 4.11.5 -> 4.11.9
Release notes:

* https://www.samba.org/samba/history/samba-4.11.6.html
* https://www.samba.org/samba/history/samba-4.11.7.html
* https://www.samba.org/samba/history/samba-4.11.8.html
* https://www.samba.org/samba/history/samba-4.11.9.html

The 4.11.8 release fixes:

* https://nvd.nist.gov/vuln/detail/CVE-2020-10700
* https://nvd.nist.gov/vuln/detail/CVE-2020-10704
2020-05-14 12:14:28 +02:00
Mario Rodas
7829e5791b Merge pull request #87655 from zowoq/gh-backport
[20.03] gitAndTools.gh: 0.6.4 -> 0.8.0
2020-05-13 19:49:38 -05:00
Michael Raskin
bd561f60a9 Merge pull request #87743 from badmutex/release-20.03-visidata-darwin
backport: visidata is supported on darwin + add setuptools
2020-05-13 23:30:15 +00:00
aszlig
89e930818a firefox: Add patch to fix AES GCM IV bit size
Regression introduced by bce5268a21.

The bit size of the initialisation vector for AES GCM has been
introduced in NSS version 3.52 in the CK_GCM_PARMS struct via the
ulIvBits field.

Unfortunately, Firefox 68.8.0 and 76.0 do not set this field and thus it
gets initialised to zero, which in turn causes IV generation to fail.

I found out about this because WebRTC stopped working after updating to
NSS 3.52 and so I started bisecting.

Since there wasn't an obvious error in Firefox hinting towards NSS but
instead just the video stream ended up as a "null" stream, I didn't
suspect the NSS update to be the culprit at first. So I verified a few
times and then also started bisecting the actual commit in NSS that
caused the issue.

This turned out to be the problematic change:

https://phabricator.services.mozilla.com/D63241

> One notable change was caused by an inconsistancy between the spec and
> the released headers in PKCS#11 v2.40. CK_GCM_PARAMS had an extra
> field in the header that was not in the spec. OASIS considers the
> header file to be normative, so PKCS#11 v3.0 resolved the issue in
> favor of the header file definition.

Since the test I've used[1] was a bit flaky, I still didn't believe the
result of the bisect to be accurate, but after running the test several
times leading same results I dug through the above change line by line
to get more clues.

It fortunately didn't take that long to stumble upon the ulIvBits change
(which is actually documented in the NSS 3.52 release notes[4], but I
managed to blatantly ignore it for some reason) and started checking the
Firefox source tree for changes regarding that field.

Initialisation of that new field has been introduced[2] in preparation
for the 76 release, but subsequently got reverted[3] prior to the
release, because Firefox 76 is expected to be shipped with NSS 3.51,
which didn't have the ulIvBits field.

The patch I'm adding here is just a reintroduction of that change,
because we're using NSS 3.52. Not initialising that field will break
WebRTC and WebCrypto, which I think the former seems to gain in
popularity these days ;-)

Tested the change against the mentioned VM test[1] and also by testing
manually using Jitsi Meet and Nextcloud Talk.

[1]: https://github.com/aszlig/avonc/tree/884315838b6f0ebb32b/tests/talk
[2]: https://hg.mozilla.org/mozilla-central/rev/3ed30e6b6de1
[3]: https://hg.mozilla.org/mozilla-central/rev/665137da70ee
[4]: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.52_release_notes

Signed-off-by: aszlig <aszlig@nix.build>
(cherry picked from commit 8fb49973ce & moved to packages.nix)
2020-05-14 00:33:15 +02:00
Robert Schütz
c3e2cbf23e qutebrowser: 1.11.0 -> 1.11.1
fixes CVE-2020-11054

(cherry picked from commit 52fcfd3876)
2020-05-13 21:35:45 +02:00
paumr
2c073a6038 qutebrowser: 1.10.1 -> 1.11.0
(cherry picked from commit 4a5b85364e)
2020-05-13 21:35:45 +02:00
Emmanuel Rosa
aa00678362 qutebrowser: 1.10.0 -> 1.10.1
(cherry picked from commit 1619ec9768)
2020-05-13 21:35:45 +02:00
adisbladis
a4f8cec54d kdeApplications.kdegraphics-thumbnailers: Fix 404ing patch url
(cherry picked from commit 5e206092be)
2020-05-13 20:59:31 +02:00
Francesco Zanini
9c2fa3cf6f sane-airscan: 0.9.17 -> 0.99.0 2020-05-13 17:57:14 +02:00
Badi' Abdul-Wahid
05d17d06c9 visidata: add darwin to supported platforms
(cherry picked from commit b3329478be)
2020-05-13 09:43:10 -05:00
Matthieu Coudron
3310a6b668 visidata: add setuptools
and ran nixpkgs-fmt.

This allows to access visidata's help via ctrl+H.

(cherry picked from commit d21cf30353)
2020-05-13 09:43:02 -05:00
Maximilian Bosch
fb5517f5c9 clipman: 1.5.1 -> 1.5.2
https://github.com/yory8/clipman/releases/tag/v1.5.2
(cherry picked from commit ebeea7497e)
2020-05-13 00:53:45 +02:00
Bjørn Forsman
d2a2ec2ebe lib.version: change pre-git to post-git on the release branch
When there is no .version-suffix file in nixpkgs (like when fetching
nixpkgs with builtins.fetchGit), lib.version suffixes the version string
with "pre-git". The "pre" bit is special cased in
builtins.compareVersions which means "20.03pre-git" is interpreted as
"less than 20.03". This is clearly wrong for the release-20.03 branch
*after* the release has been made.

Change the suffix to "post-git" to make code like this behave the same
whether nixpkgs is fetched from git or the channel (which has
.version-suffix file):

  lib.versionOlder lib.version "20.03"
  lib.versionAtLeast lib.version "20.03"

(Currently the result depend on how nixpkgs was obtained!)

This change should be made part of the release process.
2020-05-12 21:46:52 +02:00
zowoq
b24db14ff6 gitAndTools.gh: 0.7.0 -> 0.8.0
https://github.com/cli/cli/releases/tag/v0.8.0
(cherry picked from commit 6618edf594)
2020-05-12 19:18:48 +10:00
Thomas Tuegel
da7ddd822e Merge pull request #87604 from wamserma/libfm-fix-collision-backport
libfm: fix duplicate inclusion of libfm-extra
2020-05-11 15:25:21 -05:00
R. RyanTM
f75784a33b gnomeExtensions.clipboard-indicator: 30 -> 34
(cherry picked from commit 024a6dc45b)
2020-05-11 21:15:51 +02:00
dasj19
e2af3a6185 clipboard-indicator: removed broken flag. (#83088)
(cherry picked from commit 4755186bb4)
2020-05-11 21:15:51 +02:00
zowoq
c9ae4b6d62 gitAndTools.gh: 0.6.4 -> 0.7.0
https://github.com/cli/cli/releases/tag/v0.7.0
(cherry picked from commit f7b9c6c28b)
2020-05-12 04:38:22 +10:00
Frederik Rietdijk
3ffd8dc105 Merge staging-20.03 into release-20.03 2020-05-11 17:29:06 +02:00
Markus S. Wamser
02d2ab3cc1 libfm: fix duplicate inclusion of libfm-extra
(cherry picked from commit f5c0535213)
2020-05-11 17:07:39 +02:00
Ambroz Bizjak
e8cf1234d7 kdegraphics-thumbnailers: Add patch for thumbnail.so hang.
https://bugs.kde.org/show_bug.cgi?id=404652
https://phabricator.kde.org/D26635
(cherry picked from commit 57e6799d90)
2020-05-11 09:47:50 -05:00
Tim Steinbach
80e501491a linux: 5.6.11 -> 5.6.12 2020-05-11 08:51:51 -04:00
Tim Steinbach
f3a0d339d3 linux: 5.4.39 -> 5.4.40 2020-05-11 08:51:51 -04:00
Tim Steinbach
5cff0729a9 linux: 4.9.222 -> 4.9.223 2020-05-11 08:51:51 -04:00
Tim Steinbach
a92f6eef0f linux: 4.4.222 -> 4.4.223 2020-05-11 08:51:51 -04:00
Tim Steinbach
31cad52086 linux: 4.19.121 -> 4.19.122 2020-05-11 08:51:51 -04:00
Tim Steinbach
226c22f31e linux: 4.14.179 -> 4.14.180 2020-05-11 08:51:51 -04:00
Maximilian Bosch
c7b2d4998a wireguard-tools: 1.0.20200319 -> 1.0.20200510
https://lists.zx2c4.com/pipermail/wireguard/2020-May/005415.html
(cherry picked from commit b95d49d034)
2020-05-11 13:21:23 +02:00
Vojtěch Káně
52c95faadf monero: fix rcp.restricted option
According to https://monerodocs.org/interacting/monerod-reference/#node-rpc-api
the correct option is restricted-rpc, not restrict-rpc.

(cherry picked from commit e7ab236cab)
2020-05-11 12:49:17 +02:00
Jörg Thalheim
5adf2a6c11 Merge pull request #87543 from maralorn/fix-vim-plugin-order 2020-05-11 09:54:07 +01:00
Jörg Thalheim
589933201b Merge pull request #87584 from Mic92/nix-direnv 2020-05-11 08:53:16 +01:00
vasile luta
db204e759b vimUtils.vimrcFile: fixes packpath order
(cherry picked from commit 5d2ea07f02)
2020-05-11 09:45:26 +02:00
Jörg Thalheim
83e1be844c nix-direnv: add myself as maintainer 2020-05-11 08:41:03 +01:00
Jörg Thalheim
067e7ee24c nix-direnv: add preInstall/postInstall hooks 2020-05-11 08:41:01 +01:00
Damien Cassou
cbc4c7486a nix-direnv: init at 1.0.0 2020-05-11 08:40:59 +01:00
Peter Hoeg
9399cc72e6 Merge pull request #87392 from lheckemann/freerdp-backport
Freerdp backport
2020-05-11 14:08:37 +08:00
Maximilian Bosch
14dd961b8d gitea: 1.11.4 -> 1.11.5
https://github.com/go-gitea/gitea/releases/tag/v1.11.5

Also applying the patch which fixes the wiki-pages, closes #87115.

(cherry picked from commit 54677515aa)
2020-05-10 03:07:39 +02:00
Maximilian Bosch
645fd4a2c0 linuxPackages.wireguard: 1.0.20200429 -> 1.0.20200506
https://lists.zx2c4.com/pipermail/wireguard/2020-May/005408.html
(cherry picked from commit f887d09c89)
2020-05-10 01:53:30 +02:00
Maximilian Bosch
e9ea446d0f wdisplays: 2020-03-15 -> 1.0
https://github.com/cyclopsian/wdisplays/releases/tag/1.0
(cherry picked from commit fd0a039410)
2020-05-10 01:53:23 +02:00
Anderson Torres
4a0446664e Merge pull request #86170 from OPNA2608/backport-update-palemoon
[20.03] palemoon: 28.8.4 -> 28.9.1, add GTK3 option
2020-05-09 14:06:23 -03:00
Linus Heckemann
7d9eac67b7 freerdp: 2.0.0 -> 2.1.0
(cherry picked from commit f29648eca5db4f34b0d9cc159184c8de2a67ca51)

Original PR: #87285
2020-05-09 16:23:43 +02:00
Peter Hoeg
eb7f580a22 freerdp: re-enable tests except for one failing test
(cherry picked from commit 8f89b0cd0e)
2020-05-09 16:23:22 +02:00
Linus Heckemann
ff98026cb5 freerdp: 2.0.0-rc4 -> 2.0.0 (#84885)
* freerdp: 2.0.0-rc4 -> 2.0.0

* freerdp: add Xtst for input in shadow server, libxslt for manpages

* freerdp: nits

(cherry picked from commit 156ee198b2)
2020-05-09 16:22:44 +02:00
Joachim F
3461eacc9e Merge pull request #87389 from sorki/tor_cc_backport
[20.03] tor: fix cross compiling
2020-05-09 14:13:31 +00:00
Richard Marko
5c844fcb66 tor: fix cross compiling
(cherry picked from commit 8aab081504)
2020-05-09 15:41:22 +02:00
Frederik Rietdijk
6ac7ed80cd python2: 2.7.17 -> 2.7.18 (security, backport)
Closes https://github.com/NixOS/nixpkgs/issues/79729

Scurity fixes and official EOL note.

(cherry picked from commit cf1a68360e)
2020-05-09 15:12:56 +02:00
Frederik Rietdijk
438ee1a4fc Merge release-20.03 into staging-20.03 2020-05-09 15:12:21 +02:00
R. RyanTM
59cd521bad ceph: 14.2.8 -> 14.2.9
(cherry picked from commit 8a4fcfd487)
Backport of #86798
2020-05-09 15:11:22 +02:00
Michael Raskin
742ff3f699 Merge pull request #87367 from 7c6f434c/fix-tbe-20.03
tbe: fix build [20.03]
2020-05-09 11:38:57 +00:00
Michael Raskin
c04f447bea tbe: fix build
(cherry picked from commit 33932b6f83)
2020-05-09 12:37:08 +02:00
Vladimír Čunát
e56fe0ec15 Merge #87066: thunderbird*: 68.7.0 -> 68.8.0 (security)
https://www.thunderbird.net/en-US/thunderbird/68.8.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2020-18/
(cherry picked from commit 10134fc301)
Re-tested both briefly on 20.03.
2020-05-09 10:44:16 +02:00
Vladimír Čunát
d279111c4f knot-dns: 2.9.3 -> 2.9.4
https://gitlab.labs.nic.cz/knot/knot-dns/-/tags/v2.9.4
(cherry picked from commit 2147dd0648)
2020-05-09 10:44:15 +02:00
Frederik Rietdijk
3d4548bc80 Merge release-20.03 into staging-20.03 2020-05-09 09:46:01 +02:00
Martin Milata
f860b7b608 libssh: 0.8.8 -> 0.8.9
Fixes CVE-2020-1730.
Release notes: https://www.libssh.org/2020/04/09/libssh-0-9-4-and-libssh-0-8-9-security-release/

(cherry picked from commit 812ede7d26765f6663e9aa34311068a0392d95b7)
2020-05-09 09:44:11 +02:00
Martin Milata
f354d93d69 cups: 2.3.1 -> 2.3.3
https://github.com/apple/cups/releases/tag/v2.3.3

Fixes:

https://nvd.nist.gov/vuln/detail/CVE-2019-8842
https://nvd.nist.gov/vuln/detail/CVE-2020-3898
(cherry picked from commit fe90f585cacd4bda07e5c32706134a19b2c24027)
2020-05-09 09:43:03 +02:00
Martin Weinelt
afb0b51518 graphicsmagick: apply patch for CVE-2020-10938
Adapted from http://hg.graphicsmagick.org/hg/GraphicsMagick/raw-rev/95abc2b694ce
2020-05-09 09:36:16 +02:00
toonn
655649ecff wire-desktop: mac 3.16.3630 -> 3.17.3666
(cherry picked from commit b408b8c8e4)
2020-05-09 09:07:12 +02:00
toonn
b04336d3d5 wire-desktop: linux 3.16.2923 -> 3.17.2924
(cherry picked from commit 84b510775c)
2020-05-09 09:07:12 +02:00
Andreas Rammhold
d6c1b566b7 Merge pull request #87304 from mweinelt/20.03/pr/microcode/intel
[20.03] microcodeIntel: 20191115 → 20200508
2020-05-09 01:03:45 +02:00
Martin Weinelt
6b17e3557b microcodeIntel: 20191115 → 20200508
(cherry picked from commit d2ad98b1c9)
2020-05-09 00:11:10 +02:00
Michael Raskin
0fdd3e8906 Merge pull request #87297 from mweinelt/20.03/pr/squid
[20.03] squid: apply patch for CVE-2020-11945
2020-05-08 21:58:39 +00:00
Martin Weinelt
1cc15843b2 squid: apply patch for CVE-2020-11945
http://www.squid-cache.org/Advisories/SQUID-2020_4.txt

Fixes: CVE-2020-11945
2020-05-08 23:41:12 +02:00
Marek Mahut
6958957214 Merge pull request #87284 from 1000101/blockbook-20.03
blockbook: fix go version
2020-05-08 19:58:25 +02:00
1000101
a3a12c044d blockbook: 0.3.1 -> 0.3.2 2020-05-08 19:26:30 +02:00
1000101
85bb2d20df blockbook: fix go version 2020-05-08 19:20:24 +02:00
Gabriel Ebner
9daa5fba8d elan: 0.9.0 -> 0.10.0
(cherry picked from commit 115fa1c129)
2020-05-08 17:36:28 +02:00
Luflosi
7aa47b492b youtube-dl: 2020.05.03 -> 2020.05.08
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.05.08
(cherry picked from commit 906497a23f)
2020-05-08 15:15:53 +02:00
Peter Simons
6b2dc0e32e cabal2nix: update from version 2.15.0 to 2.15.3
The new version supports older versions of Cabal again and therefore doesn't
need any overrides or a newer compiler to build. The default ghc-8.6.x in the
release-20.03 release branch can compile it just fine.

Fixes https://github.com/NixOS/nixpkgs/issues/87184.
2020-05-08 14:12:55 +02:00
Jörg Thalheim
02faf44f52 Merge pull request #87252 from Mic92/fix-zed 2020-05-08 12:02:07 +01:00
Jörg Thalheim
7d3621ca98 nixos/zfs: populate PATH with needed programs for zed
(cherry picked from commit 92bede3102)
2020-05-08 11:02:01 +01:00
Maximilian Bosch
5c416f75dd clipman: 1.5.0 -> 1.5.1
https://github.com/yory8/clipman/releases/tag/v1.5.1
(cherry picked from commit b2d7c0dbf7)
2020-05-08 10:56:18 +02:00
Martin Baillie
fc9ca52944 ssm-session-manager-plugin: init at 1.1.61.0
Signed-off-by: Martin Baillie <martin@baillie.email>
(cherry picked from commit 9566c742e2)
2020-05-08 18:17:53 +10:00
Frederik Rietdijk
4e78311709 Merge release-20.03 into staging-20.03 2020-05-08 07:07:43 +02:00
Ryan Mulligan
210d8624ac Merge pull request #87228 from aanderse/moodle
moodle: 3.8.1 -> 3.8.2 [20.03]
2020-05-07 18:41:20 -07:00
R. RyanTM
6c5decf83e moodle: 3.8.1 -> 3.8.2
(cherry picked from commit e3e53adc35)
2020-05-07 20:30:12 -04:00
Maximilian Bosch
f6b2ba4936 cargo-make: 0.30.6 -> 0.30.7
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.7
(cherry picked from commit ee032804f8)
2020-05-08 00:05:43 +02:00
Bjørn Forsman
3cb7a1cffe conan: unmark as broken 2020-05-07 11:16:29 -07:00
Drew Risinger
c4086f6d78 conan: 1.24.0 -> 1.25.0
(cherry picked from commit 4454ca488c)
2020-05-07 11:16:29 -07:00
Drew Risinger
1943801922 conan: unbreak with deprecation>=2.1
(cherry picked from commit cae48ccad3)
2020-05-07 11:16:29 -07:00
Jonathan Ringer
14a46abd85 conan: 1.23.0 -> 1.24.0
(cherry picked from commit 3583757685)
2020-05-07 11:16:29 -07:00
R. RyanTM
1105bd85c8 python27Packages.patch-ng: 1.17.2 -> 1.17.4
(cherry picked from commit b914c284d9)
2020-05-07 11:16:29 -07:00
Niklas Hambüchen
0d51e3eeba conan: 1.12.3 -> 1.23.0
* remove pinned dependencies where nixpkgs provides a version
  in the acceptable range
* disable tests;
  they are no longer in the Pypi archive, see
  https://github.com/conan-io/conan/issues/4563

(cherry picked from commit f460e62d9b)
2020-05-07 11:16:29 -07:00
Niklas Hambüchen
b2a6334ab7 pythonPackages.patch-ng: Init at 1.17.2.
Newer versions of `conan` need it.

Adding @HaoZeke as maintainer (is Conan maintainer).

(cherry picked from commit 3e60781f53)
2020-05-07 11:16:29 -07:00
Niklas Hambüchen
17a6a31a7f conan: Remove unnecessary patching.
The pluginbase dependency is now pinned further up with commit

    244fcfc8 - conan: pin pluginbase to 0.7

(cherry picked from commit 03d5611ae0)
2020-05-07 11:16:29 -07:00
Niklas Hambüchen
9c9e7332f8 conan: Reformat inputs list
(cherry picked from commit 3a158da8e8)
2020-05-07 11:16:29 -07:00
Gabriel Ebner
74721f8440 elan: 0.8.0 -> 0.9.0
(cherry picked from commit f6f5f6a30f)
2020-05-07 16:07:50 +02:00
Florian Klink
240f670043 Merge pull request #83331 from helsinki-systems/backport/20.03/memcached
[20.03] memcached: 1.5.22 -> 1.6.2
2020-05-07 11:09:38 +02:00
Johan Thomsen
6b10ceb4bc kubernetes: 1.17.3 -> 1.17.5 2020-05-07 09:05:42 +02:00
Ryan Mulligan
52e9f62f52 Merge pull request #87122 from mweinelt/20.03/pr/apt-cacher-ng
[20.03] apt-cacher-ng: 3.2 → 3.5
2020-05-06 21:20:54 -07:00
Niklas Hambüchen
13a1097f5c Merge pull request #86944 from nh2/libeatmydata-launcher-backport-issue-80784-20.03
[20.03] libeatmydata: fix launcher script - find shell library properly
2020-05-07 04:36:20 +02:00
Maximilian Bosch
88e91e4882 riot-desktop: 1.5.15 -> 1.6.0
https://github.com/vector-im/riot-web/releases/tag/v1.6.0
(cherry picked from commit bc6bad222e)
2020-05-07 02:23:21 +02:00
Maximilian Bosch
31063de07c riot-web: 1.5.15 -> 1.6.0
https://github.com/vector-im/riot-web/releases/tag/v1.6.0
(cherry picked from commit b9787479e2)
2020-05-07 02:23:21 +02:00
Florian Klink
7544d59263 Merge pull request #87148 from hax404/20.03_teeworlds-0.7.5
[20.03] teeworlds: 0.7.4 -> 0.7.5
2020-05-07 00:34:51 +02:00
Georg Haas
e85b6a5e80 teeworlds: 0.7.4 -> 0.7.5
fixes CVE-2020-12066

(cherry picked from commit b89d52ee52)
2020-05-07 00:15:18 +02:00
Aaron Andersen
2d07cd64cb Merge pull request #87096 from mweinelt/20.03/pr/wordpress
[20.03] wordpress: 5.3.2 → 5.3.3
2020-05-06 17:43:32 -04:00
Tim Steinbach
404fef90de linux: 5.6.10 -> 5.6.11 2020-05-06 16:06:42 -04:00
Tim Steinbach
dc2c23c015 linux: 5.4.38 -> 5.4.39 2020-05-06 16:06:42 -04:00
Tim Steinbach
21d4bfb2f4 linux: 4.19.120 -> 4.19.121 2020-05-06 16:06:41 -04:00
Martin Weinelt
3729fae8af apt-cacher-ng: 3.2 → 3.5
Fixes: CVE-2017-7443, CVE-2020-5202
(cherry picked from commit 1c7ad58742)
2020-05-06 19:42:00 +02:00
Martin Weinelt
ef791a394b wordpress: 5.3.2 → 5.3.3
Fixes: CVE-2020-11030, CVE-2020-11029, CVE-2020-11028, CVE-2020-11027, CVE-2020-11026, CVE-2020-11025
2020-05-06 15:16:10 +02:00
Michael Weiss
b0e3df2f84 chromium: 81.0.4044.129 -> 81.0.4044.138
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop.html

This update includes 3 security fixes.

CVEs: CVE-2020-6831 CVE-2020-6464
(cherry picked from commit dec3d5f39f)
Backport of #87021.
2020-05-06 13:03:00 +02:00
Wout Mertens
788f02c4aa Merge pull request #86421 from risicle/ris-git-tcltk-darwin-r20.03
[r20.03] git: use tcl/tk from nixpkgs on darwin
2020-05-06 10:33:05 +02:00
Michele Guerini Rocco
8258818a52 Merge pull request #87006 from aanderse/duo-20.03-fix
duosec: fix module [20.03]
2020-05-06 01:21:41 +02:00
Jan Tojnar
986799d95f Remove myself from maintainers
I do not have time for dealing with issues like https://github.com/NixOS/nixpkgs/issues/87000
2020-05-06 00:00:52 +02:00
Aaron Andersen
55f53dd232 duosec: fix module 2020-05-05 17:16:36 -04:00
Benjamin Hipple
7ca490fb06 Merge pull request #86981 from mweinelt/20.03/pr/ansible/v2.8.11
[20.03] ansible: v2.8.7 → v2.8.11, v2.7.15 → v2.7.17
2020-05-05 16:36:35 -04:00
Frederik Rietdijk
fad00a9c21 Merge release-20.03 into staging-20.03 2020-05-05 22:34:36 +02:00
Benjamin Hipple
65a7e0968a Merge pull request #86987 from Mic92/nixpkgs-review
nixpkgs-review: 2.3.0 -> 2.3.1
2020-05-05 16:32:14 -04:00
Jörg Thalheim
c5520a915b nixpkgs-review: 2.3.0 -> 2.3.1
(cherry picked from commit 2805d68529)
2020-05-05 21:16:01 +01:00
Jakub Fišer
425aeec902 nixos/pantheon: mkDefault value for defaultSession
Fixes #86907

(cherry picked from commit c04989da24)
2020-05-05 15:47:42 -04:00
Martin Weinelt
0250781149 ansible: v2.7.15 → v2.7.17
Fixes: CVE-2020-10684, CVE-2020-1733, CVE-2020-1735, CVE-2020-1739, CVE-2020-1740
(cherry picked from commit e829499d69)
2020-05-05 21:31:32 +02:00
Martin Weinelt
eba95a43bd ansible: v2.8.7 → v2.8.11
Fixes: CVE-2020-10684, CVE-2020-1733, CVE-2020-1735, CVE-2020-1739, CVE-2020-1740
(cherry picked from commit 1c181e1bba)
2020-05-05 21:31:25 +02:00
Tim Steinbach
b273af1868 linux: 4.9.221 -> 4.9.222
(cherry picked from commit 32585ddcec)
2020-05-05 14:37:55 -04:00
Tim Steinbach
272abb0cec linux: 4.4.221 -> 4.4.222
(cherry picked from commit 7f75ff0777)
2020-05-05 14:37:55 -04:00
Tim Steinbach
2088108cd1 linux: 4.14.178 -> 4.14.179
(cherry picked from commit 018f49380e)
2020-05-05 14:37:55 -04:00
Andreas Rammhold
4d37318259 Merge pull request #86806 from andir/20.03/firefox76
[20.03] firefox 76
2020-05-05 19:39:22 +02:00
Echo Nolan
77207c1f5e libeatmydata: fix launcher script - find shell library properly
The new version of the launcher script in version 105 doesn't have the #8665
bug, but it does try to find the shell library using Debian tools, which
obviously doesn't work on Nix. Removed the now-unneccessary makeWrapper and
patched out the Debian bits.

(cherry picked from commit 4e9b94836f)
2020-05-05 15:34:05 +02:00
Maximilian Bosch
78332acf45 neomutt: 20200417 -> 20200501
https://github.com/neomutt/neomutt/releases/tag/20200424
https://github.com/neomutt/neomutt/releases/tag/20200501

Rationale for backport: both 20200424 and 20200501 are bugfix-releases
that solve a lot of problems such as enhanced support for unicode-chars
and improved parsers for emails. Originally, 20200424 wasn't backported
since it contained a regression within the side-bars[1], however this
was solved in 20200501[2].

[1] https://github.com/neomutt/neomutt/issues/2295
[2] f073a70cf3

(cherry picked from commit ea59fe7aa6)
(cherry picked from commit d203d553b9)
2020-05-05 12:38:01 +02:00
Maximilian Bosch
e35933d9d6 vagrant: 2.2.7 -> 2.2.8
https://github.com/hashicorp/vagrant/releases/tag/v2.2.8
(cherry picked from commit 48b6268225)
2020-05-05 12:38:00 +02:00
Vladimír Čunát
8cb990234f Merge branch 'staging-20.03' into release-20.03
All x86_64-linux jobs have finished already; let's not delay the CVEs.
2020-05-05 11:40:49 +02:00
AndersonTorres
e5cb3ef6a1 openshot-qt: 2.4.4 -> 2.5.1
(cherry picked from commit 5f382299f8)
2020-05-04 21:25:15 -07:00
AndersonTorres
1984b762ef libopenshot: 0.2.3 -> 0.2.5
(cherry picked from commit 71ab4348c0)
2020-05-04 21:25:15 -07:00
AndersonTorres
952e93061f libopenshot-audio: 0.1.8 -> 0.2.0
(cherry picked from commit ab7647b15b)
2020-05-04 21:25:15 -07:00
Benjamin Hipple
d47fb89920 Merge pull request #86098 from mjlbach/20.03-fix-nvidia-docker
[20.03] libnvidia-container: 1.0.0 -> 1.0.6
2020-05-05 00:16:32 -04:00
Benjamin Hipple
d161e202ab Merge pull request #86635 from ktor/ktor/cnijfilter2-version-update
cnijfilter2: 5.70 -> 5.90
2020-05-04 22:53:03 -04:00
Florian Klink
c1c055b8ad Merge pull request #86636 from prusnak/20.03-steam
[20.03] steam: fix more of generated runtime dependencies
2020-05-04 22:41:54 +02:00
Andreas Rammhold
4ed1431995 firefox-beta-bin: 76.0b4 -> 76.0b8
(cherry picked from commit c186bc893f)
2020-05-04 19:36:57 +02:00
Andreas Rammhold
8df8c9b412 firefox-esr-68: 68.7.0esr -> 68.8.0esr
(cherry picked from commit f3cc8dc6fa)
2020-05-04 19:36:57 +02:00
Andreas Rammhold
c0b2ba075e firefox-bin: 75.0 -> 76.0
(cherry picked from commit 3911336cc6)
2020-05-04 19:36:56 +02:00
Andreas Rammhold
a148927391 firefox: 75.0 -> 76.0
(cherry picked from commit 324e40f0f4)
2020-05-04 19:36:56 +02:00
Andreas Rammhold
45bd649b83 nss_3_52: 3.51 -> 3.52 2020-05-04 19:36:53 +02:00
Yorick van Pelt
417c964ef7 tensorflow-1: fix tensorflow-gpu-1.15.2-deps fixed-output hash 2020-05-04 19:15:10 +02:00
nyanloutre
281331a1f1 steam.chrootenv: Add Prison Architect dependencies
(cherry picked from commit 3a15a13354)
2020-05-04 16:27:57 +02:00
nyanloutre
6986bc391d steamrt: 1.20190624 -> 1.20200128
(cherry picked from commit 8bd3cf22c2)
2020-05-04 16:27:41 +02:00
Jonathan Ringer
4142a18b6f steam.chrootenv: add udev
Needed by Shadow of the Tomb Raider

(cherry picked from commit 9d4aab7880)
2020-05-04 16:25:00 +02:00
Jonathan Ringer
dd0d261745 steamPackages.chrootenv: add file command
Noticed that the setup.sh for steam was trying to call the file command.
I'm not sure what the ramifications are for these missing,
but some steam features are quietly disabled when they
don't follow happy paths.

(cherry picked from commit 9cd683ccc0)
2020-05-04 16:24:51 +02:00
Jonathan Ringer
666c378da6 steam-chrootenv: add lsof
This adds support for "Launch Game" through the friends menu

(cherry picked from commit 4ca08a2a73)
2020-05-04 16:24:43 +02:00
Franz Pletz
b5c1b6b0ec boringssl: 2017-02-23 -> 2019-12-04
(cherry picked from commit 89b673b9e6)
2020-05-04 15:04:23 +02:00
Franz Pletz
bca8a33a6b coturn: 4.5.1.1 -> 4.5.1.2
(cherry picked from commit 52b2fa943a)
2020-05-04 15:04:11 +02:00
Michael Weiss
9ecbcc501e wf-recorder: 0.2 -> 0.2.1
(cherry picked from commit ca2a222747)
2020-05-04 15:04:08 +02:00
Michael Weiss
4a5eef41e0 wf-recorder: 0.1 -> 0.2
(cherry picked from commit 31f2ff1d61)
2020-05-04 15:04:08 +02:00
Florian Klink
97762351b1 Merge pull request #86769 from m1cr0man/dnsdocs-20.03
[20.03] nixos/acme: update documentation
2020-05-04 14:58:42 +02:00
Lucas Savva
8a8a9c28c5 [20.03] nixos/acme: update documentation 2020-05-04 13:33:19 +01:00
Dennis Gosnell
410cf9ed65 Merge pull request #86659 from maralorn/fix-ghcide
[20.03] haskellPackages.ghcide: Fix build
2020-05-04 21:19:29 +09:00
Jörg Thalheim
6ea8340176 Merge pull request #86759 from johanot/backport-kubeval-fix
[20.03] kubeval: don't build against schema by default
2020-05-04 12:57:13 +01:00
Malte Brandy
4363f710e3 haskellPackages.ghcide: Fix ghcide and hie-bios 2020-05-04 13:52:37 +02:00
Johan Thomsen
8f84e120f0 kubeval: remove broken state 2020-05-04 13:19:28 +02:00
Jörg Thalheim
879ce11c21 kubeval: don't build against schema by default
kubeval-schema is a huge 7GB repository that we do not want
to build on hydra. Therefore make it optional.

(cherry picked from commit 9d144b84a3)
2020-05-04 13:06:31 +02:00
Benjamin Hipple
d97db80583 Merge pull request #86653 from Flakebi/salt-20.03
[20.03] salt: 2019.2.0 -> 2019.2.4
2020-05-03 19:48:21 -04:00
Oleksii Filonenko
1dbb648f31 bandwhich: 0.13.0 -> 0.14.0
(cherry picked from commit c788a8596a)
2020-05-03 22:41:34 +02:00
Josef Schlehofer
236016c356 wireguard-compat: 1.0.20200426 -> 1.0.20200429
(cherry picked from commit e008d5fc98)
2020-05-03 19:38:38 +02:00
Maximilian Bosch
9094a9167e clipman: 1.4.0 -> 1.5.0
https://github.com/yory8/clipman/releases/tag/v1.5.0
(cherry picked from commit 4e6204bed0)
2020-05-03 19:08:52 +02:00
Maximilian Bosch
77f14a218b packer: 1.5.5 -> 1.5.6
https://github.com/hashicorp/packer/releases/tag/v1.5.6
(cherry picked from commit 6fd3426230)
2020-05-03 19:08:51 +02:00
Pawel Kruszewski
40fa456abb cnijfilter2: 5.70 -> 5.90 2020-05-03 18:28:45 +02:00
Luflosi
213be768b9 youtube-dl: 2020.03.24 -> 2020.05.03
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.05.03
(cherry picked from commit a54f374413)
2020-05-03 16:41:53 +02:00
Flakebi
b5a4c50e31 salt: 2019.2.0 -> 2019.2.4
Fixes CVE-2020-11651 and CVE-2020-11652
2020-05-03 16:16:29 +02:00
Andrew Childs
f98c32e69e git: use tcl/tk from nixpkgs on darwin
(cherry picked from commit bc4264a95f)
2020-05-03 13:04:57 +01:00
Benjamin Hipple
c0137ebba7 Merge pull request #86604 from LibreCybernetics/backport-keybase-upgrades
[20.03] keybase,kbfs,keybase-gui: 5.0.0 -> 5.4.2
2020-05-02 21:31:51 -04:00
Florian Klink
bb33bca4ae Merge pull request #86619 from prusnak/20.03-steam
[20.03] steam: update generated runtime dependencies
2020-05-03 01:34:25 +02:00
Martin Weinelt
9acae7c4ed steam: update generated runtime dependencies
The referenced zenity URL wasn't valid anymore:

trying http://repo.steampowered.com/steamrt/pool/main/z/zenity/zenity_3.4.0-0ubuntu4+steamrt2+srt6_amd64.deb
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
curl: (22) The requested URL returned error: 404 Not Found

(cherry picked from commit 467a987f0b)
2020-05-03 01:09:27 +02:00
Tim Steinbach
1f4f3c428c linux: 5.6.8 -> 5.6.10 2020-05-02 14:47:06 -04:00
Tim Steinbach
176db52eda linux: 5.4.36 -> 5.4.38 2020-05-02 14:47:06 -04:00
Tim Steinbach
d93d452519 linux: 4.9.220 -> 4.9.221 2020-05-02 14:47:05 -04:00
Tim Steinbach
da264f171a linux: 4.4.220 -> 4.4.221 2020-05-02 14:47:04 -04:00
Tim Steinbach
08ab30620d linux: 4.19.119 -> 4.19.120 2020-05-02 14:47:04 -04:00
Tim Steinbach
e7eda9544b linux: 4.14.177 -> 4.14.178 2020-05-02 14:47:03 -04:00
Aldwin Vlasblom
eaae309039 Add myself (avaq) to the keybase package maintainers
(cherry picked from commit 0a7e9c3d5d9082a0f1d153f4f4b1d912429aef10)
2020-05-02 12:39:58 -05:00
Aldwin Vlasblom
d26aa07c89 keybase,kbfs,keybase-gui: 5.3.1 -> 5.4.2
(cherry picked from commit e1820dc344d36c27b3b8a81fbd3274d50041cb66)
2020-05-02 12:39:58 -05:00
Piotr Szegda
0dd6de01b2 keybase,kbfs,keybase-gui: 5.3.0 -> 5.3.1
(cherry picked from commit 3f8e7741cf723b36a278750614036bebbd74e9c6)
2020-05-02 12:39:58 -05:00
Piotr Szegda
9137038050 keybase,kbfs,keybase-gui: 5.2.1 -> 5.3.0
(cherry picked from commit d47ddc636b134e4070b0c7cbee6a879bb7992005)
2020-05-02 12:39:58 -05:00
Cassidy Dingenskirchen
0a7cc5d984 keybase,kbfs,keybase-gui: 5.1.1 -> 5.2.1
(cherry picked from commit 0dbccd06cab066f8e5094b3ed53910e234fff891)
2020-05-02 12:39:58 -05:00
Oleksii Filonenko
9fbd53d77a keybase,keybase-gui: 5.1.0 -> 5.1.1
(cherry picked from commit ee2faf31e55cab1192fc57876dff6dce6d561bc3)
2020-05-02 12:39:58 -05:00
Oleksii Filonenko
008f2184d0 keybase,keybase-gui: add filalex77 to maintainers
(cherry picked from commit 0c65f3f0d78b2d91df0e2a6819a7f9ce6780549e)
2020-05-02 12:39:58 -05:00
Oleksii Filonenko
f4d6be02af keybase,keybase-gui: 5.0.0 -> 5.1.0
(cherry picked from commit a665c1e0c87a1dd97c12940cad9d659b9e22bcd7)
2020-05-02 12:39:58 -05:00
Benjamin Herr
4a41762c51 silence warning from #63103 in encrypted-devices.nix
(cherry picked from commit 0f5acc5ebe)
2020-05-02 12:42:17 +02:00
adisbladis
354beb85c5 Merge pull request #86485 from cole-h/staging-20.03
[20.03] libvorbis: fix 404'ing patch
2020-05-02 11:30:17 +02:00
adisbladis
9c3d0d4d9a Merge pull request #86487 from adisbladis/nix-pythonprefix-2003
Python: introduce NIX_PYTHONPREFIX in order to set site.PREFIXES (20.03 backport)
2020-05-02 10:59:55 +02:00
Tim Steinbach
9c4b22793e zoom-us: 5.0.398100.0427 -> 5.0.399860.0429
(cherry picked from commit c56c72b4f8)
2020-05-01 18:11:12 -07:00
Bernardo Meurer
53d2870781 zoom-us: 3.5.385850.0413 -> 5.0.398100.0427
(cherry picked from commit de2b31490b)
2020-05-01 18:11:12 -07:00
Tim Steinbach
5a7ec9b939 zoom-us: 3.5.383291.0407 -> 3.5.385850.0413
(cherry picked from commit f6a53ee71f)
2020-05-01 18:11:12 -07:00
Tim Steinbach
fae7a251b2 zoom-us: 3.5.374815.0324 -> 3.5.383291.0407
(cherry picked from commit c4c017f982)
2020-05-01 18:11:12 -07:00
Tim Steinbach
f39c3bc8bc zoom-us: 3.5.372466.0322 -> 3.5.374815.0324
(cherry picked from commit f47e15a63c)
2020-05-01 18:11:12 -07:00
Tim Steinbach
0fd98a37a5 zoom-us: 3.5.361976.0301 -> 3.5.372466.0322
(cherry picked from commit 66172a2ea4)
2020-05-01 18:11:12 -07:00
Tim Steinbach
e7d570d719 zoom-us: 3.5.359539.0224 -> 3.5.361976.0301
(cherry picked from commit 1ccc73cd1f)
2020-05-01 18:11:12 -07:00
Bernardo Meurer
2f636791e5 zoom-us: add qtgraphicaleffects dependency
(cherry picked from commit 33c04eac64)
2020-05-01 18:11:12 -07:00
Tim Steinbach
8590e7ae20 zoom-us: 3.5.359165.0223 -> 3.5.359539.0224
(cherry picked from commit 8f3f727e06)
2020-05-01 18:11:12 -07:00
Tim Steinbach
2668d578b6 zoom-us: 3.5.352596.0119 -> 3.5.359165.0223
(cherry picked from commit da84ff331b)
2020-05-01 18:11:12 -07:00
Danylo Hlynskyi
e0063fe77b zoom-us: fix launch (#80005)
zoom-us: fix launch

Probably due to glibc update, ZoomLauncher became broken when v4l is present in
LD_PRELOAD path. It can be fixed by a) removing ZoomLauncher from startup chain,
so `zoom` is started directly or b) removing v4l from LD_PRELOAD.

The reason v4l was added before was because my video was rotated upside down without it.
Seem like nowadays this is fixed by Zoom itself, so I'm removing it.

Fixes https://github.com/NixOS/nixpkgs/issues/79954

Co-authored-by: @mmlb
(cherry picked from commit 854638ea29)
2020-05-01 18:11:12 -07:00
Jan Tojnar
07683662ae terminator: clean up
(cherry picked from commit 64c09a3d5c)
2020-05-01 22:33:23 +02:00
Stefan Frijters
97d3082c52 terminator: 1.91 -> 1.92
(cherry picked from commit 8855c3a1c7)
2020-05-01 22:33:23 +02:00
Peter Simons
0602ea9eca Merge pull request #85656 from samuelrivas/fix-stylish-haskell-for-20-03
haskellPackages.stylish-haskell: fix broken dependencies
2020-05-01 20:20:30 +02:00
Frederik Rietdijk
467008d10c Fix sys.prefix in case of a Nix env
The prefix will now be correct in case of Nix env.

Note, however, that creating a venv from a Nix env still does not function. This does not seem to be possible
with the current approach either, because venv will copy or symlink our Python wrapper. In case it symlinks
(the default) it won't see a pyvenv.cfg. If it is copied I think it should function but it does not...

(cherry picked from commit 7447fff95a)
2020-05-01 19:05:36 +01:00
adisbladis
ac50996ba0 Python: introduce NIX_PYTHONPREFIX in order to set site.PREFIXES
This is needed in case of `python.buildEnv` to make sure site.PREFIXES
does not only point to the unwrapped executable prefix.

--------------------------------------------------------------------------------

This PR is a story where your valiant hero sets out on a very simple adventure but ends up having to slay dragons, starts questioning his own sanity and finally manages to gain enough knowledge to slay the evil dragon and finally win the proverbial price.

It all started out on sunny spring day with trying to tackle the Nixops plugin infrastructure and make that nice enough to work with.

Our story begins in the shanty town of [NixOps-AWS](https://github.com/nixos/nixops-aws) where [mypy](http://mypy-lang.org/) type checking has not yet been seen.

As our deuteragonist (@grahamc) has made great strides in the capital city of [NixOps](https://github.com/nixos/nixops) our hero wanted to bring this out into the land and let the people rejoice in reliability and a wonderful development experience.

The plugin work itself was straight forward and our hero quickly slayed the first small dragon, at this point things felt good and our hero thought he was going to reach the town of NixOps-AWS very quickly.

But alas! Mypy did not want to go, it said:
`Cannot find implementation or library stub for module named 'nixops'`

Our hero felt a small sliver of life escape from his body. Things were not going to be so easy.

After some frustration our hero discovered there was a [rule of the land of Python](https://www.python.org/dev/peps/pep-0561/) that governed the import of types into the kingdom, more specificaly a very special document (file) called `py.typed`.
Things were looking good.

But no, what the law said did not seem to match reality. How could things be so?

After some frustrating debugging our valiant hero thought to himself "Hmm, I wonder if this is simply a Nix idiosyncrasy", and it turns out indeed it was.
Things that were working in the blessed way of the land of Python (inside a `virtualenv`) were not working the way they were from his home town of Nix (`nix-shell` + `python.withPackages`).

After even more frustrating attempts at reading the mypy documentation and trying to understand how things were supposed to work our hero started questioning his sanity.
This is where things started to get truly interesting.

Our hero started to use a number of powerful weapons, both forged in the land of Python (pdb) & by the mages of UNIX (printf-style-debugging & strace).

After first trying to slay the dragon simply by `strace` and a keen eye our hero did not spot any weak points.
Time to break out a more powerful sword (`pdb`) which also did not divulge any secrets about what was wrong.

Our hero went back to the `strace` output and after a fair bit of thought and analysis a pattern started to emerge. Mypy was looking in the wrong place (i.e. not in in the environment created by `python.withPackages` but in the interpreter store path) and our princess was in another castle!

Our hero went to the pub full of old grumpy men giving out the inner workings of the open source universe (Github) and acquired a copy of Mypy.
He littered the code with print statements & break points.
After a fierce battle full of blood, sweat & tears he ended up in 20f7f2dd71/mypy/sitepkgs.py and realised that everything came down to the Python `site` module and more specifically https://docs.python.org/3.7/library/site.html#site.getsitepackages which in turn relies on https://docs.python.org/3.7/library/site.html#site.PREFIXES .

Our hero created a copy of the environment created by `python.withPackages` and manually modified it to confirm his findings, and it turned out it was indeed the case.
Our hero had damaged the dragon and it was time for a celebration.

He went out and acquired some mead which he ingested while he typed up his story and waited for the dragon to finally die (the commit caused a mass-rebuild, I had to wait for my repro).

In the end all was good in [NixOps-AWS](https://github.com/nixos/nixops-aws)-town and type checks could run. (PR for that incoming tomorrow).

(cherry picked from commit d88a7735d2)
2020-05-01 19:05:19 +01:00
Frederik Rietdijk
cd39647098 Merge release-20.03 into staging-20.03 2020-05-01 19:29:25 +02:00
Cole Helbling
62216c7f8e libvorbis: fix 404'ing patch
Also use full commit for the other patch, just in case there's ever a
collision, as unlikely as that may be.

(cherry picked from commit f02e1c2878b90fa42c45465f80ad0647987ce5b0)
2020-05-01 08:45:03 -07:00
ajs124
f466a3484b memtest86-efi: replace p7zip with mtools
and dd

(cherry picked from commit ac8066c144)
2020-05-01 16:44:42 +02:00
Andreas Rammhold
cff5440d19 Merge pull request #86468 from tokudan/20.03/p7zip-cve
p7zip: fix two CVEs
2020-05-01 15:48:36 +02:00
Daniel Frank
de316f97d7 p7zip: fix two CVEs
(cherry picked from commit dd16c3944c)
2020-05-01 14:52:12 +02:00
Florian Klink
53a1ae1f98 Merge pull request #86440 from elohmeier/20.03-kmod-backports
[20.03] backport v4l2loopback and broadcom-sta fixes
2020-05-01 14:41:51 +02:00
Florian Klink
f84e95677d Merge pull request #86460 from talyz/20.03-gitlab-12.8.10
[20.03] gitlab: 12.8.9 -> 12.8.10
2020-05-01 14:01:29 +02:00
Jörg Thalheim
30cd0839bf Merge pull request #86452 from danieldk/softmaker-office-backport-976 2020-05-01 12:41:19 +01:00
Florian Klink
439e3b379f gitlab: update.py: use the /refs endpoint
It seems the atom feed now needs authentication. Use the /refs endpoint,
which is used for the switch branch/tag dropdown. It doesn't show all
records, but has some pagination, but works well enough for now.

(cherry picked from commit fc64bca95b)
2020-05-01 13:20:43 +02:00
Florian Klink
c9b984ec7a gitlab: 12.8.9 -> 12.8.10
(cherry picked from commit fdd0d0de1f)
2020-05-01 13:20:37 +02:00
Florian Klink
2eceb02d9e gitaly: 12.8.9 -> 12.8.10
(cherry picked from commit 9eb6dc762f)
2020-05-01 13:19:55 +02:00
Ryan Mulligan
f3fcc1a93d Merge pull request #81646 from r-ryantm/auto-update/tribler
tribler: 7.4.1 -> 7.4.4
(cherry picked from commit e291c9040b)
2020-05-01 12:32:35 +02:00
Daniël de Kok
128ee4fc4a softmaker-office: 972 -> 976
This is a bugfix release:

https://www.softmaker.com/en/servicepacks-office-changelog
(cherry picked from commit cb5580e4c0)
2020-05-01 11:35:51 +02:00
Martin Milata
9c14030f8a re2c: add patch for CVE-2020-11958
https://nvd.nist.gov/vuln/detail/CVE-2020-11958
(cherry picked from commit 7263c895ed)
2020-05-01 10:53:23 +02:00
Martin Milata
8134bd1aac re2c: 1.2.1 -> 1.3
(cherry picked from commit 2e9c802cee)
2020-05-01 10:53:17 +02:00
Andreas Stührk
cf9f88bd9a v4l2loopback: 0.12.3 -> 0.12.4
(cherry picked from commit 9ddfde8977)
Reason: fixes issue for linuxPackages_latest users in 20.03, see #84929
2020-05-01 08:44:09 +02:00
Matthieu Coudron
129e603619 broadcom_sta: fix build on 5.6
(cherry picked from commit 8ce65087c3)
Reason: fixes issue for linuxPackages_latest users in 20.03, see #84736
2020-05-01 08:44:09 +02:00
Andreas Rammhold
aef39c7bcc Merge pull request #86279 from mweinelt/20.03/dnsmasq/2.81
[20.03] dnsmasq: 2.80 → 2.81
2020-05-01 03:58:35 +02:00
Maximilian Bosch
73e73c7d6b Merge pull request #86412 from mmilata/20.03-wireshark-3.2.3
[20.03] wireshark: 3.2.2 -> 3.2.3
2020-04-30 23:16:08 +02:00
zowoq
86dd44e35e wireshark: 3.2.2 -> 3.2.3
https://www.wireshark.org/docs/relnotes/wireshark-3.2.3.html

(cherry picked from commit 7145a692b1)
2020-04-30 19:32:08 +02:00
Kim Lindberger
7b838df7f8 Merge pull request #86354 from talyz/20.03-skypeforlinux
[20.03] skypeforlinux: 8.58.0.93 -> 8.59.0.77
2020-04-30 09:28:13 +02:00
Maximilian Bosch
47fbd1e413 roundcube: 1.4.3 -> 1.4.4
https://github.com/roundcube/roundcubemail/releases/tag/1.4.4
(cherry picked from commit 42539c4c89)
2020-04-29 23:48:51 +02:00
Pascal Bach
32e43fc1ce skypeforlinux: add additional mirror
The university of chigaco keeps the binaries of old releases.

This reduces the change of #81868 and #85724 happening again in the
future.

(cherry picked from commit e4aab9cded)
2020-04-29 22:25:13 +02:00
Pascal Bach
9a505ee830 skypeforlinux: 8.58.0.93 -> 8.59.0.77
(cherry picked from commit 7b38685bb6)
2020-04-29 22:25:06 +02:00
Tim Steinbach
2a126b332e linux: 5.6.7 -> 5.6.8 2020-04-29 15:41:46 -04:00
Tim Steinbach
8368472a17 linux: 5.4.35 -> 5.4.36 2020-04-29 15:41:45 -04:00
Tim Steinbach
6d20136324 linux: 4.19.118 -> 4.19.119 2020-04-29 15:41:45 -04:00
Robert Helgesson
911c0a54b3 Merge pull request #86344 from cprussin/release-20.03
[20.03] emacs: improve setup hook
2020-04-29 21:07:44 +02:00
Michael Raskin
eaa3839194 Merge pull request #86339 from 7c6f434c/monotone-no-botan-openssl-20.03
monotone: openssl in botan is not needed, so drop to avoid old openssl
2020-04-29 18:08:47 +00:00
Robert Helgesson
49f7706509 emacs: fix setup-hook
This change fixes byte compilation of, e.g., Helm without breaking
builds using, e.g., `trivialBuild`.

See https://github.com/NixOS/nixpkgs/pull/82604#issuecomment-607201755

(cherry picked from commit bf486f784d)
2020-04-29 10:34:31 -07:00
Robert Helgesson
a90008938a emacs: improve setup hook
- Add packages installed in a sub-directory of site-lisp, such as
  mu4e, to EMACSLOADPATH.

- Add ELPA packages to EMACSLOADPATH.

- Add each package only once to EMACSLOADPATH. Before, each package
  would typically be added twice for each transitive dependency
  leading to a huge variable for a package having many dependencies.

Fixed #78680

(cherry picked from commit 2d2de743d0)
2020-04-29 10:34:17 -07:00
Michael Raskin
a4d6599765 monotone: openssl in botan is not needed, so drop to avoid old openssl
(cherry picked from commit 4644776b2e)
2020-04-29 19:33:27 +02:00
Alvar
f00d6dfbc6 Revert "st: copy config file in 'prePatch' instead of 'preBuild'"
Also change the custom config generation to the postPatch phase.

(cherry picked from commit 50b213a45e)
2020-04-29 15:01:44 +01:00
Alexey Shmalko
2a7c7cb06c Merge pull request #86270 from mweinelt/20.03/coturn/CVE-2020-6061+6062
[20.03] coturn: apply patch for CVE-2020-6061/6062
2020-04-29 16:50:41 +03:00
Martin Weinelt
142060cd87 coturn: apply patch for CVE-2020-6061/6062
Fixes: CVE-2020-6061, CVE-2020-6062

An exploitable heap overflow vulnerability exists in the way CoTURN
4.5.1.1 web server parses POST requests. A specially crafted HTTP
POST request can lead to information leaks and other misbehavior.
An attacker needs to send an HTTPS request to trigger this vulnerability.

An exploitable denial-of-service vulnerability exists in the way
CoTURN 4.5.1.1 web server parses POST requests. A specially crafted
HTTP POST request can lead to server crash and denial of service.
An attacker needs to send an HTTP request to trigger this vulnerability.

(cherry picked from commit 704a018aae)
2020-04-29 12:54:07 +02:00
Michael Weiss
fe4a40a782 chromium: 81.0.4044.122 -> 81.0.4044.129
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_27.html

This update includes 2 security fixes.

CVEs: CVE-2020-6462 CVE-2020-6461
(cherry picked from commit db4aece884)
Backport of #86206.
2020-04-29 11:17:14 +02:00
Vincent Laporte
d6f7778d57 coqPackages.gappalib: 1.4.1 → 1.4.3
(cherry picked from commit 95b35a2514)
2020-04-29 07:24:08 +02:00
worldofpeace
dacf6ca896 nixos/pantheon: fix doc typo
(cherry picked from commit a6dc21fa2d)
2020-04-29 01:22:17 -04:00
Martin Weinelt
c9d3271c17 dnsmasq: 2.80 → 2.81
Fixes: CVE-2019-14834

A vulnerability was found in dnsmasq before version 2.81, where the
memory leak allows remote attackers to cause a denial of service
(memory consumption) via vectors involving DHCP response creation.

Changelog:

version 2.81
	Improve cache behaviour for TCP connections. For ease of
	implementaion, dnsmasq has always forked a new process to handle
	each incoming TCP connection. A side-effect of this is that
	any DNS queries answered from TCP connections are not cached:
	when TCP connections were rare, this was not a problem.
	With the coming of DNSSEC, it is now the case that some
	DNSSEC queries have answers which spill to TCP, and if,
	for instance, this applies to the keys for the root, then
	those never get cached, and performance is very bad.
	This fix passes cache entries back from the TCP child process to
	the main server process, and fixes the problem.

	Remove the NO_FORK compile-time option, and support for uclinux.
	In an era where everything has an MMU, this looks like
	an anachronism, and it adds to (Ok, multiplies!) the
	combinatorial explosion of compile-time options. Thanks to
	Kevin Darbyshire-Bryant for the patch.

	Fix line-counting when reading /etc/hosts and friends; for
	correct error messages. Thanks to Christian Rosentreter
	for reporting this.

	Fix bug in DNS non-terminal code, added in 2.80, which could
	sometimes cause a NODATA rather than an NXDOMAIN reply.
	Thanks to Norman Rasmussen, Sven Mueller and Maciej Żenczykowski
	for spotting and diagnosing the bug and providing patches.

	Support TCP-fastopen (RFC-7413) on both incoming and
	outgoing TCP connections, if supported and enabled in the OS.

	Improve kernel-capability manipulation code under Linux. Dnsmasq
	now fails early if a required capability is not available, and
	tries not to request capabilities not required by its
	configuration.

	Add --shared-network config. This enables allocation of addresses
	by the DHCP server in subnets where the server (or relay) does not
	have an interface on the network in that subnet. Many thanks to
	kamp.de for sponsoring this feature.

	Fix broken contrib/lease_tools/dhcp_lease_time.c. A packet
	validation check got borked in commit 2b38e382 and release 2.80.
	Thanks to Tomasz Szajner for spotting this.

	Fix compilation against nettle version 3.5 and later.

	Fix spurious DNSSEC validation failures when the auth section
	of a reply contains unsigned RRs from a signed zone,
	with the exception that NSEC and NSEC3 RRs must always be signed.
        Thanks to Tore Anderson for spotting and diagnosing the bug.

	Add --dhcp-ignore-clid. This disables reading of DHCP client
	identifier option (option 61), so clients are only identified by
	MAC addresses.

	Fix a bug which stopped --dhcp-name-match from working when a hostname
	is supplied in --dhcp-host. Thanks to James Feeney for spotting this.

	Fix bug which caused very rarely caused zero-length DHCPv6 packets.
	Thanks to Dereck Higgins for spotting this.

	Add --tftp-single-port option.

	Enhance --conf-dir to load files in a deterministic order. Thanks to
	Evgenii Seliavka for the suggestion and initial patch.

	In the router advert code, handle case where we have two
	different interfaces on the same IPv6 net, and we are doing
	RA/DHCP service on only one of them. Thanks to NIIBE Yutaka
	for spotting this case and making the initial patch.

	Support prefixed ranges of ipv6 addresses in dhcp-host.
	This eases problems chain-netbooting, where each link in the
	chain requests an address using a different UID. With a single
	address, only one gets the "static" address, but with this
	fix, enough addresses can be reserved for all the stages of the
	boot. Many thanks to Harald Jensås for his work on this idea and
	earlier patches.

	Add filtering by tag of --dhcp-host directives. Based on a patch
	by Harald Jensås.

	Allow empty server spec in --rev-server, to match --server.

	Remove DSA signature verification from DNSSEC, as specified in
	RFC 8624. Thanks to Loganaden Velvindron for the original patch.

	Add --script-on-renewal option.

(cherry picked from commit 051af8e386dc7d2fd1feeea7ba4ed2e162b52320)
2020-04-29 04:25:50 +02:00
Florian Klink
f7efe36e1f Merge pull request #86247 from mweinelt/20.03/openldap/v2.4.50
[20.03] openldap: 2.4.49 → 2.4.50
2020-04-29 00:05:35 +02:00
Graham Christensen
ab3adfe1c7 Merge pull request #85757 from mweinelt/20.03/babeld-1.9.2
[20.03] babeld: 1.9.1 → 1.9.2
2020-04-28 17:56:19 -04:00
Martin Weinelt
dd86564612 openldap: 2.4.49 → 2.4.50
Fixes: CVE-2020-12243

In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters
with nested boolean expressions can result in denial of service
(daemon crash).

(cherry picked from commit 8934e710d4692f954b5b3616c71e10e374df0137)
2020-04-28 21:53:17 +02:00
Matthew Bauer
e64b2be53c kde/{kate,konqueror,okular}: decrease text mimetype preference
These .desktop files set InitialPreference>1 which will override other
associations even the .desktop appears first in XDG_DATA_DIRS. This
applies to:

- org.kde.kate.desktop
- org.kde.kwrite.desktop
- kfmclient_html.desktop
- okularApplication_txt.desktop

Fixes #86137

(cherry picked from commit b3f812688c)
2020-04-28 14:11:20 -04:00
worldofpeace
a5b5cb8765 pantheon.gala: 3.3.0 -> 3.3.1
https://github.com/elementary/gala/releases/tag/3.3.1
(cherry picked from commit f5ddad7d5e)
2020-04-28 14:04:28 -04:00
worldofpeace
657c31ea8d pantheon.switchboard-plug-pantheon-shell: 2.8.3 -> 2.8.4
(cherry picked from commit 9d73d28580)
2020-04-28 14:04:28 -04:00
Michael Fellinger
e97d89fde2 gitlab: update.py: invoke bundle lock manually
`bundix -l` doesn't work, as it treats bundler's warning about upgrading
the lockfile version as an error, so invoke `bundle lock` manually.

(cherry picked from commit c7d47ce06fba88341e2d072379013414be4ee2e1)
2020-04-28 18:54:44 +02:00
Florian Klink
e2650954d3 gitaly: 12.8.8 -> 12.8.9
(cherry picked from commit c86c77be0cf45023586e7252bfb05238ae6d38db)
2020-04-28 18:54:44 +02:00
Florian Klink
0364b92be6 gitlab-workhorse: 8.21.1 -> 8.21.2
(cherry picked from commit f7ddd30bef15238d6d9a12f48408d38571944d85)
2020-04-28 18:54:43 +02:00
Florian Klink
c69934e1b9 gitlab: support passing --rev to the update-all script
While it's already possible to invoke `update-data` with the `--rev`
argument, one still needs to run all later phases manually.

Fix this, by having `update-all` also accept a `--rev` argument, and
pass it down to `update-data`.

Also, make the help text a bit more usable, by suggesting the usual
versioning scheme used these times.

(cherry picked from commit 191c2c67a409ae8cf3d3bee7811a7b10397efe81)
2020-04-28 18:54:43 +02:00
adisbladis
2437cd6094 Merge pull request #86213 from afrepues/build-melpa-stable-with-no-null-pkgs
emacs-modes: build MELPA package sets without null packages
2020-04-28 16:47:14 +02:00
Martin Milata
1d8a149cce libmicrodns: 0.1.0 -> 0.1.2
- CVE-2020-6071
- CVE-2020-6072
- CVE-2020-6073
- CVE-2020-6077
- CVE-2020-6078
- CVE-2020-6079

Buildsystem switched to Meson+Ninja.

(cherry picked from commit 18f3661f92)
2020-04-28 15:25:19 +01:00
Florian Klink
9153c23157 gitlab: 12.8.8 -> 12.8.9
See
https://about.gitlab.com/releases/2020/04/14/critical-security-release-gitlab-12-dot-9-dot-3-released/
for details.
(cherry-picked from commit d1902923fa)
2020-04-28 16:15:47 +02:00
Michael Weiss
fc30d6f68f Merge pull request #86199 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.33.3 -> 1.33.4 (backport)
2020-04-28 15:20:57 +02:00
Kim Lindberger
ac29e16aee Merge pull request #86190 from talyz/release-20.03
[20.03] nixos/gitlab: Fix services.gitlab.enableStartTLSAuto
2020-04-28 14:06:03 +02:00
Michael Weiss
24202c0c2e signal-desktop: 1.33.3 -> 1.33.4
(cherry picked from commit 660d284137)
2020-04-28 13:49:53 +02:00
talyz
5a527386f0 nixos/gitlab: Fix services.gitlab.enableStartTLSAuto
'toString false' results in an empty string, which, in this context,
is a syntax error. Use boolToString instead.

Fixes #86160

(cherry picked from commit c0a838df38)
2020-04-28 11:45:19 +02:00
Christoph Neidahl
ffe9bf6311 palemoon: 28.8.4 -> 28.9.1, add GTK3 option
(cherry picked from commit e17bc8281b7423d766d4a95949523618ae628335)
2020-04-28 08:20:50 +02:00
Samuel Rivas
dd1f0a1518 stylish-haskell: Unmark broken in hackage-packages
HsYAML-aeson: Unmark broken

As suggested in the review
2020-04-28 07:11:39 +02:00
Samuel Rivas
171aace39d haskellPackages.stylish-haskell: fix broken dependencies 2020-04-28 07:05:05 +02:00
Matthew Bauer
365ca11121 Merge pull request #86154 from bhipple/bp/grpcio
[20.03] python.pkgs.grpcio: use system openssl, zlib, and c-ares
2020-04-27 22:54:46 -05:00
worldofpeace
f18719c1dc Merge pull request #86118 from xaverdh/options-types-backport
[20.03] treewide: add types to boolean / enable options
2020-04-27 22:20:51 -04:00
Benjamin Hipple
3aeaf74984 Merge pull request #86155 from kevinastock/ftp.gnu.org
[20.03] aspell, tla: use HTTPS instead of FTP
2020-04-27 19:53:43 -04:00
Kevin Stock
31cab04568 aspell, tla: use HTTPS instead of FTP
ftp.gnu.org intends to disable the FTP protocol for downloads on this
server, and strongly recommends using https instead.

(cherry picked from commit 295475a378)
2020-04-27 19:33:43 -04:00
Matthew Bauer
b6ec576f05 python.pkgs.grpcio: use system openssl, zlib, and c-ares
(cherry picked from commit 849f26d61c)
2020-04-27 19:25:30 -04:00
Maximilian Bosch
2faa76db27 mautrix-whatsapp: 2020-04-21 -> 2020-04-21-1
(cherry picked from commit 1066f11e4b)
2020-04-28 00:44:43 +02:00
Jörg Thalheim
7d0b089bf3 Merge pull request #86108 from knl/security-fix-oauth2_proxy 2020-04-27 15:29:48 +01:00
Elyhaka
b4f2f298e1 teams: fixing pulseaudio access
(cherry picked from commit 73e4647085)
2020-04-27 15:12:10 +01:00
Nikola Knezevic
92ab8778e8 oauth2_proxy: Backport security fix (CVE-2017-1000070)
Since 20.03 still uses old oauth2_proxy (3.2.0), which is not compatible
with the newest one (5.1.0), this change backports an important security
fix to 3.2.0:

a316f8a06f

The vulnerability is an open redirect, where a bad actor can redirect a
session to another domain using `/\` in redirect URIs.
2020-04-27 15:56:22 +02:00
David Terry
9c44146647 wireguard-compat: 1.0.20200413 -> 1.0.20200426
https://lists.zx2c4.com/pipermail/wireguard/2020-April/005237.html
(cherry picked from commit e9c44e8956)
2020-04-27 13:07:28 +02:00
Dominik Xaver Hörl
1b290e764e treewide: add types to boolean / enable options or make use of mkEnableOption 2020-04-27 12:24:52 +02:00
Vincent Laporte
694b4ca705 coqPackages.coqhammer: 1.1.1 → 1.2
Add support for Coq 8.11

(cherry picked from commit ef964a801e)
2020-04-27 10:41:18 +02:00
Vincent Laporte
61bea7bf4a coqPackages.equations: 1.2 → 1.2.1
(cherry picked from commit a4adb1f75b)
2020-04-27 08:47:42 +02:00
Michael Lingelbach
324a7844dc libnvidia-container: 1.0.0 -> 1.0.6
(cherry picked from commit 9e315b98a21bb9e05b0254c321086b832c17f2be)
2020-04-26 21:12:25 -07:00
worldofpeace
9137f05564 Merge pull request #86071 from NinjaTrappeur/luaexpat-remove-broken
lua51Packages.luaexpat: Removing broken meta attribute.
2020-04-26 14:45:03 -04:00
Félix Baylac-Jacqué
5a31e46b7a lua51Packages.luaexpat: Removing broken meta attribute.
It seems like luaexpat as been mistakenly marked as broken during a
20.03 a zero hydra failures tree-wide commit. Removing the broken meta
attribute.

Discovered this problem when trying to rebuild the prosody XMPP server.
2020-04-26 20:17:31 +02:00
worldofpeace
5bc2da9f42 Merge pull request #86066 from davidak/backport-commit-policy
[20.03] Update commit policy for stable release branches
2020-04-26 13:38:56 -04:00
Tim Steinbach
ba710d964f linux: 4.9.219 -> 4.9.220
(cherry picked from commit 4883dde6b7)
2020-04-26 12:32:14 -04:00
Tim Steinbach
29b1136583 linux: 4.4.219 -> 4.4.220
(cherry picked from commit 6efb2ba2bf)
2020-04-26 12:32:14 -04:00
Tim Steinbach
e98c8862c2 linux: 4.14.176 -> 4.14.177
(cherry picked from commit 6617a79ba3)
2020-04-26 12:32:14 -04:00
davidak
57e2dcb1dd Update commit policy for stable release branches
only very few people followed the strict policy in the last 5 years. the
maintainers accept backports without reason when it's obvious, so i
updated the policy to reflect that

(cherry picked from commit bcc269e6c87a4f445a7ede5207fe3537b0ce7648)
2020-04-26 18:06:09 +02:00
Graham Christensen
0cd47d9c05 Merge pull request #86060 from AmineChikhaoui/20.03-amis-backport
[20.03] ec2-amis.nix: add NixOS 20.03 images
2020-04-26 10:02:04 -04:00
AmineChikhaoui
a1e2b647e5 ec2-amis.nix: add NixOS 20.03 images
Fixes #85857.

(cherry picked from commit 9cf9e66e6f)
2020-04-26 09:58:48 -04:00
Amit Levy
c0c339b645 zulip: 4.0.0 -> 5.0.0 (#85770)
Zulip 5.0 fixes multiple security issues. See:
https://blog.zulip.org/2020/04/01/zulip-desktop-5-0-0-security-release/

(cherry picked from commit 1586f2851e)
Reason: Zulip < 5.0.0 no longer works with the Zulip server---if you run
it with an up to date Zulip server you get an error message requesting
you upgrade to 5.0 and the app will otherwise not be functional.
2020-04-26 12:14:12 +00:00
Jörg Thalheim
a49a2fb8c1 wireguard: 1.0.20200401 -> 1.0.20200413
(cherry picked from commit 21ec1f5ead)
2020-04-26 13:50:12 +02:00
Jörg Thalheim
24cf10d080 wireguard-tools: reference tests
(cherry picked from commit 77dc7ef908)
2020-04-26 13:50:10 +02:00
Benjamin Hipple
74a80c5a9a Merge pull request #86023 from knedlsepp/fix-ncview
ncview: Unmark as broken on 20.03
2020-04-25 20:02:04 -04:00
bb010g
6df8f27c39 nixos/documentation: Allow specifying extraSources
Because there was absolutely no way of setting this without rewriting
parts of the module otherwise.

(cherry picked from commit 34dd64b0cc)
2020-04-26 00:18:20 +02:00
worldofpeace
dffd0dfe3c Merge pull request #86015 from worldofpeace/p11-kit-trust-paths-20.03
[20.03] p11-kit: add trust paths
2020-04-25 17:52:16 -04:00
worldofpeace
4b6bfecc0b Merge pull request #85908 from paumr/release-20.03-alacritty
[20.03] alacritty: backport 0.4.2
2020-04-25 17:47:36 -04:00
Josef Kemetmüller
1489d61a4d ncview: Unmark as broken
Tested that the GUI works using an example netCDF file.
2020-04-25 22:44:14 +02:00
paumr
aa9ea94636 alacritty: fixed cargo hash
The cargo hash differed from the cherry-picked one due to changes to
fetchCargoTarball on the master branch #79975

On the master this happened here:
eb11feaa0b
1f03a3434f

This should not effect the actual build result.
2020-04-25 21:43:41 +02:00
Cole Helbling
2b9ad34d16 alacritty: 0.4.1 -> 0.4.2
* alacritty now has its own org, so I changed the URLs to point there
* updated the description to match upstream's description
* formatted with nixpkgs-format

(cherry picked from commit 45f53ccd8b)
Reason:
Fixes some bugs on X11, namely:
- Crash when starting on some X11 systems
- Alacritty not ignoring keyboard events for changing WM focus on X11
- Incorrect modifiers tracking on X11 and macOS, leading to 'sticky' modifiers
2020-04-25 21:43:41 +02:00
Cole Helbling
7535e9a046 maintainers: add cole-h
(cherry picked from commit ecf79a07e1)
2020-04-25 21:43:41 +02:00
worldofpeace
51e6e8930e p11-kit: add trust paths
Fixes  #82422

(cherry picked from commit 4c40b43a7c)
2020-04-25 14:14:06 -04:00
worldofpeace
6c2e7b28e7 Merge pull request #86008 from ryneeverett/python-stem-unbroken2
[20.03] pythonPackages.stem: unbroken
2020-04-25 14:10:27 -04:00
worldofpeace
4786f8e5b7 Merge pull request #85854 from emmanuelrosa/skype-dep-8.56
skypeforlinux: 8.55.0.141 -> 8.56.0.103
2020-04-25 11:59:11 -04:00
Maximilian Bosch
9aa5f83b41 epson-escpr2: 1.1.1 -> 1.1.11
(cherry picked from commit f5f85d16d1)
2020-04-25 17:54:24 +02:00
worldofpeace
5450e23dd0 Merge pull request #86000 from mweinelt/20.03/hostapd/cve-2019-16275
[20.03] hostapd: apply patch for CVE-2019-16275
2020-04-25 11:44:08 -04:00
worldofpeace
1cdb903086 Merge pull request #85990 from Ma27/linux-5.5-eval-error
[20.03] linux_5_5: throw a meaningful error instead of just removing the attribute
2020-04-25 11:16:50 -04:00
ryneeverett
e349f5ccba pythonPackages.stem: remove marked as broken
A third attempt after #85642 which I hadn't recognized as a backport
of #81679.

The bug is just with the test suite on python 3.8 which was fixed in 1.8.0.
See bug report: https://trac.torproject.org/projects/tor/ticket/30847.

(cherry picked from commit 618cdd24731c49ef62d2d4f4de46162eb5f3e5bb)
2020-04-25 15:06:22 +00:00
Cole Mickens
7bb0ca24b8 pythonPackages.stem: 1.7.1 -> 1.8.0
(cherry picked from commit f539a47dab)
2020-04-25 15:04:58 +00:00
Jan Tojnar
915d2c3e69 gnome3.updateScript: optimize unfrozen updates
When the updates are not frozen, there is no need to try to extract versions from attributes.

(cherry picked from commit 4239bf17ec)
2020-04-25 15:33:44 +02:00
Jan Tojnar
eff0f82385 gnome3.updateScript: fix tarball eval on nonexisting attrpaths
As reported in 974f11cb29 (commitcomment-38735081),
the tarball will fail to evaluate when updateScript is given a non-existing attrPath because getAttrFromPath
uses abort, which terminates the evaluation.

(cherry picked from commit f544c293ec)
2020-04-25 15:33:43 +02:00
Jan Tojnar
189a0de9bf goocanvasmm2: fix update script attrPath
(cherry picked from commit 03c0ab3857)
2020-04-25 15:33:43 +02:00
Martin Weinelt
356c8990ae hostapd: apply patch for CVE-2019-16275
AP mode PMF disconnection protection bypass

Published: September 11, 2019
Identifiers:
- CVE-2019-16275
Latest version available from: https://w1.fi/security/2019-7/

Vulnerability

hostapd (and wpa_supplicant when controlling AP mode) did not perform
sufficient source address validation for some received Management frames
and this could result in ending up sending a frame that caused
associated stations to incorrectly believe they were disconnected from
the network even if management frame protection (also known as PMF) was
negotiated for the association. This could be considered to be a denial
of service vulnerability since PMF is supposed to protect from this type
of issues. It should be noted that if PMF is not enabled, there would be
no protocol level protection against this type of denial service
attacks.

An attacker in radio range of the access point could inject a specially
constructed unauthenticated IEEE 802.11 frame to the access point to
cause associated stations to be disconnected and require a reconnection
to the network.

Vulnerable versions/configurations

All hostapd and wpa_supplicants versions with PMF support
(CONFIG_IEEE80211W=y) and a runtime configuration enabled AP mode with
PMF being enabled (optional or required). In addition, this would be
applicable only when using user space based MLME/SME in AP mode, i.e.,
when hostapd (or wpa_supplicant when controlling AP mode) would process
authentication and association management frames. This condition would
be applicable mainly with drivers that use mac80211.

Possible mitigation steps

- Merge the following commit to wpa_supplicant/hostapd and rebuild:

  AP: Silently ignore management frame from unexpected source address

  This patch is available from https://w1.fi/security/2019-7/

- Update to wpa_supplicant/hostapd v2.10 or newer, once available

(cherry picked from commit 3e9f3a3ebd)
2020-04-25 14:36:31 +02:00
Jörg Thalheim
346317b9fa zfs: fix build against 5.6
(cherry picked from commit 75c28ebdf7)
2020-04-25 13:35:38 +02:00
Maximilian Bosch
7a0bafad23 iwd: 1.6 -> 1.7
(cherry picked from commit 61c95a2eec)
2020-04-25 13:28:37 +02:00
Maximilian Bosch
f4c9084865 ell: 0.30 -> 0.31
(cherry picked from commit 74fcd4f2d6)
2020-04-25 13:28:34 +02:00
Maximilian Bosch
b938618b5a linux_5_5: throw a meaningful error instead of just removing the attribute
I was using a 5.5 kernel on NixOS 20.03 and got an "attribute not found"
error yesterday when trying to update my system.

In order to understand why, I had to look up what happened in the `git
log` which is IMHO not a good experience for e.g. a beginner.
2020-04-25 11:39:51 +02:00
Frederik Rietdijk
94e39623a4 playonlinux: fix build
(cherry picked from commit 93a9ac696b)
2020-04-25 08:00:29 +02:00
worldofpeace
f18b83859e Merge pull request #85975 from worldofpeace/common-updater-backports
[20.03] common-updater-scripts: Handle errors in src hashing
2020-04-24 21:18:05 -04:00
worldofpeace
ab577e7723 Merge branch 'release-20.03' into staging-20.03 2020-04-24 20:44:48 -04:00
worldofpeace
a001d7cdde gnome3.mutter328: backports from gnome-3-28 2020-04-24 17:22:48 -07:00
worldofpeace
3613d9d9ed gnome3.mutter: 3.34.4 -> 3.34.5, backports
Backports gnome-3-34 patches as well.
2020-04-24 17:22:48 -07:00
Konrad Borowski
4e85c84cc7 slimrat: remove
The package was marked as broken for 3 years, there were no
upstream updates for 8 years, and the program requires third
party services that don't provide APIs to work. I think it's
safe to say that this program is not going to work.

(cherry picked from commit 409f57508d)
2020-04-24 20:16:19 -04:00
Jan Tojnar
8ccd53f989 common-updater-scripts: Fix replacing SRI hashes
SRI hashes (base64 encoded) can contain + sign which is a special character
in extended regular expressions so it needs to be escaped.

(cherry picked from commit 09a4a051e8)
2020-04-24 20:09:53 -04:00
Jan Tojnar
e6825ab4ee common-updater-scripts: Handle errors in src hashing
Previously, when downloading src failed for other reason than hash mismatch,
the error ended up in newHash. This made evaluation fail since the error message
is not valid hash. Now the failure will make newHash empty.

It is also much cleaner than previously since \K is very cool thing
and we no longer grep for legacy messages.

(cherry picked from commit 2e9eb449eb)
2020-04-24 20:09:52 -04:00
Jan Tojnar
2cd74ace74 maintainers/scripts/update.nix: allow updating overlays
(cherry picked from commit bacb0969f2)
2020-04-24 20:09:52 -04:00
worldofpeace
ace9deb7b2 Merge pull request #85973 from worldofpeace/gnome-update-freezer-20.03
[20.03] gnome3.updateScript: Add freeze functionality
2020-04-24 20:06:49 -04:00
worldofpeace
942a6016ea gnome3.updateScript: frozen 2020-04-24 19:38:34 -04:00
Jan Tojnar
89a74d4384 gnome3.updateScript: format with black
(cherry picked from commit b0a2fb1e03)
2020-04-24 19:37:58 -04:00
Jan Tojnar
dd45b8a692 gnome3.updateScript: Add freeze functionality
On stable releases, we will want to change the freeze parameter in pkgs/desktops/gnome-3/update.nix
to true to limit the gnome update script to only bump patch versions.

(cherry picked from commit 974f11cb29)
2020-04-24 19:37:58 -04:00
Florian Klink
ebffadfda3 Merge pull request #85971 from m-scr/vbox-6.1.6-20.03
[20.03] virtualbox: 6.1.4 -> 6.1.6
2020-04-25 00:57:10 +02:00
Maximilian Bosch
0657426ad9 gitAndTools.diff-so-fancy: 1.2.7 -> 1.3.0
https://github.com/so-fancy/diff-so-fancy/releases/tag/v1.3.0
(cherry picked from commit a3467dfa82)
2020-04-24 21:43:52 +02:00
Maximilian Bosch
b79ee84c29 matrix-synapse: 1.12.1 -> 1.12.4
https://github.com/matrix-org/synapse/releases/tag/v1.12.4
(cherry picked from commit 72cdc6d365)
2020-04-24 18:05:32 +02:00
Fabian Möller
e5bea8e95a virtualbox: 6.1.4 -> 6.1.6
(cherry picked from commit 0481e09ad3)
2020-04-24 18:03:17 +02:00
Fabian Möller
e0c113dc78 virtualbox: add update script
(cherry picked from commit 93e8f5d90f)
2020-04-24 18:02:48 +02:00
Maximilian Bosch
85e5cc38f8 cargo-make: 0.30.5 -> 0.30.6
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.6
(cherry picked from commit 2a77540f7f)
2020-04-24 15:47:40 +02:00
Michael Weiss
b18d66f5d5 Merge pull request #85937 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.33.1 -> 1.33.3 (backport)
2020-04-24 15:43:01 +02:00
Michael Weiss
489d014b2c signal-desktop: 1.33.1 -> 1.33.3
(cherry picked from commit edc421138b)
2020-04-24 15:10:29 +02:00
Jörg Thalheim
ab816b9de0 Merge pull request #85888 from mmilata/20.03-openvpn-2.4.9 2020-04-24 13:58:23 +01:00
rnhmjoj
2750685450 haskellPackages.breve: unbreak 2020-04-24 14:41:30 +02:00
Pascal Bach
08630e56d9 skypeforlinux: 8.56.0.103 -> 8.58.0.93
Cherry-picked 36c7dc26e4
Original commit merged in PR https://github.com/NixOS/nixpkgs/pull/83355
2020-04-24 12:13:19 +07:00
Dmitry Kalinkin
4b30d97cd5 pulumi-bin: fix darwin build
(cherry picked from commit 712d1596ef)
cc #85801
2020-04-23 19:02:33 -04:00
Dmitry Kalinkin
c0a4a45313 pulumi-bin: use nativeBuildInputs
(cherry picked from commit ba13482494)
cc #85801
2020-04-23 19:02:13 -04:00
Ismaël Bouya
4d9a0aff06 texlive: Fix texlive pstricks
The upgrade of ghostscript to 9.50 produced some issues with texlive
2019. This patch adds an additional fix necessary for the upgrade
preventing pstricks from working correctly:

  https://tug.org/pipermail/dvipdfmx/2019-November/000036.html

(cherry picked from commit bb79233b94)
cc #85736

Conflicts:
	pkgs/tools/typesetting/tex/texlive/bin.nix
2020-04-23 18:25:40 -04:00
Dmitry Kalinkin
726ffc157b texlive.bin: use patches to apply poppler84.patch
This is a cherry-pick of af72bf0ae2
without addition of the new patch.
2020-04-23 18:23:10 -04:00
Martin Milata
fc12046f29 openvpn: 2.4.7 -> 2.4.9
Fixes CVE-2020-11736

(cherry picked from commit f35d50c68c)
2020-04-23 21:32:08 +02:00
Tim Steinbach
89273a29d3 linux: 5.6.6 -> 5.6.7 2020-04-23 08:18:15 -04:00
Tim Steinbach
bf7da65645 linux: 5.4.34 -> 5.4.35 2020-04-23 08:18:15 -04:00
Tim Steinbach
f39d668fcf linux: 4.19.117 -> 4.19.118 2020-04-23 08:18:15 -04:00
Niklas Hambüchen
429a8ab9ca journald service: Add helpful comments about the journal getting full
(cherry picked from commit 811411db6e)
2020-04-23 13:35:47 +02:00
Aaron Andersen
60fe3a1235 Merge pull request #85645 from aanderse/redmine
redmine: 4.1.0 -> 4.1.1 [20.03 backport]
2020-04-23 06:02:41 -04:00
Arian van Putten
acf9d818b0 nixos/datadog-agent: Fix restartTriggers
Fixes #85800

1d61efb7f1 accidentially changed the
restartTriggers of `datadog-agent.service` to point to the attribute
name (in this case, a location relative to `/etc`), instead of the
location of the config files in the nix store.

This caused datadog to not get restarted on activation of new
config, if the file name hasn't changed.

Fix this, by pointing this back to the location in the nix store.

(cherry picked from commit f332109ebf)
2020-04-23 10:37:49 +02:00
Arian van Putten
e7cc8ca669 nixos/networkd: Fix restartTriggers
1d61efb7f1 accidentially changed the
restartTriggers of systemd-networkd.service` to point to the attribute
name (in this case, a location relative to `/etc`), instead of the
location of the network-related unit files in the nix store.

This caused systemd-networkd to not get restarted on activation of new
networking config, if the file name hasn't changed.

Fix this, by pointing this back to the location in the nix store.

(cherry picked from commit 14395cc687)
2020-04-23 10:37:49 +02:00
Frederik Rietdijk
cf87b99622 Merge staging-20.03 into release-20.03
Build security updates on release branch so *-small channel is updated as soon as possible.
2020-04-23 08:56:16 +02:00
Samuel Dionne-Riel
c23427de0d Merge pull request #85845 from cole-h/linux-remove-5.5
[20.03] linux: really remove 5.5
2020-04-23 02:21:25 -04:00
Jörg Thalheim
8a966ceb0d Merge pull request #85674 from xaverdh/enable-add-type-backport 2020-04-23 07:20:25 +01:00
Ingo Blechschmidt
0321ceaf44 tigervnc: fix vncserver
vncserver of tigervnc doesn't start because xauth is missing from $PATH
2020-04-23 07:14:36 +01:00
Jörg Thalheim
b3da48e3db Merge pull request #85792 from Mic92/nixpkgs-review 2020-04-23 06:59:47 +01:00
Cole Helbling
3f72b7d952 linux: really remove 5.5
5.5 was removed in aa7c5b02ff,
but this attribute was missed, leading to an evaluation failure for the
nixos-20.03-small channel.
2020-04-22 21:49:46 -07:00
worldofpeace
d72fcc568d pantheon.wingpanel: add elementary-gtk-theme
(cherry picked from commit 834a49e0d4)
2020-04-22 21:54:15 -04:00
worldofpeace
eb7baaf13b pantheon.elementary-greeter: add elementary-gtk-theme
(cherry picked from commit 6cecb196fd)
2020-04-22 21:54:14 -04:00
worldofpeace
b3f8bbf782 elementary-planner: cleanup
* add elementary theme
The program forces this theme to be used
* update description

(cherry picked from commit 19c3bbfff1)
2020-04-22 21:54:09 -04:00
Dennis Gosnell
0787c45bd6 Merge pull request #85753 from vaibhavsagar/hakyll-upper-warp
haskellPackages.hakyll: relax upper bound on warp
2020-04-23 10:02:00 +09:00
kraem
a6a08dee68 linux: 5.6.5 -> 5.6.6
(cherry picked from commit c9cf25bc61)
2020-04-22 19:38:52 -04:00
kraem
792afd5e12 linux: 5.6.4 -> 5.6.5
(cherry picked from commit 4307923b86)
2020-04-22 19:38:52 -04:00
Tim Steinbach
70a12cabce linux: 5.6.3 -> 5.6.4
(cherry picked from commit f6e64feb14)
2020-04-22 19:38:51 -04:00
Tim Steinbach
fa5cfac879 linux: 5.6.2 -> 5.6.3
(cherry picked from commit 7bd91fe7af)
2020-04-22 19:38:50 -04:00
Tim Steinbach
ea522912f0 linux: 5.6.1 -> 5.6.2
(cherry picked from commit 4fbd9e3ab8)
2020-04-22 19:38:50 -04:00
Tim Steinbach
aa7c5b02ff linux: Remove 5.5
As per stable release policy, all LTS + latest stable kernel are available
2020-04-22 19:37:56 -04:00
Tim Steinbach
3ab0df6ade linux: Init 5.6.1
Change linux_latest to 5.6

(cherry picked from commit 7f56fdd997)
2020-04-22 19:36:13 -04:00
Tim Steinbach
6ab0695b54 Merge pull request #85806 from kraem/kraem/linux-bumps-20.03
[20.03] linux: version bumps
2020-04-22 19:29:31 -04:00
Vaibhav Sagar
3aa001ccaa haskellPackages.hakyll: relax upper bound on warp 2020-04-23 06:59:07 +08:00
Andreas Rammhold
24e0307028 luaPackages.luaexpat: unbreak, it builds just fine
While upgrading my Jabber server to 20.03 I noticed that the package was
marked broken but builds just fine.
2020-04-23 00:12:30 +02:00
adisbladis
10bfa0159c Merge pull request #85786 from adisbladis/p7zip-free-backport
p7zip: remove non-free RAR support (20.03 backport)
2020-04-22 22:50:55 +02:00
kraem
4f8f71a2ef linux: 5.5.17 -> 5.5.19
(cherry picked from commit 1e23dcbf22)

original commit bumped version
linux: 5.5.18 -> 5.5.19
2020-04-22 21:52:28 +02:00
kraem
d4cde17db2 linux: 5.4.33 -> 5.4.34
(cherry picked from commit 18c2b5a9aa)
2020-04-22 21:51:50 +02:00
kraem
ebc0cc8553 linux: 4.19.116 -> 4.19.117
(cherry picked from commit e074301be8)
2020-04-22 21:51:39 +02:00
Bjørn Forsman
150b510420 pythonPackages.pyside2-tools: unmark as broken
It builds fine.

Fixes: c6be4c1957 ("treewide: mark broken packages for 20.03")
2020-04-22 19:58:49 +02:00
Bjørn Forsman
56e89916c0 pythonPackages.pyside2: unmark as broken
It builds fine.

Fixes: c6be4c1957 ("treewide: mark broken packages for 20.03")
2020-04-22 19:58:48 +02:00
Martin Milata
4e03e34b3b tensor: use qt5's mkDerivation
(cherry picked from commit d5b14e58c4)
2020-04-22 13:40:25 -04:00
Martin Milata
3876c603e6 candle: use qt5's mkDerivation
(cherry picked from commit 1d8ea89504)
2020-04-22 13:40:24 -04:00
Martin Milata
e76489840d colord-kde: use qt5's mkDerivation
(cherry picked from commit 2e8962bb6e)
2020-04-22 13:40:24 -04:00
Martin Milata
6d09de03f7 luckybackup: use qt5's mkDerivation
(cherry picked from commit 8dd46d4ffe)
2020-04-22 13:40:24 -04:00
Martin Milata
e8c846ad9a firebird-emu: use qt5's mkDerivation
(cherry picked from commit 65050cd7e5)
2020-04-22 13:40:24 -04:00
Martin Milata
fe8274e733 glogg: use qt5's mkDerivation
(cherry picked from commit 7dce1c5202)
2020-04-22 13:40:23 -04:00
Martin Milata
fca141e5e0 iannix: use qt5's mkDerivation
(cherry picked from commit 9384f48860)
2020-04-22 13:40:23 -04:00
Martin Milata
93b73125eb pro-office-calculator: use qt5's mkDerivation
(cherry picked from commit ec922277e4)
2020-04-22 13:40:23 -04:00
Martin Milata
e637823f0d rocket: use qt5's mkDerivation
(cherry picked from commit adae9f1260)
2020-04-22 13:40:22 -04:00
Martin Milata
c91e56a430 qt-box-editor: use qt5's mkDerivation
(cherry picked from commit cc8d12118c)
2020-04-22 13:40:22 -04:00
Martin Milata
2f202c0fdb aqemu: use qt5's mkDerivation
(cherry picked from commit 4ee9179a11)
2020-04-22 13:40:22 -04:00
Martin Milata
dc89fcb5b3 awesomebump: use qt5's mkDerivation
Wrap Qt program manually, remove makeWrapper from nativeBuildInputs.

(cherry picked from commit a0a076b857)
2020-04-22 13:40:22 -04:00
Martin Milata
13d1d6a327 bibletime: use qt5's mkDerivation
(cherry picked from commit eae808331c)
2020-04-22 13:40:21 -04:00
Martin Milata
04125179fe bomi: use qt5's mkDerivation
Wrap Qt program manually, remove makeWrapper from nativeBuildInputs.

(cherry picked from commit 98f126615f)
2020-04-22 13:40:21 -04:00
Martin Milata
91924c8aef dfasma: use qt5's mkDerivation
(cherry picked from commit 21d3ce5887)
2020-04-22 13:40:21 -04:00
Martin Milata
a9eb2f3968 mindforger: use qt5's mkDerivation
(cherry picked from commit 22af8e8ed7)
2020-04-22 13:40:21 -04:00
Martin Milata
64918b6441 okteta: use qt5's mkDerivation
(cherry picked from commit affebc8600)
2020-04-22 13:40:20 -04:00
Martin Milata
564d837bd7 openbrf: use qt5's mkDerivation
(cherry picked from commit 9f0dba1302)
2020-04-22 13:40:20 -04:00
Martin Milata
8c74166139 phototonic: use qt5's mkDerivation
(cherry picked from commit 606a15d9d8)
2020-04-22 13:40:20 -04:00
Martin Milata
e678c75fd1 qcomicbook: use qt5's mkDerivation
(cherry picked from commit 2986699ab0)
2020-04-22 13:40:20 -04:00
Martin Milata
5534c1a925 qmediathekview: use qt5's mkDerivation
(cherry picked from commit 5f70a209da)
2020-04-22 13:40:19 -04:00
Martin Milata
2119ff2ef2 qstopmotion: use qt5's mkDerivation
(cherry picked from commit e036261b15)
2020-04-22 13:40:19 -04:00
Martin Milata
c4a0d91de3 ricochet: use qt5's mkDerivation
(cherry picked from commit 4b7193b67a)
2020-04-22 13:40:19 -04:00
Martin Milata
b31f27372c swift-im: use qt5's mkDerivation
(cherry picked from commit 86aab71590)
2020-04-22 13:40:18 -04:00
Martin Milata
d2da1247b9 traverso: use qt5's mkDerivation
(cherry picked from commit 461843af71)
2020-04-22 13:40:18 -04:00
Martin Milata
1f9a1564f9 valentina: use qt5's mkDerivation
(cherry picked from commit 01de13ad6f)
2020-04-22 13:40:18 -04:00
Martin Milata
f4c79152d9 write_stylus: use qt5's mkDerivation
(cherry picked from commit 904fc69424)
2020-04-22 13:40:18 -04:00
Martin Milata
844e157279 caneda: use qt5's mkDerivation
(cherry picked from commit 7d1c2c05c5)
2020-04-22 13:40:17 -04:00
Martin Milata
ef76bc4b35 calaos_installer: use qt5's mkDerivation
(cherry picked from commit 5858162f5e)
2020-04-22 13:40:17 -04:00
Martin Milata
dd4ad79e57 yabause: use qt5's mkDerivation
(cherry picked from commit f9ef2c194a)
2020-04-22 13:40:17 -04:00
Martin Milata
c605199ee5 httraqt: use qt5's mkDerivation
(cherry picked from commit b98fa7cdb8)
2020-04-22 13:40:17 -04:00
Martin Milata
c29d18f501 enyo-doom: use qt5's mkDerivation
(cherry picked from commit 83102fcbae)
2020-04-22 13:40:16 -04:00
worldofpeace
8ee460a3db pantheon.wingpanel-indicator-datetime: patch in a lot of fixes
These were rejected upstream, sadly https://github.com/elementary/wingpanel-indicator-datetime/pull/207.

(cherry picked from commit 7a164bf678)
2020-04-22 13:35:51 -04:00
Frederik Rietdijk
825a88e603 Merge pull request #85785 from primeos/git-backport-stable
[20.03] git: 2.25.3 -> 2.25.4 (security, CVE-2020-11008)
2020-04-22 19:27:08 +02:00
worldofpeace
5d69135c88 Merge pull request #85716 from minijackson/release-20.03
backport: python27Packages.soco: 0.18.1 -> 0.19, remove broken
2020-04-22 13:18:35 -04:00
R. RyanTM
5964eebb74 python27Packages.soco: 0.18.1 -> 0.19
(cherry picked from commit 84b95b46d8)
2020-04-22 19:13:47 +02:00
Jörg Thalheim
c7aa277bd4 nixpkgs-review: 2.2.0 -> 2.3.0
(cherry picked from commit 43790ee675)
2020-04-22 17:37:41 +01:00
adisbladis
72c633224a p7zip: Make unfree features (rar support) optional
(cherry picked from commit 955e235da3)
2020-04-22 16:45:06 +01:00
Emily
93dd26f969 p7zip: remove non-free RAR support
7-Zip's RAR implementation is built on the non-free UnRAR source code;
DOC/License.txt says:

      Licenses for files are:

        1) CPP/7zip/Compress/Rar* files:  GNU LGPL + unRAR restriction
        2) All other files:  GNU LGPL

      The GNU LGPL + unRAR restriction means that you must follow both
      GNU LGPL rules and unRAR restriction rules.

    ...

      unRAR restriction
      -----------------

        The decompression engine for RAR archives was developed using source
        code of unRAR program.
        All copyrights to original unRAR code are owned by Alexander Roshal.

        The license for original unRAR code has the following restriction:

        The unRAR sources cannot be used to re-create the RAR compression algorithm,
        which is proprietary. Distribution of modified unRAR sources in separate form
        or as a part of other software is permitted, provided that it is clearly
        stated in the documentation and source comments that the code may
        not be used to develop a RAR (WinRAR) compatible archiver.

The unrar licensing is [infamously restrictive and non-free][fedora];
it's inappropriate for us to keep the RAR support while labelling the
package as free software (and indeed there's a commented-out line
pointing out that the current `meta.license` is false). Unfortunately,
the 7-Zip upstream seems uninterested in replacing the code with a
freely-licensed alternative (see [7-Zip ticket #1229][7zip]).

[fedora]: https://fedoraproject.org/wiki/Licensing:Unrar
[7zip]: https://sourceforge.net/p/sevenzip/feature-requests/1229/

An alternative solution would be to mark the p7zip package as non-free
instead; I decided not to because its other functionality (especially
`.7z` support) is freely-licensed and useful, and there are free
software alternatives for extracting RAR files (e.g. in nixpkgs there's
`archiver`, which is written in a memory-safe language, and `unar`,
which at least doesn't have two patches for CVEs that haven't been
addressed upstream...).

I checked that `7z(1)` fails gracefully on `.rar` files now:

    emily@renko ~/tmp> curl -L -O https://www.philippwinterberg.com/download/example.rar
      % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                     Dload  Upload   Total   Spent    Left  Speed
    100 5715k  100 5715k    0     0  6716k      0 --:--:-- --:--:-- --:--:-- 6716k
    emily@renko ~/tmp> 7z x example.rar

    7-Zip [64] 16.02 : Copyright (c) 1999-2016 Igor Pavlov : 2016-05-21
    p7zip Version 16.02 (locale=en_CA.UTF-8,Utf16=on,HugeFiles=on,64 bits,8 CPUs x64)

    Scanning the drive for archives:
    1 file, 5853119 bytes (5716 KiB)

    Extracting archive: example.rar
    ERROR: example.rar
    Can not open the file as archive

    Can't open as archive: 1
    Files: 0
    Size:       0
    Compressed: 0

(cherry picked from commit 95f82e2a45)
2020-04-22 16:44:59 +01:00
Michael Weiss
961dbb2e6f git: 2.25.3 -> 2.25.4 (security, CVE-2020-11008)
See: https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.17.5.txt
2020-04-22 17:42:35 +02:00
Michael Weiss
065874054d git: Fix the update.sh script and use HTTPS
The syntax is ${parameter:-word} (i.e. previously this used
"latestTag" instead of the actual value).
(Fixes a regression from #85278.)

Also: Even though getting the latest tag isn't really security critical
(as long as Git itself is secure against untrusted input), I'd prefer to
switch from the Git to the HTTPS protocol (for authentication of the
server and encryption + uses a standard port).

(cherry picked from commit 666042141e)
2020-04-22 17:42:30 +02:00
James Ottaway
9b9fa3f7fc git: Allow the update script to target non-latest versions
This came in handy when I wanted to bump a patch version while avoiding
a new minor version.

(cherry picked from commit 4848eef29d)
2020-04-22 17:42:29 +02:00
Dennis Gosnell
8b5004fa32 Merge pull request #85759 from schmittlauch/staging-bump-asn1-types
haskellPackages.asn1-types: backport 0.3.3 -> 0.3.4
2020-04-22 23:59:34 +09:00
worldofpeace
95b9c99f6d Merge pull request #85533 from ivan/mark-some-unbroken
[20.03] pythonPackages.{namedlist, ludios_wpull}: mark broken only on Python 3.8
2020-04-22 07:55:37 -04:00
Michael Weiss
bd8e084703 chromium: 81.0.4044.113 -> 81.0.4044.122
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html

This update includes 8 security fixes.

CVEs: CVE-2020-6459 CVE-2020-6460 CVE-2020-645
(cherry picked from commit a2df9776f0)
Backport of #85729.
2020-04-22 12:45:04 +02:00
Michael Weiss
fc3722a534 chromium{Beta,Dev}: M81 -> M83 -> M84
(cherry picked from commit cb5c0a4bbc)
2020-04-22 12:45:03 +02:00
Michael Weiss
9ad0025195 chromium: Fix the VA-API build
(cherry picked from commit b533f10345)
2020-04-22 12:45:03 +02:00
Trolli Schmittlauch
e3d36b6ce5 haskellPackages.asn1-types: backport 0.3.3 -> 0.3.4
backports the fix for vincenthz/hs-asn1#35

(cherry picked from commit cb0e38127c7a66c292e60d7e8c1ab4eeb26c44a4)
2020-04-22 12:03:24 +02:00
Martin Weinelt
22be0dac7b babeld: 1.9.1 → 1.9.2
Dear all,

Babeld-1.9.2 is available from

  https://www.irif.fr/~jch/software/files/babeld-1.9.2.tar.gz
  https://www.irif.fr/~jch/software/files/babeld-1.9.2.tar.gz.asc

For more information about the Babel routing protocol, please see

  https://www.irif.fr/~jch/software/babel/

This is a bug fix release.  It fixes two bugs where IPv4 prefixes could be
represented incorrectly, with a range of confusing symptoms ; many thanks
to Faban Bläse for diagnosing the issue.  In addition, it fixes incorrect
parsing of unknown address encodings, thanks to Théo Bastian for the fix.

21 April 2020: babeld-1.9.2

  * Fixed two issues that could cause IPv4 routes to be represented
    incorrectly, with a range of confusing symptoms.  Thanks to
    Fabian Bläse.
  * Fixed incorrect parsing of TLVs with an unknown Address Encoding.
    Thanks to Théophile Bastian.
  * Fixed access to mis-aligned data structure.  Thanks to Antonin Décimo.

-- Juliusz Chroboczek

_______________________________________________
Babel-users mailing list
Babel-users@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/babel-users

(cherry picked from commit 34c230ad12ef4542c088964e2a450fba6a87ad65)
2020-04-22 11:59:43 +02:00
Ivan Kozik
dd2570d992 pythonPackages.ludios_wpull: unmark broken, mark disabled for Python 3.8
ludios_wpull depends on namedlist, which currently has failing tests
on Python 3.8.
2020-04-22 05:57:03 +00:00
Ivan Kozik
3f7a5cb2ac pythonPackages.namedlist: unmark broken, mark disabled for Python 3.8
https://nix-cache.s3.amazonaws.com/log/a4mdvyjbsy157i1v97rg6avp5a8inm0g-python3.8-namedlist-1.7.drv
2020-04-22 05:55:29 +00:00
Frederik Rietdijk
fca299bb64 Merge release-20.03 into staging-20.03 2020-04-22 07:48:30 +02:00
Vincent Laporte
b6c7259c4d ocamlPackages.merlin: 3.3.3 → 3.3.4
(cherry picked from commit 513e1339c0)
2020-04-22 07:28:29 +02:00
worldofpeace
abd33333de Merge pull request #85734 from mweinelt/20.03/openssl1.1.1g
[20.03] openssl: 1.1.1f → 1.1.1g
2020-04-21 21:44:23 -04:00
worldofpeace
63284ecf6f Merge pull request #85742 from cole-h/fix-ninja-patch
[20.03] ninja: fix 404'ing patch
2020-04-21 21:38:16 -04:00
Cole Helbling
91d4e9aa97 ninja: fix 404'ing patch
Kyndig on IRC noticed that building `ninja` from source would fail due
to a patch 404'ing (because the repo appears to no longer exist). Fetch
from upstream instead.
2020-04-21 18:22:14 -07:00
Martin Weinelt
ab06bb17da openssl: 1.1.1f → 1.1.1g
Fixes: CVE-2020-1967

Segmentation fault in SSL_check_chain (CVE-2020-1967)
=====================================================

Severity: High

Server or client applications that call the SSL_check_chain() function during or
after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a
result of incorrect handling of the "signature_algorithms_cert" TLS extension.
The crash occurs if an invalid or unrecognised signature algorithm is received
from the peer. This could be exploited by a malicious peer in a Denial of
Service attack.

OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue.  This
issue did not affect OpenSSL versions prior to 1.1.1d.

Affected OpenSSL 1.1.1 users should upgrade to 1.1.1g

This issue was found by Bernd Edlinger and reported to OpenSSL on 7th April
2020. It was found using the new static analysis pass being implemented in GCC,
- -fanalyzer. Additional analysis was performed by Matt Caswell and Benjamin
Kaduk.

(cherry picked from commit bb4f46855f)
2020-04-22 02:16:01 +02:00
worldofpeace
9e523c4d71 Merge pull request #85726 from davidak/os-release
Backport: Update link in /etc/os-release
2020-04-21 18:47:18 -04:00
davidak
dc73011436 Update link in /etc/os-release (#85723)
(cherry picked from commit 6a7e0562de)
2020-04-22 00:38:21 +02:00
Nicolas Schneider
9ee1172f6d android-studio: add ps to closure
When killing processes, android-studio uses `ps` to figure out which
subprocesses to kill. Without `ps` in the closure, this fails and the
process is never killed.

(cherry picked from commit c296bf7169)
Reason: Fixes a bug, see #85719.
2020-04-21 23:52:04 +02:00
Thomas Churchman
cbb2d6214f nixos/phpfpm: fix erroneous pools example
(cherry picked from commit 8880957042)
2020-04-21 22:16:48 +02:00
Florian Klink
ea83ab577a Merge pull request #82693 from m-scr/vbox-6.1.4-20.03
[20.03] virtualbox: 6.0.14 -> 6.1.4
2020-04-21 22:11:44 +02:00
obadz
083662c4a1 citrix_workspace: add 2004
(cherry picked from commit b06164281c)
2020-04-21 19:28:41 +02:00
Maximilian Bosch
b76b6c6d8d mongodb_3_4: fix license
As noted in #83433, the 3.4 branch of `mongodb` is still licensed under
AGPL[1].

[1] https://github.com/mongodb/mongo/blob/r3.4.24/README

(cherry picked from commit 25b9bca759)
2020-04-21 19:28:41 +02:00
Maximilian Bosch
00d5d64dc6 mautrix-whatsapp: 2020-04-12 -> 2020-04-21
(cherry picked from commit c844633cc7)
2020-04-21 19:28:41 +02:00
worldofpeace
4a549b819d Merge pull request #85644 from petabyteboy/feature/generate-config-2003
[20.03] nixos/tools: adapt for renamed console options
2020-04-21 12:51:02 -04:00
Dominik Xaver Hörl
33d12d781e treewide: add bool type to enable options, or make use of mkEnableOption
Add missing type information to manually specified enable options or replace them by mkEnableOption where appropriate.
2020-04-21 14:19:41 +02:00
Fabian Möller
e1c5a0a82a virtualboxExtpack: synchronize version with virtualbox
(cherry picked from commit b3323dbd07ab86a64bf4d32a13323ff564dde8f7)
2020-04-21 10:29:33 +02:00
Drew Risinger
e79d1e83f9 python3Packages.cirq: enable on python 3.8 2020-04-21 07:43:57 +02:00
Drew Risinger
85895aaca2 python3Packages.cirq: fix test failures (ZHF)
Also build on aarch64 by disabling a few failing tests.

(cherry picked from commit 02a5282c4f544dcc6c32cfeb1c4acd4a07615786)
2020-04-21 07:43:57 +02:00
Benjamin Hipple
1e90c46c2d mesa-glu: use HTTPS instead of FTP
FTP is often blocked by firewalls and is generally slower and less secure than HTTPS.

No change to `src` hash.

(cherry picked from commit ba8c116519)
2020-04-20 23:47:17 -04:00
Aaron Andersen
0811899e73 redmine: 4.1.0 -> 4.1.1
(cherry picked from commit 8eefb7ce14)
2020-04-20 20:11:52 -04:00
Milan Pässler
1866b4b9b0 nixos/tools: adapt for renamed console options 2020-04-21 02:09:35 +02:00
worldofpeace
c185d15160 Merge pull request #85424 from orivej/v20.03-muse
[release-20.03] muse: 3.1pre1 -> 3.1.0
2020-04-20 16:42:13 -04:00
worldofpeace
5272327b81 rl-2003: release date
(cherry picked from commit 6380be302a)
2020-04-20 11:58:47 -04:00
worldofpeace
b5fc240b3b nixos/manual: 19.09 -> 20.03
(cherry picked from commit 40f3faedbd)
2020-04-20 11:58:47 -04:00
worldofpeace
c6696bd6c7 CONTRIBUTING.md: 20.03
(cherry picked from commit a045b050dc)
2020-04-20 11:58:46 -04:00
worldofpeace
2a7ea90237 README.md: 20.03 release
(cherry picked from commit 51fcafe779)
2020-04-20 11:58:46 -04:00
Maximilian Bosch
e03eeffd61 Merge pull request #85557 from kmcopper/r20.03/vswitch-2.13
[20.03] openvswitch 2.12.0 -> 2.13.0
2020-04-20 01:57:02 +02:00
Florian Klink
426646cc9b Merge pull request #85584 from emilazy/acme-test-cleanups-20.03
[20.03] ACME test cleanups
2020-04-20 00:30:38 +02:00
Emily
f035e2638f nixos/tests/common/acme: don't set nameservers for client
The resolver is mainly useful for the ACME server, and acme.nix uses its
own DNS server to test DNS-01 challenges.

(cherry picked from commit 21f183a3fe)
2020-04-19 23:26:19 +01:00
Emily
60e6ba6630 nixos/tests/acme: use CAP_NET_BIND_SERVICE
(cherry picked from commit 695fd78ac4)
2020-04-19 23:26:18 +01:00
Emily
2b8100d702 nixos/tests/acme: use *.test domains
Shimming out the Let's Encrypt domain name to reuse client configuration
doesn't work properly (Pebble uses different endpoint URL formats), is
recommended against by upstream,[1] and is unnecessary now that the ACME
module supports specifying an ACME server. This commit changes the tests
to use the domain name acme.test instead, and renames the letsencrypt
node to acme to reflect that it has nothing to do with the ACME server
that Let's Encrypt runs. The imports are renamed for clarity:

* nixos/tests/common/{letsencrypt => acme}/{common.nix => client}
* nixos/tests/common/{letsencrypt => acme}/{default.nix => server}

The test's other domain names are also adjusted to use *.test for
consistency (and to avoid misuse of non-reserved domain names such
as standalone.com).

[1] https://github.com/letsencrypt/pebble/issues/283#issuecomment-545123242

Co-authored-by: Yegor Timoshenko <yegortimoshenko@riseup.net>
(cherry picked from commit d0f04c1623)
2020-04-19 23:26:14 +01:00
Emily
8283094333 nixos/tests/acme: don't restrict to x86_64
This was added in aade4e577b, but the
implementation of the ACME module has been entirely rewritten since
then, and the test seems to run fine on AArch64.

(cherry picked from commit 352e30df8a)
2020-04-19 23:25:04 +01:00
Emily
b0d26e9d67 nixos/tests/common/acme: enable Pebble strict mode
This lets us get early warning about any bugs or backwards-compatibility
hazards in lego.

Pebble will default to this in the future, but doesn't currently;
see https://github.com/letsencrypt/pebble/blob/v2.3.0/README.md#strict-mode.

(cherry picked from commit e6d5e83cf1)
2020-04-19 23:25:03 +01:00
Emily
e1c41b8c56 pebble: v2.2.2 -> v2.3.0
Also add myself to maintainers and correct meta.homepage.

(cherry picked from commit 6285d5eabd)
2020-04-19 23:25:02 +01:00
R. RyanTM
60ce81079a openvswitch: 2.12.0 -> 2.13.0
(cherry picked from commit c8523fe003)
2020-04-19 11:08:14 +00:00
worldofpeace
a17e021b94 Merge pull request #85366 from immae/fix_acme_postrun_20_03
nixos/acme: Fix postRun in acme certificate being ran at every run
2020-04-18 13:16:30 -04:00
Markus Wamser
7fcae3781e maintainers: add wamserma
Signed-off-by: Markus S. Wamser <github-dev@mail2013.wamser.eu>
2020-04-18 10:02:16 -04:00
Florian Klink
e79b7c45c3 Merge pull request #85370 from immae/fix_acme_reuse_key_20_03
Update the release documentation
2020-04-18 14:14:45 +02:00
Benjamin Hipple
a60473031a Merge pull request #85430 from kuznero/release-20.03
vscode, vscodium: 1.44.0 -> 1.44.1
2020-04-17 23:05:24 -04:00
Ismaël Bouya
ed20edf012 nixos/acme: Fix postRun in acme certificate being ran at every run
(cherry picked from commit 8e88b8dce2)
2020-04-17 23:51:32 +02:00
rnhmjoj
2e08e8cb26 mitmproxy: fix build
ZHF: #80379
2020-04-17 23:10:48 +02:00
Ismaël Bouya
21c4a33cee rl-2003: Update the release documentation
It currently says that everything will be backward compatible between lego and simp-le certificates, but it’s not.
2020-04-17 22:19:34 +02:00
Maximilian Bosch
668d0ded6b grocy: 2.7.0 -> 2.7.1
https://github.com/grocy/grocy/releases/tag/v2.7.1
(cherry picked from commit 135ae45d24)
2020-04-17 22:03:52 +02:00
Maximilian Bosch
e3354dfc8c neomutt: 20200320 -> 20200417
https://github.com/neomutt/neomutt/releases/tag/20200417

To fix the tests, I had to copy the recently created
`neomutt-test-files`[1] repository into the build-environment.

Also applied a patch from master[2] which ensures that the
`change-folder` macro actually switches to the specified folder.

[1] https://github.com/neomutt/neomutt-test-files
[2] 9e7537cadd

(cherry picked from commit 192485f8fa)
2020-04-17 19:39:55 +02:00
Dominik Xaver Hörl
8e053b9b2a neomutt: configure with zlib to enable imap compression
(cherry picked from commit 45cc3c986d)
2020-04-17 19:39:55 +02:00
worldofpeace
708ed56f52 Merge pull request #85436 from symphorien/paperwork-broken
paperwork: unmark as broken
2020-04-17 13:23:02 -04:00
worldofpeace
a68f099e18 Merge pull request #85395 from tollb/flashplayer-32.0.0.363-release-20.03
[20.03] flashplayer: 32.0.0.330 -> 32.0.0.363
2020-04-17 12:33:52 -04:00
nschoe
a96fbaac8c st: copy config file in 'prePatch' instead of 'preBuild'
The patch phase runs after the build phase. Which means than when
using an override to override both 'conf' and 'patches' to provide
a custom config file and apply some patches, it doesn't work:
- first the patches applied (optionally changing config.def.h)
- then preBuild is run which overrides config.def.h with the user
supplied one (effectively cancelling previously applied patches)

By copying the config file in the prePatch phase instead, changes
are kept and applied in order.

(cherry picked from commit b584941ab9)
2020-04-17 14:56:35 +01:00
Tim Steinbach
edd58cf4a7 linux: 5.4.32 -> 5.4.33
(cherry picked from commit e341107367)
2020-04-17 08:35:59 -04:00
Tim Steinbach
ca713d3f76 linux: 4.19.115 -> 4.19.116
(cherry picked from commit d9258d33be)
2020-04-17 08:35:59 -04:00
Symphorien Gibol
b27ac93054 paperwork: unmark as broken on x86 2020-04-17 12:00:00 +00:00
Jörg Thalheim
9094d35925 python38.pkgs.python-jsonrpc-server: disable for python38
(cherry picked from commit ee6f5a32bb)
2020-04-17 11:25:18 +01:00
Roman Kuznetsov
41ed7bf2ef vscodium: 1.44.0 -> 1.44.1
(cherry picked from commit 4fd1f49ea4)
2020-04-17 09:58:29 +02:00
Roman Kuznetsov
a5f5386b5c vscode: 1.44.0 -> 1.44.1
(cherry picked from commit 4a129e6a32)
2020-04-17 09:55:13 +02:00
Orivej Desh
47bf53ea40 muse: 3.1pre1 -> 3.1.0
cherry picked from commits:
624c83f70a
3c23cf9050
d5b27c6c74
2020-04-17 04:36:04 +00:00
Orivej Desh
4ed0ab5a8d libinstpatch: init at 1.1.4
cherry picked from commits:
f4c15495a6
577ab2b68b
49e2a18dbd
2020-04-17 04:33:53 +00:00
worldofpeace
5fe104de46 Merge pull request #85331 from NixOS/treewide-broken-20.03
treewide: mark broken packages for 20.03
2020-04-16 22:01:08 -04:00
worldofpeace
48c5aaa2fc treewide: mark broken wip 2020-04-16 21:29:49 -04:00
Maximilian Bosch
be4a41d062 mautrix-whatsapp: 2020-04-02 -> 2020-04-12
(cherry picked from commit e61c924adb)
2020-04-17 01:47:37 +02:00
Maximilian Bosch
962976d340 evcxr: 0.5.0 -> 0.5.1
582ce09f21/RELEASE_NOTES.md (version-051)
(cherry picked from commit cd5bc89cca)
2020-04-17 01:47:37 +02:00
Maximilian Bosch
34104aa360 grocy: 2.6.2 -> 2.7.0
(cherry picked from commit d4659dece2)
2020-04-16 23:31:44 +02:00
Maximilian Bosch
077bbd67d9 nixos/tests: fix inclusion of hydra test
(cherry picked from commit 5e124e5abd)
2020-04-16 23:31:44 +02:00
Maximilian Bosch
e7fea4336a hydra*: add passthru.tests to reference VM-tests
(cherry picked from commit ef80b6324b)
2020-04-16 23:31:44 +02:00
Maximilian Bosch
68ab8cf78b hydra-unstable: 2020-04-07 -> 2020-04-16
(cherry picked from commit 6f6c08af30)
2020-04-16 23:31:44 +02:00
Michael Weiss
1775cb5701 chromium: 81.0.4044.92 -> 81.0.4044.113
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html

This update includes 1 security fix.

CVEs: CVE-2020-6457
(cherry picked from commit ef2c3ab20e)
Backport of #85360.
2020-04-16 22:35:18 +02:00
Michael Weiss
81dccfd358 google-chrome-{beta,dev}: Fix one substituteInPlace pattern
(cherry picked from commit 16477d764f)
2020-04-16 22:35:18 +02:00
taku0
23f337162d [20.03] flashplayer: 32.0.0.330 -> 32.0.0.363
(cherry picked from commit ac374d41c816f7365a3945e657d2beba3962587d)

Backported 32.0.0.363 to release 20.03 for important bug fixes.

Also needed because old upstream release is no longer available.
2020-04-16 12:51:42 -04:00
Matthew Bauer
5eb6f1ed44 build-bazel-package: fix linkopt flags
These values were incorrect. We need to use NIX_LDFLAGS, not
NIX_LD_FLAGS. Also need to prefix all flags with -Wl, for GCC to
accept it.

(cherry picked from commit 184cd9f6ff)
2020-04-16 11:33:59 -05:00
Benjamin Hipple
956a83820b Merge pull request #85375 from lbpdt/bp/node-problem-detector
[20.03] node-problem-detector: init at 0.8.1
2020-04-16 12:03:38 -04:00
Emily
f2d4179af3 nixos/stage-1: check secret paths before copying
Fixes #84976.

(cherry picked from commit 91c6809946)
2020-04-16 18:01:56 +03:00
Vladimír Čunát
0e48b5079a Merge branch 'staging-20.03' into release-20.03 2020-04-16 16:50:43 +02:00
James Ottaway
dd3652df6b git: 2.25.0 -> 2.25.3
v2.25.3 addresses CVE-2020-5260.  /cc roundup #75974.

See https://lore.kernel.org/lkml/xmqqy2qy7xn8.fsf@gitster.c.googlers.com/
2020-04-16 16:45:50 +02:00
Michael Weiss
7e466bfc9b Merge pull request #85372 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.33.0 -> 1.33.1 (backport)
2020-04-16 16:38:56 +02:00
Louis Blin
d73ea8dbde node-problem-detector: init at 0.8.1
Package is missing, built from Golang sources on GitHub.

(cherry picked from commit 511cb624b7)
2020-04-16 15:04:05 +01:00
worldofpeace
2ee6b5ce7c Merge pull request #85333 from arianvp/revert-acme-backport
[20.03] Revert "nixos/acme: Fix allowKeysForGroup not applying immediately"
2020-04-16 08:43:41 -04:00
Michael Weiss
efdee67fca signal-desktop: 1.33.0 -> 1.33.1
(cherry picked from commit 56f7c93a2f)
2020-04-16 14:32:53 +02:00
Pascal Bach
900b58e4ee unifiStable: 5.12.35 -> 5.12.66
(cherry picked from commit 05cc2b1f51)
2020-04-16 12:57:32 +02:00
Vladimír Čunát
a8e2838a29 Merge branch 'release-20.03' into staging-20.03 2020-04-16 11:44:06 +02:00
Maximilian Bosch
c7153272cb nixos/doc: fix database-setup example for matrix-synapse
Closes #85327

(cherry picked from commit 74d6e86ec2)
2020-04-16 11:43:26 +02:00
Arian van Putten
c51c677140 Revert "nixos/acme: Fix allowKeysForGroup not applying immediately"
This reverts commit 5532065d06.

As far as I can tell setting RemainAfterExit=true here completely breaks
certificate renewal, which is really bad!

the sytemd timer will activate the service unit every OnCalendar=,
however with RemainAfterExit=true the service is already active! So the
timer doesn't rerun the service!

The commit also broke the actual tests, (As it broke activation too)
but this was fixed later in https://github.com/NixOS/nixpkgs/pull/76052
I wrongly assumed that PR fixed renewal too, which it didn't!

testing renewals is hard, as we need to sleep in tests.
2020-04-16 10:36:34 +02:00
Ben Wolsieffer
0f920b05cb g2o: fix log limit exceeded error in Hydra
(cherry picked from commit dd14ee840c)
2020-04-16 02:34:20 -04:00
Dmitry Kudriavtsev
92d43c9279 multimc: 0.6.7 -> 0.6.11
(cherry picked from commit d44b9d3028)
2020-04-16 02:11:28 -04:00
worldofpeace
931c4db67a pantheon.pantheon-agent-geoclue2: 1.0.3 -> 1.0.4
https://github.com/elementary/pantheon-agent-geoclue2/releases/tag/1.0.4
(cherry picked from commit 7eb0a87ace)
2020-04-16 02:06:45 -04:00
worldofpeace
e6b82df11d pantheon.elementary-videos: 2.7.0 -> 2.7.1
https://github.com/elementary/videos/releases/tag/2.7.1
(cherry picked from commit 8da467e04b)
2020-04-16 02:06:45 -04:00
worldofpeace
17f92998ad ephemeral: 6.3.1 -> 6.3.3
https://github.com/cassidyjames/ephemeral/releases/tag/6.3.2
https://github.com/cassidyjames/ephemeral/releases/tag/6.3.3
(cherry picked from commit c3408adb7d)
2020-04-16 02:06:45 -04:00
worldofpeace
a37adb3367 monitor: add note how to use indicator.
(cherry picked from commit fbd4290fa9)
2020-04-16 02:06:44 -04:00
worldofpeace
2c0f6ef15f monitor: 0.6.2 -> 0.7.1
https://github.com/stsdc/monitor/releases/tag/0.7.0
https://github.com/stsdc/monitor/compare/0.7.0...0.7.1
(cherry picked from commit f646069c4c)
2020-04-16 02:06:44 -04:00
worldofpeace
a5ad726734 agenda: 1.0.12 -> 1.1.0
https://github.com/dahenson/agenda/releases/tag/1.1.0
(cherry picked from commit e4dc205023)
2020-04-16 02:06:44 -04:00
R. RyanTM
9c11bd9318 ephemeral: 6.3.0 -> 6.3.1
(cherry picked from commit e38859deac)
2020-04-16 02:06:44 -04:00
Mario Rodas
3abf820bc1 Merge pull request #85353 from das-g/release-20.03_chromedriver-81.0.4044
chromedriver: 78.0.3904.70 -> 81.0.4044.69
2020-04-15 23:26:20 -05:00
Raphael Das Gupta
d219b7b59f chromedriver: 78.0.3904.70 -> 81.0.4044.69
backport of NixOS/nixpkgs#85302
2020-04-16 05:09:28 +02:00
worldofpeace
142afb8942 nasc: fix build
(cherry picked from commit 433ea74af1)
2020-04-15 17:20:51 -04:00
worldofpeace
6ca86a05fb ping: use vala_0_40
fails to build otherwise.

(cherry picked from commit 10c03528c0)
2020-04-15 17:20:40 -04:00
Samuel Leathers
c6be4c1957 treewide: mark broken packages for 20.03 2020-04-15 17:07:33 -04:00
Maximilian Bosch
8c3b765bc6 cargo-make: 0.30.4 -> 0.30.5
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.5
(cherry picked from commit b7c3c3f5cc)
2020-04-15 22:40:10 +02:00
vasile luta
a438aed5a6 tig: fix tig-completion's dependency on __git_complete
tig recently updated it's bash-completion making it depend on __git-complete from git.
Becase __git-complete is not automatically sourced tig bash completion fails.
Also this PR makes tig completion load on-demand.

(cherry picked from commit f57da8ef0a)
2020-04-15 22:23:44 +02:00
R. RyanTM
67e45efa3a nix-zsh-completions: 0.4.3 -> 0.4.4 (#85267)
(cherry picked from commit 7c21abdf4c)
2020-04-15 19:01:50 +02:00
Roberto Di Remigio
946287b319 mkl: 2020.0.166 -> 2020.1.217
(cherry picked from commit 488527eaa6)
2020-04-15 08:21:35 -04:00
Florian
e393449b43 airsonic: enable nginx.recommendedProxySettings with virtualHost
This fixes music playback when using the `services.airsonic.virtualHost`
option.

(cherry picked from commit 519d4f8e33)
2020-04-15 09:33:55 +02:00
Michael Weiss
07b3634cb4 Merge pull request #84713 from primeos/gn-backport
[20.03] gn: 20190403 -> 2020-03-09 (backport)
2020-04-14 22:07:14 +02:00
Michael Weiss
9a7d216703 chromiumDev: Override gn to fix the configuration phase
The configuration phase was failing due to:
```
configuring
ERROR at //BUILD.gn:1376:5: Unknown function.
    filter_exclude([ "$root_build_dir/foo" ],
    ^-------------
```

(cherry picked from commit ad3220f9ff)
2020-04-14 21:14:14 +02:00
Michael Weiss
72acf9cd34 aseprite.skia: Override the gn version to fix the build
With #83290 merged the build would fail during the configuration phase:
```
configuring
ERROR at //gn/BUILDCONFIG.gn:85:14: Script returned non-zero exit code.
  is_clang = exec_script("gn/is_clang.py",
             ^----------
Current dir: /build/source/out/Release/
Command: python /build/source/gn/gn/is_clang.py cc c++
Returned 2.
stderr:

python: can't open file '/build/source/gn/gn/is_clang.py': [Errno 2] No such file or directory
```

(cherry picked from commit ad66bbd98b)
2020-04-14 21:14:14 +02:00
Michael Weiss
4424442dc8 gn: 20190403 -> 2020-03-09
This updates gn to the required version for chromiumDev (the recommended
version for the stable release of Chromium isn't sufficient [0]).

[0]: The Chromium build fails during the configuration phase:
ERROR at //mojo/public/tools/bindings/mojom.gni:393:16: Undefined identifier
               "cpp_typemaps",
               ^-------------

(cherry picked from commit a1b4bfe34f)
2020-04-14 21:14:14 +02:00
Linus Heckemann
7f9c1d0ec3 nixos/libinput: refer to libinput manual
(cherry picked from commit 9953a26be1)
2020-04-14 09:43:27 -04:00
Sander van der Burg
6fd93c3389 nixos/dysnomia: fix documentRoot property
(cherry picked from commit 0ffb720e8c)
2020-04-14 14:44:47 +02:00
Sander van der Burg
8b40e8907b dysnomia: 0.9 -> 0.9.1
(cherry picked from commit dc13460a6c)
2020-04-14 14:44:47 +02:00
worldofpeace
7cf85ddf67 Merge pull request #84648 from cleverca22/fix-kafka-test
nixos: kafka test: fix building for other arches
2020-04-14 08:41:03 -04:00
Florian Klink
897182cdaf nixosTests.networking.virtual: fix with networkd
We only need to wait for network.target to get up, and the
network-addresses-${interfaceName} units are scripted networking only.

(cherry picked from commit a501abd5499d8f82f0991a7b78bcbc4169b0537f)
ZHF: #80379
Fix a failing test.
2020-04-14 14:35:06 +02:00
Dominik Honnef
3add50e56d luminance-hdr: use Qt5's mkDerivation
(cherry picked from commit b233a19fe1)
2020-04-14 08:33:10 -04:00
worldofpeace
e5ba0c5da5 Merge pull request #84431 from srhb/bp-ceph-14.2.8
[20.03] ceph 14.2.6 -> 14.2.8
2020-04-14 08:25:08 -04:00
Benjamin Hipple
89b864de64 ethminer: mark as broken
Doesn't build with gcc9, and if overlayed to use gcc8 stdenv fails on CUDA issues.

(cherry picked from commit 7f453f1822)
2020-04-14 08:16:23 -04:00
Lucas Savva
ecfd73db44 acme: share accounts between certificates
There are strict rate limits on account creation for Let's Encrypt
certificates. It is important to reuse credentails when possible.

(cherry picked from commit 827d5e6b44)
2020-04-14 13:13:40 +01:00
R. RyanTM
21750051b2 modemmanager: 1.12.6 -> 1.12.8
(cherry picked from commit b2fe03baf4)
2020-04-13 17:53:09 -04:00
R. RyanTM
8aa17dea0f modemmanager: 1.12.4 -> 1.12.6
(cherry picked from commit fe898d5f76)
2020-04-13 17:53:07 -04:00
Pavol Rusnak
22b5a32fad electron: fix wrapGAppsHook usage
(cherry picked from commit 96f52cb22b)
2020-04-13 17:43:46 -04:00
Pavol Rusnak
3ad8596931 Revert "riot-desktop: wrap with wrapGAppsHook"
This reverts commit fe6addbbf7.

(cherry picked from commit 3abd151f8e)
2020-04-13 17:43:45 -04:00
Linus Heckemann
9f0f06ac8b freeradius: make debug logging optional
(cherry picked from commit 0587329191)
2020-04-13 20:34:14 +02:00
Michael Weiss
ef7f4788c7 android-studio: Fix the license (unfree)
Android Studio states that it contains proprietary code!

(cherry picked from commit adcd8baa02)
2020-04-13 18:06:13 +02:00
Tim Steinbach
cb8b71c645 linux: 5.5.16 -> 5.5.17 2020-04-13 08:40:59 -04:00
Tim Steinbach
bab08a49df linux: 5.4.31 -> 5.4.32 2020-04-13 08:40:59 -04:00
Tim Steinbach
44537fa3f4 linux: 4.9.218 -> 4.9.219 2020-04-13 08:40:59 -04:00
Tim Steinbach
788dd86a62 linux: 4.19.114 -> 4.19.115 2020-04-13 08:40:59 -04:00
Tim Steinbach
585f651020 linux: 4.14.175 -> 4.14.176 2020-04-13 08:40:59 -04:00
Tim Steinbach
be8daae10c linux: 4.4.218 -> 4.4.219 2020-04-13 08:40:59 -04:00
Renato Alves
2fd2e031a3 mnemosyne: Install mnemosyne.desktop
(cherry picked from commit f5814e2075)
2020-04-13 14:00:22 +02:00
Renato Alves
7a0cb9c305 mnemosyne: Add pyopengl to silence OpenGL warning
(cherry picked from commit 4ea30958a8)
2020-04-13 14:00:22 +02:00
Renato Alves
ec099df093 mnemosyne: Fix 'Could not find Qt' segfault
(cherry picked from commit f6889aa21e)
2020-04-13 14:00:22 +02:00
Renato Alves
93e93f82e6 pythonPackages.gtts: init at 2.1.1
(cherry picked from commit 71113dbc69)
2020-04-13 14:00:22 +02:00
Renato Alves
c2d209265d pythonPackages.googletrans: init at 2.4.0
(cherry picked from commit e30abffb66)
2020-04-13 14:00:22 +02:00
Renato Alves
0182312e11 mnemosyne: add googletrans and gtts python dependencies
These python packages interface with Google Translate and their absence
causes mnemosyne to fail at launch.
2020-04-13 13:51:56 +02:00
Maximilian Bosch
96e35bf2a0 EmptyEpsilon: 2020.03.22 -> 2020.04.09
https://github.com/daid/EmptyEpsilon/releases/tag/EE-2020.04.09
(cherry picked from commit 0516977e49)
2020-04-13 12:23:19 +02:00
Maximilian Bosch
9325edaa1e linuxPackages.bpftrace: 0.9.3 -> 0.9.4
https://github.com/iovisor/bpftrace/releases/tag/v0.9.4
(cherry picked from commit 89d2967c9e)
2020-04-13 12:23:19 +02:00
Maximilian Bosch
56ff118499 packer: 1.5.4 -> 1.5.5
https://github.com/hashicorp/packer/releases/tag/v1.5.5
(cherry picked from commit 42ca8f54db)
2020-04-13 12:23:18 +02:00
Maximilian Bosch
26702dfb58 wdisplays: 2020-01-12 -> 2020-03-15
ba331ca...0faafdc
(cherry picked from commit 6b5186c2ca)
2020-04-13 12:23:18 +02:00
Vincent Laporte
1610b4ab21 coqPackages.dpdgraph: fix build with OCaml ≥ 4.08
(cherry picked from commit f2eeeb83f2)
2020-04-13 11:29:26 +02:00
John Ericson
708cb6b307 Merge pull request #85101 from Ericson2314/document-haskell-env-changes
nixos/doc: Document breaking change to Haskell dev shells for 20.03
2020-04-12 16:42:03 -04:00
worldofpeace
88661bfb64 Merge pull request #84846 from worldofpeace/backports-vscode-vscodium
vscode vscodium backports [20.03]
2020-04-12 15:15:10 -04:00
Andreas Rammhold
18cad55231 Merge pull request #84591 from andir/20.03/firefox
[20.03] firefox: 74.0.1 -> 75.0 and releated updates
2020-04-12 20:09:56 +02:00
worldofpeace
ea1c1ba19e Merge pull request #84971 from Emantor/fix/release_notes_i915
nixos/relrease-notes/rl-2003.xml: remove section on intel GPU workaround
2020-04-12 06:04:42 -04:00
Rouven Czerwinski
da764d22ce rl-2003: remove section on intel GPU workaround
According to my analysis the last critical fix went into v5.4.23, I have
confirmed this by running WebGL over night and haven't seen a single
i915 GPU hang. Lets remove the notes from the release notes.
2020-04-12 06:03:56 -04:00
Mario Rodas
ba1f98542d Merge pull request #84537 from JeffLabonte/20.03-brave_1.5.115_to_1.5.123
brave: 1.5.115 -> 1.5.123
2020-04-12 04:33:23 -05:00
Vladimír Čunát
21b3020b1a Merge #83022: simutrans: 120.2.2 -> 120.4.1 (unbreak)
(cherry picked from commit e7ca19f7cb)
2020-04-12 10:26:30 +02:00
Maximilian Bosch
b3f4b4dc3c feh: 3.3 -> 3.4
https://feh.finalrewind.org/archive/3.4/
(cherry picked from commit 2d836ab922)
2020-04-12 10:12:57 +02:00
Dmitry Kalinkin
d0982c0e0e herwig: 7.2.0 -> 7.2.1
thepeg: 2.2.0 -> 2.2.1

A minor bugfix

(cherry picked from commit 7cbffa0530)
2020-04-11 15:18:16 -04:00
R. RyanTM
1f4c855782 snakemake: 5.10.0 -> 5.13.0 (#83839)
(cherry picked from commit cff5adc2fb)
2020-04-11 14:40:48 -04:00
Dmitry Kalinkin
42f4fa6b0b snakemake: 5.9.1 -> 5.10.0
(cherry picked from commit 68db99ad97)
2020-04-11 14:40:43 -04:00
Dmitry Kalinkin
f070c90c01 pythonPackages.awkward1: use pytestCheckHook
(cherry picked from commit 5c72e84169)
2020-04-11 11:50:49 -04:00
Dmitry Kalinkin
8246657ddb pythonPackages.awkward1: 0.1.38 -> 0.2.12
(cherry picked from commit ab1c67eacd)
2020-04-11 11:50:43 -04:00
Michael Raskin
4528f9dbfb Merge pull request #84918 from woffs/backport-pingus-83706-20.03
[nixos-20.03] pingus: 0.7.6 -> unstable
2020-04-11 10:35:25 +00:00
Florian Klink
836e4b71c4 Merge pull request #84930 from flokli/rl-2003-highlights
nixos/release-notes/rl-2003.xml: add highlights
2020-04-11 12:11:22 +02:00
Maximilian Bosch
c218f19494 nixos/release-notes: fix minor spelling mistake in the Nextcloud section
As discovered by flokli.

(cherry picked from commit 9cddcac995)
2020-04-11 10:38:40 +02:00
Samuel Dionne-Riel
f3a3c969fe nextcloud: Review installation upgrade warning wording
The new wording does not assume the user is upgrading.

This is because a user could be setting up a new installation on 20.03
on a server that has a 19.09 or before stateVersion!!

The new wording ensures that confusion is reduced by stating that they
do not have to care about the assumed 16→17 transition.

Then, the wording explains that they should, and how to upgrade to
version 18.

It also reviews the confusing wording about "multiple" upgrades.

* * *

The only thing we cannot really do is stop a fresh install of 17 if
there was no previous install, as it cannot be detected. That makes a
useless upgrade forced for new users with old state versions.

It is also important to state that they must set their package to
Nextcloud 18, as future upgrades to Nextcloud will not allow an uprade
from 17!

I assume future warning messages will exist specifically stating what to
do to go from 18 to 19, then 19 to 20, etc...

(cherry picked from commit a1efbdb600)
2020-04-11 00:02:27 -04:00
worldofpeace
806ddfb696 Merge pull request #84950 from bhipple/bp/nose
[20.03] python3Packages.nose2: 0.9.1 -> 0.9.2 and fix build for ZHF
2020-04-10 22:53:51 -04:00
Niklas Hambüchen
fd7ac7e607 Merge pull request #84963 from nh2/issue-84391-nginx-as-root-changelog-20.03
[20.03] release notes: Explain how to run nginx master as root
2020-04-11 03:46:49 +02:00
Niklas Hambüchen
0e79744e20 release notes: Explain how to run nginx master as root. Fixes #84391
(cherry picked from commit ba50a7a3f1)
2020-04-11 03:34:24 +02:00
Mario Rodas
9099f30636 Merge pull request #84948 from nyanloutre/nginx_sso_backport_0_24_1
[20.03] nginx-sso: 0.24.0 -> 0.24.1
2020-04-10 19:09:11 -05:00
Benjamin Hipple
bb5bd4e831 python3Packages.nose2: 0.9.1 -> 0.9.2 and fix build for ZHF
See inline comment; this is currently broken and not going to continue working
on python2 without significant effort, so mark it python >= 3.6 only.

https://hydra.nixos.org/build/114680648
https://hydra.nixos.org/build/115518949

CC @NixOS/nixos-release-managers

ZHF: #80379
(cherry picked from commit f9bc195430)
2020-04-10 19:08:24 -04:00
nyanloutre
dc25644537 nginx-sso: 0.24.0 -> 0.24.1
(cherry picked from commit 0e087981ec)
2020-04-11 00:55:46 +02:00
worldofpeace
c26487314f nixos/gnome-remote-desktop: enable pipewire
We need the pipewire service to actually use this.
Tested with g-c-c Sharing.

(cherry picked from commit 94eb65a287)
2020-04-10 18:08:44 -04:00
worldofpeace
8d37cca45f pantheon.wingpanel-applications-menu: 2.5.0 -> 2.6.0
https://github.com/elementary/applications-menu/releases/tag/2.6.0
(cherry picked from commit dd805599a9)
2020-04-10 18:08:23 -04:00
worldofpeace
74ae69926e pantheon.switchboard-plug-security-privacy: 2.2.2 -> 2.2.3
* gtk toolbar to actionbar

https://github.com/elementary/switchboard-plug-security-privacy/releases/tag/2.2.3
(cherry picked from commit e7d592edb6)
2020-04-10 18:08:22 -04:00
worldofpeace
75a32d7434 pantheon.switchboard-plug-pantheon-shell: 2.8.2 -> 2.8.3
Don't need backgrounds patch anymore because of my patch upstream [0]

https://github.com/elementary/switchboard-plug-pantheon-shell/releases/tag/2.8.3

[0]: 541b1711fe

(cherry picked from commit 3c4cf5db81)
2020-04-10 18:08:22 -04:00
worldofpeace
e43ec384f7 pantheon.switchboard-plug-mouse-touchpad: 2.4.0 -> 2.4.1
https://github.com/elementary/switchboard-plug-mouse-touchpad/releases/tag/2.4.1
(cherry picked from commit cc1550c1ac)
2020-04-10 18:08:22 -04:00
worldofpeace
2507c5f0b4 pantheon.switchboard-plug-applications: 2.1.6 -> 2.1.7
https://github.com/elementary/switchboard-plug-applications/releases/tag/2.1.7
(cherry picked from commit c8a38c9ee1)
2020-04-10 18:08:22 -04:00
worldofpeace
44821b7121 pantheon.switchboard-plug-display: 2.2.0 -> 2.2.1
https://github.com/elementary/switchboard-plug-display/releases/tag/2.2.1
(cherry picked from commit a86f2a18ad)
2020-04-10 18:08:22 -04:00
worldofpeace
698d28006b pantheon.switchboard-plug-about: 2.6.1 -> 2.6.2
just translations

(cherry picked from commit 45e3470ae4)
2020-04-10 18:08:22 -04:00
worldofpeace
99e05f5a23 pantheon.wingpanel-indicators-bluetooth: 2.1.4 -> 2.1.5
(cherry picked from commit ac2f83c1ad)
2020-04-10 18:08:22 -04:00
worldofpeace
2165cd7a81 pantheon.elementary-capnet-assist: 2.2.4 -> 2.2.5
just translations

(cherry picked from commit 082d977eac)
2020-04-10 18:08:22 -04:00
worldofpeace
f64401aa1f pantheon.pantheon-agent-polkit: 1.0.0 -> 1.0.1
just translations

(cherry picked from commit b810ce57f7)
2020-04-10 18:08:22 -04:00
worldofpeace
86822f8ed8 pantheon.wingpanel: 2.3.0 -> 2.3.1 2020-04-10 18:08:22 -04:00
worldofpeace
9db8c33847 pantheon.elementary-photos: 2.6.5 -> 2.7.0
https://github.com/elementary/photos/releases/tag/2.7.0
(cherry picked from commit d484e6a9e9)
2020-04-10 18:08:22 -04:00
worldofpeace
da30881e58 pantheon.appcenter: 3.2.3 -> 3.2.4
https://github.com/elementary/appcenter/releases/tag/3.2.4
(cherry picked from commit 0ec78fe131)
2020-04-10 18:08:22 -04:00
Frank Doepper
e8ae534af7 pingus: move cmake to nativeBuildInputs
(cherry picked from commit de6a28d63a73f5d68187fafc5330f80d2857b86c)
2020-04-10 23:47:23 +02:00
Joshua Fern
f35b2f29d2 citra: 2019-10-05 -> 2020-03-21
Version bump, also fixes the common qt xcb plugin error

(cherry picked from commit 83616f1bc5)

This contains a fix for issue #65399.
2020-04-10 22:06:52 +02:00
worldofpeace
7c9f30befa rl-2003: qa touchups
Fixes https://github.com/NixOS/nixpkgs/issues/82777
2020-04-10 15:44:58 -04:00
Izorkin
59d50ed9db maxscale: make broken package
(cherry picked from commit 63d9ab069a)
2020-04-10 15:41:57 -04:00
Florian Klink
ec11fd2163 nixos/release-notes/rl-2003.xml: add highlights
Fixes #79180.
2020-04-10 21:14:37 +02:00
Eelco Dolstra
63c1baa3eb nix: Fix fallback paths
(cherry picked from commit aa084e2a24)
2020-04-10 21:14:14 +02:00
Eelco Dolstra
609878cafb nix: 2.3.3 -> 2.3.4
(cherry picked from commit cea352d276)
2020-04-10 21:14:09 +02:00
Eelco Dolstra
12b319cd86 nix-fallback-paths.nix: Fix x86_64-linux path
https://github.com/NixOS/nix/issues/3370
(cherry picked from commit 21a3b141c3)
2020-04-10 21:14:06 +02:00
Eelco Dolstra
d676b04132 nix: 2.3.2 -> 2.3.3
(cherry picked from commit 3c47f78e82)
2020-04-10 21:11:19 +02:00
worldofpeace
66d8a2bda5 Merge pull request #84811 from Emantor/bump/20.03/xorg_server
[20.03] xorg.xorgserver: 1.20.7 -> 1.20.8
2020-04-10 14:36:12 -04:00
Michael Raskin
a63370143f pingus: 0.7.6 -> unstable; fixes build conflicts with dependency updates
(cherry picked from commit 35a2f790f6)
2020-04-10 19:13:45 +02:00
worldofpeace
ab018f754b Merge pull request #84221 from erictapen/dhcpcd-error-on-bridges
[20.03] nixos/network-interfaces: Assert that bridges can get an address via DHCP
2020-04-10 12:49:44 -04:00
Benjamin Hipple
f19157dfa0 Merge pull request #84840 from helsinki-systems/backport/20.03/unit
[20.03] unit: 1.14.0 -> 1.16.0
2020-04-10 12:40:39 -04:00
Justin Humm
54ad186461 nixos/network-interfaces: assertion for DHCP on bridges
Assert that the user doesn't have a bridge configured while
networking.useDHCP is true. Due to new behaviour of dhcpcd [0], this
would result in the bridge not getting an address via DHCP, regardless
of wether it has networking.interfaces.<name?>.useDHCP set or not.

[0] https://roy.marples.name/archives/dhcpcd-discuss/0002621.html
2020-04-10 17:28:22 +02:00
worldofpeace
c2d5fe8586 Merge pull request #84891 from schmittlauch/cawbird1.0.5-backport
[backport] cawbird: 1.0.4 -> 1.0.5
2020-04-10 11:06:07 -04:00
Joachim F
f372211402 Merge pull request #84893 from andriokha/tor-browser-bundle-bin-9.0.9-release-20.03
[20.03] tor-browser-bundle-bin: 9.0.7 -> 9.0.9
2020-04-10 14:56:53 +00:00
Frederik Rietdijk
a1119e2239 Merge release-20.03 into staging-20.03 2020-04-10 12:09:49 +02:00
Andy Fowlston
c713b1b49f tor-browser-bundle-bin: 9.0.7 -> 9.0.9
https://blog.torproject.org/new-release-tor-browser-909
https://blog.torproject.org/new-release-tor-browser-908
(cherry picked from commit 85e4f2d554)
2020-04-10 10:29:26 +01:00
ajs124
1e925e1545 performous: fix build (#84841)
(cherry picked from commit 87f75f8e35)

Co-authored-by: Orivej Desh <orivej@gmx.fr>
2020-04-10 01:33:51 +00:00
worldofpeace
d3d904c2f1 Merge pull request #84707 from zowoq/gh-backport
[20.03] gitAndTools.gh: 0.5.3 -> 0.6.4
2020-04-09 20:57:09 -04:00
worldofpeace
9e50a36859 Merge pull request #84863 from worldofpeace/backport-83551
[20.03] iso-image: normalize volumeID
2020-04-09 20:51:45 -04:00
worldofpeace
17d67c00c9 iso-image: make $ARCH shorter
we use stdenv.hostPlatform.uname.processor, which I believe is just like
`uname -p`.

Example values:
```
(import <nixpkgs> { system = "x86_64-linux"; }).stdenv.hostPlatform.uname.processor
"x86_64"

(import <nixpkgs> { system = "aarch64-linux"; }).stdenv.hostPlatform.uname.processor
aarch64

(import <nixpkgs> { system = "armv7l-linux"; }).stdenv.hostPlatform.uname.processor
"armv7l"
```

(cherry picked from commit df8c30fa25)
2020-04-09 20:26:57 -04:00
worldofpeace
0a634109d4 iso-image: make sure volumeID is less than 32 chars
(cherry picked from commit 591e8d5708)
2020-04-09 19:36:09 -04:00
worldofpeace
519ace8441 iso-image: normalize volumeID
The volumeID will now be in the format of:
nixos-$EDITON-$RELEASE-$ARCH

an example for the minimal image would look like:
nixos-minimal-20.09-x86-64-linux

(cherry picked from commit 70a8e9ace9)
2020-04-09 19:36:09 -04:00
worldofpeace
84b906d5c4 make-iso9660-image.sh: enable joliet extension
This is per the advice of the osinfo-db maintainers https://gitlab.com/libosinfo/osinfo-db/-/merge_requests/107#note_313094852

(cherry picked from commit f59aa66fc1)
2020-04-09 19:36:09 -04:00
Maximilian Bosch
a74e7092b0 gitAndTools.tig: 2.5.0 -> 2.5.1
https://github.com/jonas/tig/releases/tag/tig-2.5.1
(cherry picked from commit a3eaf6c88b)
2020-04-09 22:29:19 +02:00
Maximilian Bosch
5f33f338ce thermald: also install thermal-conf.xml into $out
Otherwise you get errors like this when running `thermald.service` from
the `services.thermald` module:

```
[WARN]22 CPUID levels; family:model:stepping 0x6:8e:a (6:142:10)
[WARN]Polling mode is enabled: 4
[WARN]sensor id 10 : No temp sysfs for reading raw temp
I/O warning : failed to load external entity "/nix/store/7d7cfc1949g7n7ywx47a0dsfz3b3rix5-thermald-1.9.1/etc/thermald/thermal-conf.xml"
[WARN]error: could not parse file /nix/store/7d7cfc1949g7n7ywx47a0dsfz3b3rix5-thermald-1.9.1/etc/thermald/thermal-conf.xml
[WARN]sysfs open failed
I/O warning : failed to load external entity "/nix/store/7d7cfc1949g7n7ywx47a0dsfz3b3rix5-thermald-1.9.1/etc/thermald/thermal-conf.xml"
[WARN]error: could not parse file /nix/store/7d7cfc1949g7n7ywx47a0dsfz3b3rix5-thermald-1.9.1/etc/thermald/thermal-conf.xml
I/O warning : failed to load external entity "/nix/store/7d7cfc1949g7n7ywx47a0dsfz3b3rix5-thermald-1.9.1/etc/thermald/thermal-conf.xml"
[WARN]error: could not parse file /nix/store/7d7cfc1949g7n7ywx47a0dsfz3b3rix5-thermald-1.9.1/etc/thermald/thermal-conf.xml
```

(cherry picked from commit 9fc8856b25)
2020-04-09 22:29:18 +02:00
Patrick Hilhorst
69f1529084 vscode, vscodium: 1.43.2 -> 1.44.0
(cherry picked from commit 939041bce4)
2020-04-09 16:26:06 -04:00
Edmund Wu
763a3b46ec vscodium: 1.43.0 -> 1.43.2
(cherry picked from commit 3f75bc2660)
2020-04-09 16:26:05 -04:00
Edmund Wu
829f656072 vscode: 1.43.0 -> 1.43.2
(cherry picked from commit a05f67ea0a)
2020-04-09 16:26:05 -04:00
worldofpeace
13d0920dad vscodium: add backports notice
(cherry picked from commit f9fc1d3be4)
2020-04-09 16:26:05 -04:00
worldofpeace
de5269a3ff vscode: add backports notice
(cherry picked from commit c9fd76de75)
2020-04-09 16:26:04 -04:00
Domen Kožar
d6209e540c vscode: fix build on darwin
(cherry picked from commit be80721e74)
2020-04-09 16:26:04 -04:00
Patrick Hilhorst
5c8fd2d9e1 vscode, vscodium: 1.42.1 -> 1.43.0
(cherry picked from commit 9be58002ed)
2020-04-09 16:26:04 -04:00
Domen Kožar
35b1992f6d vscode: specify runtimeDependencies instead of LD_LIBRARY_PATH
This avoids glibc verions mismatches in vscode terminal, as
LD_LIBRARY_PATH leaks into terminal and break with user installed
executables.

(cherry picked from commit 40d7ce7828)
2020-04-09 16:26:04 -04:00
Patrick Hilhorst
95ca22a418 vscode, vscodium: 1.42.0 -> 1.42.1
(cherry picked from commit 91a106d4b4)
2020-04-09 16:26:03 -04:00
Patrick Hilhorst
7514605998 vscodium: 1.41.1 -> 1.42.0
(cherry picked from commit 603109c171)
2020-04-09 16:26:03 -04:00
Izorkin
56eb406631 unit: 1.15.0 -> 1.16.0
(cherry picked from commit 5dbe01af5b)
2020-04-09 20:47:09 +02:00
R. RyanTM
4efd728157 unit: 1.14.0 -> 1.15.0
(cherry picked from commit 3815de80c0)
2020-04-09 20:46:23 +02:00
Mario Rodas
5f6ba36fd2 Merge #82267: sane-airscan: init at 0.9.17
(cherry picked from commit ab1a184de3)
2020-04-09 18:08:41 +02:00
Vladimír Čunát
842167291c Merge #84773: thunderbird*: 68.6.0 -> 68.7.0
https://www.thunderbird.net/en-US/thunderbird/68.7.0/releasenotes/
(ATM it's unclear if there are any security fixes or not.)

(cherry picked from commit f719350bac)
Re-tested both on 20.03.
2020-04-09 18:08:33 +02:00
Matthew Bauer
5ad2b732e9 kwallet-pam: unset QT_PLUGIN_PATH
kwallet sets a limit of 1000 for a single characters for environment
variables read from the socket[1]. wrapQtApps gives us a huge value
for QT_PLUGIN_PATH (up to 13000 bytes on my system!) Since this was
overflowing, the Qt plugin loading mechanism was hitting a segfault
when it was trying to parse the truncated QT_PLUGIN_PATH.

So for now, we can just unset QT_PLUGIN_PATH in the pam_kwallet_init
script. kwalletd5 has its own QT_PLUGIN_PATH which it can use.

This problem occured on 20.03, but not 19.09. It’s unclear what
changes were made in that time, but likely that previously we weren’t
getting a QT_PLUGIN_PATH set in the plasma5 startup at all. This means
that in 19.09 our QT_PLUGIN_PATH value must have been small enough to
fit into the 1000 char limit.

Fixes #77290

[1]: bc9713e272/src/runtime/kwalletd/main.cpp (L44)

/cc @ttuegel

(cherry picked from commit f0db4de598)
2020-04-09 10:50:03 -04:00
Rouven Czerwinski
aa4ec3bb37 xorg.xorgserver: 1.20.7 -> 1.20.8
https://lists.x.org/archives/xorg-announce/2020-March/003041.html

This release contains a fix for XWayland which removes a buffer swap
race between XWayland and the compositor. This resulted in flickering in
previous versions.
2020-04-09 15:24:09 +02:00
Shea Levy
253f8a76fa emacsPackages: Add standalone agda-input package that doesn't require building Agda.
(cherry picked from commit 6fac063e09)
2020-04-09 09:14:55 -04:00
Aaron Andersen
0ef4da1ea1 Merge pull request #84293 from aanderse/httpd-20.03
apacheHttpd: 2.4.41 -> 2.4.43 [20.03]
2020-04-09 08:42:51 -04:00
Maximilian Bosch
c25e25f46f hydra: 2020-03-24 -> 2020-04-07
Also removed `pkgs.hydra-flakes` since flake-support has been merged
into master[1]. Because of that, `pkgs.hydra-unstable` is now compiled
against `pkgs.nixFlakes` and currently requires a patch since Hydra's
master doesn't compile[2] atm.

[1] https://github.com/NixOS/hydra/pull/730
[2] https://github.com/NixOS/hydra/pull/732

(cherry picked from commit 0f5c38feed)
2020-04-09 12:35:51 +02:00
Jörg Thalheim
377b0248c5 acme: create certificates in subdirectory
This allows to have multiple certificates with the same common name.
Lego uses in its internal directory the common name to name the certificate.

fixes #84409

(cherry picked from commit d7ff6ab94a)
2020-04-09 11:06:10 +01:00
Domen Kožar
8c6a5a26a7 Merge pull request #84789 from bennofs/backport-ghc-llvm-aarch64
[20.03] haskell.compiler.ghc822Binary: propagate llvm dependency
2020-04-09 11:40:47 +02:00
Andrew Childs
48a0195416 haskell.compiler.ghc822Binary: propagate llvm dependency
Fixes the following error when attempting to build packages using this
compiler:

  <no location info>: error:
      Warning: Couldn't figure out LLVM version!
               Make sure you have installed LLVM 3.9

  <no location info>: error: ghc: could not execute: opt

(cherry picked from commit 31f557c88f)
2020-04-09 11:01:15 +02:00
Bernardo Meurer
f56a3e1aac linuxPackages.nvidia_x11: 440.64 -> 440.82
(cherry picked from commit 73ff54e7b9)
cc #84680
2020-04-09 00:18:56 -04:00
Mike Sperber
5ac5f503b2 bazel_0_26: fix linker flags for darwin (#84614)
Same as done for bazel_0_29 in d1ee615f1c:

(cherry picked from commit 677b2d818e)
2020-04-08 18:56:57 -04:00
worldofpeace
84aa023cf4 Merge pull request #82295 from erictapen/dhcpcd-release-notes
nixos/release-notes: mention that dhcpcd stopped giving IPv4 addresses to bridges
2020-04-08 17:44:53 -04:00
Trolli Schmittlauch
6d4959314c cawbird: 1.0.4 -> 1.0.5
(cherry picked from commit 6be41c6df8)
2020-04-08 21:22:19 +02:00
Jörg Thalheim
4ca13721d9 vocal: add missing glib-networking
otherwise https is disabled

(cherry picked from commit b9b8388e4a)
2020-04-08 13:24:27 -04:00
Michael Fellinger
f16ed9f715 set GEM_HOME via Gem.paths
(cherry picked from commit b285fa07d5)
2020-04-08 12:57:28 -04:00
Michael Fellinger
97f1e86387 update versions in Gemfile.lock
(cherry picked from commit f92600b406)
2020-04-08 12:57:26 -04:00
Michael Fellinger
c6758ee13d bundler: 1.17.3 -> 2.1.4
(cherry picked from commit a2e73b062a)
2020-04-08 12:47:42 -04:00
Jörg Thalheim
78e69d9306 linuxPackages.acpi-call: switch to nix-community fork
This fixes also build against linux 5.6
We also took the opportunity to cleanup the build.

(cherry picked from commit 1ae03c9db1)
2020-04-08 15:35:21 +01:00
Graham Christensen
99cbf968fd Merge pull request #84717 from bennofs/backport-test-hibernate-x86_64
nixos/release-combined.nix: test hibernate only on x86_64
2020-04-08 09:40:59 -04:00
Tim Steinbach
c1af4f35b7 linux: 5.5.15 -> 5.5.16 2020-04-08 08:52:43 -04:00
Tim Steinbach
2d68afdaab linux: 5.4.30 -> 5.4.31 2020-04-08 08:52:43 -04:00
Benno Fünfstück
6193a9e242 nixos/release-combined.nix: test hibernate only on x86_64
(cherry picked from commit 918cb88d1f)
2020-04-08 14:52:19 +02:00
Michael Weiss
224a5e5b05 chromiumDev: Add the missing setuptools dependency
The build was failing with:
```
[1625/39505] ACTION //components/schema_org:generate_schema_org_code(//build/toolchain/linux:clang_x64)
FAILED: gen/components/schema_org/schema_org_entity_names.h gen/components/schema_org/schema_org_entity_names.cc gen/components/schema_org/schema_org_property_configurations.h gen/components/schema_org/schema_org_property_configurations.cc gen/components/schema_org/schema_org_property_names.h gen/components/schema_org/schema_org_property_names.cc
python ../../components/schema_org/generate_schema_org_code.py --schema-file ../../third_party/schema_org/schema.jsonld --output-dir gen/components/schema_org --templates templates/schema_org_entity_names.cc.tmpl templates/schema_org_entity_names.h.tmpl templates/schema_org_property_configurations.cc.tmpl templates/schema_org_property_configurations.h.tmpl templates/schema_org_property_names.cc.tmpl templates/schema_org_property_names.h.tmpl
Traceback (most recent call last):
  File "../../components/schema_org/generate_schema_org_code.py", line 22, in <module>
    env = Environment(loader=PackageLoader('generate_schema_org_code', ''))
  File "/build/chromium-83.0.4100.3/components/schema_org/../../third_party/jinja2/loaders.py", line 222, in __init__
    from pkg_resources import DefaultProvider, ResourceManager, \
ImportError: No module named pkg_resources
```

(cherry picked from commit d782c440ae)
2020-04-08 13:50:12 +02:00
Michael Weiss
3cfa78fe30 chromiumDev: Fix the build
Building Chromium 82 requires LLVM 10 for the new argument
"-fintegrated-cc1". LLVM 9 fails with:
clang++: error: unknown argument: '-fintegrated-cc1'

(cherry picked from commit 1d961a4c6d)
2020-04-08 13:47:31 +02:00
Michael Weiss
a62dac34e6 chromium: 80.0.3987.163 -> 81.0.4044.92
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html

This update includes 32 security fixes.

CVEs:
CVE-2020-6454 CVE-2020-6423 CVE-2020-6455 CVE-2020-6430 CVE-2020-6456
CVE-2020-6431 CVE-2020-6432 CVE-2020-6433 CVE-2020-6434 CVE-2020-6435
CVE-2020-6436 CVE-2020-6437 CVE-2020-6438 CVE-2020-6439 CVE-2020-6440
CVE-2020-6441 CVE-2020-6442 CVE-2020-6443 CVE-2020-6444 CVE-2020-6445
CVE-2020-6446 CVE-2020-6447 CVE-2020-6448

(cherry picked from commit da832dd7d4)
Backport of #84671.
2020-04-08 13:36:38 +02:00
Michael Weiss
85e8548a1f chromiumBeta: Fix the build
This patch was also backported to M81 [0][1].

[0]: https://chromium-review.googlesource.com/c/chromium/src/+/2091896
[1]: bbf0fad592

(cherry picked from commit ff3bc51d2b)
2020-04-08 13:36:38 +02:00
Michael Weiss
df50124d63 chromium: Ignore unknown warning options
This can e.g. save around 150k lines of unnecessary log messages which
take up around 66% of the total lines (based on a log of 80.0.3987.100):
29527 warning: unknown warning option '-Wno-bitwise-conditional-parentheses'; did you mean '-Wno-bitwise-op-parentheses'? [-Wunknown-warning-option]
29527 warning: unknown warning option '-Wno-builtin-assume-aligned-alignment' [-Wunknown-warning-option]
29527 warning: unknown warning option '-Wno-deprecated-copy'; did you mean '-Wno-deprecated'? [-Wunknown-warning-option]
29527 warning: unknown warning option '-Wno-final-dtor-non-final-class'; did you mean '-Wno-abstract-final-class'? [-Wunknown-warning-option]
29527 warning: unknown warning option '-Wno-implicit-int-float-conversion'; did you mean '-Wno-implicit-float-conversion'? [-Wunknown-warning-option]

(cherry picked from commit 9f3914824d)
2020-04-08 13:36:37 +02:00
Michael Weiss
468fa8738f Merge pull request #84705 from primeos/signal-desktop-backport
[20.03] signal-desktop: 1.32.3 -> 1.33.0 (backport)
2020-04-08 13:08:19 +02:00
zowoq
fbd0974dff gitAndTools.gh: 0.6.3 -> 0.6.4
https://github.com/cli/cli/releases/tag/v0.6.4
(cherry picked from commit 26a6d89cab)
2020-04-08 19:46:36 +10:00
zowoq
cf7513bc27 gitAndTools.gh: 0.6.2 -> 0.6.3
https://github.com/cli/cli/releases/tag/v0.6.3
(cherry picked from commit 68a50aaaa5)
2020-04-08 19:46:27 +10:00
zowoq
f7b3dfc9d8 gitAndTools.gh: 0.6.1 -> 0.6.2
https://github.com/cli/cli/releases/tag/v0.6.2
(cherry picked from commit 20f197d0b9)
2020-04-08 19:46:18 +10:00
zowoq
ba71d71c13 gitAndTools.gh 0.6.0 -> 0.6.1
https://github.com/cli/cli/releases/tag/v0.6.1
(cherry picked from commit 4656fba5ab)
2020-04-08 19:46:09 +10:00
zowoq
86a179a74b gitAndTools.gh: 0.5.7 -> 0.6.0
https://github.com/cli/cli/releases/tag/v0.6.0
(cherry picked from commit 85a8d13017)
2020-04-08 19:46:01 +10:00
zowoq
085b7360d5 gitAndTools.gh: 0.5.6 -> 0.5.7
https://github.com/cli/cli/releases/tag/v0.5.7
(cherry picked from commit 3338225cd2)
2020-04-08 19:45:51 +10:00
zowoq
1d6ad14c73 gitAndTools.gh: 0.5.5 -> 0.5.6
https://github.com/cli/cli/releases/tag/v0.5.6
(cherry picked from commit 185aabefb0)
2020-04-08 19:45:42 +10:00
zowoq
ca75c088e9 gitAndTools.gh: 0.5.4 -> 0.5.5
https://github.com/cli/cli/releases/tag/v0.5.5
(cherry picked from commit 66f50128dc)
2020-04-08 19:45:33 +10:00
R. RyanTM
1e8fc3dd4d gitAndTools.gh: 0.5.3 -> 0.5.4
(cherry picked from commit 7b61246b95)
2020-04-08 19:45:14 +10:00
Michael Weiss
ef5b4301fc signal-desktop: 1.32.3 -> 1.33.0
(cherry picked from commit fdedc5d16c)
2020-04-08 11:38:10 +02:00
Vincent Laporte
d41fe83633 alt-ergo: 2.3.1 → 2.3.2
(cherry picked from commit f4ff33cce6)
2020-04-08 10:28:59 +02:00
Dennis Gosnell
0b1657a278 Merge pull request #84571 from woffs/unbreak-amqp-utils-20.03a
[nixos-20.03] haskellPackages.amqp-utils: fix amqp-0.19 dependency
2020-04-08 10:39:47 +09:00
Dennis Gosnell
540d6716cc Merge pull request #84645 from rnhmjoj/pandoc-crossref-20.03
[20.03] haskellPackages.pandoc-crossref: downgrade to latest working
2020-04-08 09:40:12 +09:00
Michael Bishop
6be1626da5 nixos: kafka test: fix building for other arches
(cherry picked from commit 8b7e843dab)
2020-04-07 15:44:32 -03:00
Benjamin Hipple
d63f95896c Merge pull request #84623 from bhipple/bp/tmux-plugins
[20.03] tmuxPlugins: upgrade all to latest
2020-04-07 14:21:30 -04:00
worldofpeace
a5a30e85c9 Merge branch 'release-20.03' into staging-20.03 2020-04-07 13:25:36 -04:00
worldofpeace
29b6ad6278 Merge branch 'staging-20.03' into release-20.03 2020-04-07 13:24:24 -04:00
Benjamin Hipple
5b34063594 tmuxPlugins: upgrade all to latest
Many of the tmux plugins had not been updated in some time. This PR:

- Updates all of them to the latest version. This is notable because `tmux 3.0`
  has come out recently, and some of them have compatibility fixes for the new
  version (e.g., `vim-tmux-navigator`), as well as general performance
  improvements and bugfixes for many of them.

- Uses `fetchFromGitHub`, which is both more performant and hashed mirror friendly.

- Adds the standard `version = "unstable-YYYY-MM-DD"`, which makes it easy to
  determine at a glance how old/unmaintained some of these are.

- Adds the standard `pname` for overlay friendliness

(cherry picked from commit d5ccc59056)
2020-04-07 12:06:17 -04:00
rnhmjoj
c5a806cfc0 haskellPackages.pandoc-crossref: downgrade to latest working 2020-04-07 17:39:13 +02:00
Andreas Rammhold
5e9ae03746 firefox-devedition-bin: 75.0b12 -> 76.0b1
(cherry picked from commit 79fb58973f)
2020-04-07 13:47:47 +02:00
Andreas Rammhold
f545f8ec14 firefox-beta-bin: 75.0b11 -> 76.0b1
(cherry picked from commit 9d6a7fdaad)
2020-04-07 13:47:47 +02:00
Andreas Rammhold
9b3e192bcb firefox-bin: 74.0.1 -> 75.0
(cherry picked from commit bab82e78b2)
2020-04-07 13:47:47 +02:00
Andreas Rammhold
fb97dfdcfa firefox-esr-68: 68.6.1esr -> 68.7.0esr
(cherry picked from commit f56ea6cdd7)
2020-04-07 13:47:47 +02:00
Andreas Rammhold
37e814ba75 firefox: 74.0.1 -> 75.0
(cherry picked from commit 4a41fd7a1e)
2020-04-07 13:47:47 +02:00
Andreas Rammhold
8aa6834525 firefox: prepare for version 75
(cherry picked from commit 9de3c9749c)
2020-04-07 13:47:46 +02:00
Andreas Rammhold
612a2978de libvpx_1_8: init at 1.8.2
Adding this as a new attribute as software is likely going to break when
we switch the default from the 1.7 branch to 1.8.

(cherry picked from commit 1859b5a5ae)
2020-04-07 13:47:45 +02:00
Maximilian Bosch
4291ef9bb6 prometheus-wireguard-exporter: 3.2.4 -> 3.3.0
https://github.com/MindFlavor/prometheus_wireguard_exporter/releases/tag/3.3.0
(cherry picked from commit e2b327cd4e)
2020-04-07 13:35:04 +02:00
Maximilian Bosch
3c700b8aa6 cargo-make: 0.30.2 -> 0.30.4
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.3
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.4
(cherry picked from commit 564af64783)
2020-04-07 13:35:04 +02:00
Frank Doepper
6570f2aec5 haskellPackages.amqp-utils: fix amqp-0.19 dependency 2020-04-07 10:14:11 +02:00
Jeff Labonte
f7522984c4 brave: 1.5.115 -> 1.5.123
Updated the checksum and the version of the brave package.

(cherry picked from commit 7a80ead781153ff40ab35ca02aef9d732e74f7e6)
Reason: The browser must be kept up-to-date
2020-04-06 22:30:31 -04:00
worldofpeace
29eddfc36d Merge pull request #80848 from worldofpeace/20.03-release-notes
rl-2003: mention python driver
2020-04-06 20:31:14 -04:00
worldofpeace
a435d41af5 rl-2003: mention python driver 2020-04-06 20:07:11 -04:00
Bernardo Meurer
8b8b278a8a linuxPackages.nvidia_x11: 440.59 -> 440.64
(cherry picked from commit 408de509cc)
cc #84163
2020-04-06 19:06:18 -04:00
Silvan Mosberger
2216211144 nixos/lib/test-driver: Fix require_unit_state hardcoded formatting
(cherry picked from commit 85e866db6f)
2020-04-07 00:58:50 +02:00
Florian Klink
0abc66e252 Merge pull request #84497 from toonn/release-20.03
[20.03] wire-desktop: mac 3.15.3621 -> 3.16.3630
2020-04-06 22:13:12 +02:00
toonn
4cedeb7475 wire-desktop: mac 3.15.3621 -> 3.16.3630
(cherry picked from commit 39c5e1c723)
2020-04-06 19:01:20 +02:00
Daiderd Jordan
10f80999df Merge pull request #84334 from LnL7/darwin-itstool
itstool: fix double-shebang backport
2020-04-06 18:42:53 +02:00
Daiderd Jordan
ef0537b9cd Merge pull request #84332 from LnL7/darwin-backports
darwin 20.03 backports
2020-04-06 18:41:53 +02:00
Elis Hirwing
84926c9480 php72: 7.2.28 -> 7.2.29
Changelog: https://www.php.net/ChangeLog-7.php#7.2.29
(cherry picked from commit 8272ebe961)
2020-04-06 17:58:23 +02:00
Elis Hirwing
185b684425 php73: 7.3.15 -> 7.3.16
Changelog: https://www.php.net/ChangeLog-7.php#7.3.16
(cherry picked from commit 1118080dc0)
2020-04-06 17:58:04 +02:00
Elis Hirwing
865abba6e9 php74: 7.4.3 -> 7.4.4
Changelog: https://www.php.net/ChangeLog-7.php#7.4.4
(cherry picked from commit faf79b6384)
2020-04-06 17:57:36 +02:00
Jörg Thalheim
5d1de8ca0f Merge pull request #84483 from bcdarwin/backport-fix-sedlex-inputs
ocamlPackages.sedlex: fix dependencies
2020-04-06 16:48:47 +01:00
Ben Darwin
81ae9cbefe ocamlPackages.sedlex: fix dependencies
(cherry picked from commit 77901a96da)
2020-04-06 11:09:33 -04:00
worldofpeace
649b8e1f0f Merge pull request #82886 from bennofs/fix-nixos-aarch64-eval
Fix evaluation of release-20.03-aarch64 jobset
2020-04-06 10:48:31 -04:00
Artem Khramov
10d60f7fae rockbox-utility: add wrapQtAppsHook
It seems like all QT apps which use dynamic plugins should be wrapped
with `wrapQtAppsHook`. However, rockbox-utility is still not wrapped,
therefore fails to launch.

This change adds `qt5.wrapQtAppsHook` to nativeBuildInputs of
rockbox-utility.

(cherry picked from commit 861df8abd5)
2020-04-06 12:21:04 +01:00
Eelco Dolstra
b4e14e9254 nix: 2.4pre7250_94c93437 -> 2.4pre7346_5e7ccdc9, 2.4pre20200220_4a4521f -> 2.4pre20200403_3473b19
(cherry picked from commit b23f697b00)
2020-04-06 12:51:08 +02:00
Eelco Dolstra
13cbfa88db Remove Nix 1.x
(cherry picked from commit 5d583db5a2)
2020-04-06 12:51:04 +02:00
Edward Amsden
0dda3d53a5 nix: Drive-by cleanup: replace ifthenelse with lib.optionalString
(cherry picked from commit 3b72c55fc5)
2020-04-06 12:50:59 +02:00
Edward Amsden
93c13ab1f0 nix: Patch config.nix.in to reference host platform binaries
(cherry picked from commit f1415f633c)
2020-04-06 12:50:33 +02:00
worldofpeace
a128dd3af8 riot-desktop: wrap with wrapGAppsHook
wrap as per https://nixos.org/nixpkgs/manual/#sec-language-gnome.

(cherry picked from commit fe6addbbf7)
2020-04-06 03:51:56 -04:00
worldofpeace
57ecbc5c61 Revert "riot-desktop: add gsettings schemas to the wrapper"
This reverts commit 1af6a1a134.

(cherry picked from commit 204d7bc28b)
2020-04-06 03:51:56 -04:00
Vincent Laporte
9fa7ee47b7 coq_8_11: 8.11.0 → 8.11.1
(cherry picked from commit d6a8d0ca5b)
2020-04-06 08:00:13 +02:00
Sarah Brofeldt
637325d63f nixos/tests/ceph: Fix pg number to power of 2
(cherry picked from commit 6ccd347e46)
2020-04-06 07:49:37 +02:00
Sarah Brofeldt
74ee45c435 ceph: 14.2.7 -> 14.2.8
(cherry picked from commit ec21f70c4b)
2020-04-06 07:49:35 +02:00
Sarah Brofeldt
ee47f5285f ceph: 14.2.6 -> 14.2.7
(cherry picked from commit 41547d11ec)
2020-04-06 07:49:28 +02:00
worldofpeace
4c2401ae4d pantheon.wingpanel-indicator-notifications: remove wnck
Don't need it 8ba4666015

(cherry picked from commit ce867da997)
2020-04-06 01:36:14 -04:00
worldofpeace
7ff1a0d9f1 Merge pull request #84418 from worldofpeace/pantheon-update-04-03-20.03
[20.03] Pantheon update 2020-04-03
2020-04-06 00:03:03 -04:00
worldofpeace
133f76fff0 pantheon.gala: 3.2.0 -> 3.3.0
https://github.com/elementary/gala/releases/tag/3.3.0
2020-04-05 22:28:15 -04:00
worldofpeace
11aea6c3c6 pantheon.elementary-greeter: 5.0.2 -> 5.0.3
https://github.com/elementary/greeter/releases/tag/5.0.3
2020-04-05 22:28:15 -04:00
worldofpeace
d723711d63 pantheon.wingpanel: 2.2.6 -> 2.3.0
https://github.com/elementary/wingpanel/releases/tag/2.3.0
2020-04-05 22:28:14 -04:00
worldofpeace
883e15f223 pantheon.xml: drop slow shutdown workaround
Them removing cerbere and registering with the SessionManager
should make shutdown very fast. This was even done in plank [0]
which was the last factor outside cerbere causing this.

[0]]: a8d2f255b2
2020-04-05 22:28:14 -04:00
worldofpeace
2c4c025107 pantheon.elementary-dock: init at 2020-02-28
It seems Pantheon has forked Plank.
2020-04-05 22:28:14 -04:00
worldofpeace
5e12c6403d pantheon.cerbere: remove 2020-04-05 22:27:52 -04:00
worldofpeace
90a3d62260 pantheon.wingpanel-indicator-sound: 2.1.4 -> 2.1.5 2020-04-05 22:27:34 -04:00
worldofpeace
cf1f59cf2f pantheon.wingpanel-indicator-session: 2.2.7 -> 2.2.8 2020-04-05 22:27:34 -04:00
worldofpeace
6319579a07 pantheon.wingpanel-indicator-power: 2.1.4 -> 2.1.5 2020-04-05 22:27:34 -04:00
worldofpeace
5ddd566191 pantheon.wingpanel-indicator-notifications: 2.1.3 -> 2.1.4 2020-04-05 22:27:34 -04:00
worldofpeace
32175d2a87 pantheon.wingpanel-indicator-network: 2.2.2 -> 2.2.3 2020-04-05 22:27:33 -04:00
worldofpeace
6123950811 pantheon.wingpanel-indicator-keyboard: 2.2.0 -> 2.2.1 2020-04-05 22:27:33 -04:00
worldofpeace
6350caf275 pantheon.wingpanel-indicator-datetime: 2.2.1 -> 2.2.2 2020-04-05 22:27:33 -04:00
worldofpeace
ce8bce8352 pantheon.elementary-shortcut-overlay: 1.1.0 -> 1.1.1 2020-04-05 22:27:33 -04:00
worldofpeace
a569a23a40 pantheon.elementary-onboarding: 1.1.0 -> 1.2.0 2020-04-05 22:27:33 -04:00
worldofpeace
1e219069be pantheon.switchboard-plug-sound: 2.2.2 -> 2.2.3 2020-04-05 22:27:32 -04:00
worldofpeace
eaa6002188 pantheon.switchboard-plug-sharing: 2.1.3 -> 2.1.4 2020-04-05 22:27:32 -04:00
worldofpeace
1dda5cab01 pantheon.switchboard-plug-printers: 2.1.7 -> 2.1.8 2020-04-05 22:27:32 -04:00
worldofpeace
4576a78233 pantheon.switchboard-plug-power: 2.4.0 -> 2.4.1 2020-04-05 22:27:32 -04:00
worldofpeace
9f4e21ff3e pantheon.switchboard-plug-notifications: 2.1.5 -> 2.1.6 2020-04-05 22:27:32 -04:00
worldofpeace
d63add4516 pantheon.switchboard-plug-network: 2.2.0 -> 2.3.0 2020-04-05 22:27:31 -04:00
worldofpeace
13be8d025f pantheon.switchboard-plug-keyboard: 2.3.5 -> 2.3.6 2020-04-05 22:27:31 -04:00
worldofpeace
89eeebc42a pantheon.switchboard-plug-datetime: 2.1.6 -> 2.1.7 2020-04-05 22:27:31 -04:00
worldofpeace
86719de340 pantheon.switchboard-plug-a11y: 2.1.3 -> 2.2.0 2020-04-05 22:27:31 -04:00
worldofpeace
568500a93f pantheon.granite: 5.3.0 -> 5.3.1 2020-04-05 22:27:31 -04:00
worldofpeace
f2f7833bdd pantheon.switchboard: 2.3.8 -> 2.3.9 2020-04-05 22:27:31 -04:00
worldofpeace
ef4ce3bdc1 pantheon.sideload: 1.0.1 -> 1.1.0 2020-04-05 22:27:30 -04:00
worldofpeace
b9087a830f pantheon.elementary-terminal: 5.5.1 -> 5.5.2 2020-04-05 22:27:30 -04:00
worldofpeace
d24c057ecb pantheon.elementary-files: 4.4.1 -> 4.4.2 2020-04-05 22:27:30 -04:00
worldofpeace
16712bb2e6 pantheon.elementary-code: 3.3.0 -> 3.4.0 2020-04-05 22:27:30 -04:00
worldofpeace
802a803ec0 pantheon.elementary-camera: 1.0.5 -> 1.0.6 2020-04-05 22:27:30 -04:00
worldofpeace
3434b85c75 pantheon.elementary-calendar: 5.0.3 -> 5.0.4 2020-04-05 22:27:29 -04:00
worldofpeace
fed6a0b63d pantheon.elementary-calculator: 1.5.4 -> 1.5.5 2020-04-05 22:27:29 -04:00
worldofpeace
b98eceeed1 pantheon.appcenter: 3.2.2 -> 3.2.3 2020-04-05 22:27:29 -04:00
Robert Helgesson
2444e3c418 documentation: minor spelling and stylistic fixes
(cherry picked from commit 40bbbb8f7d)
2020-04-06 02:38:44 +02:00
volth
0bb35152be firefox: mark as broken on 32-bit buildPlatform
(cherry picked from commit ed33a6c327)
2020-04-05 20:30:18 +02:00
Maximilian Bosch
8f720ba725 bandwhich: 0.12.0 -> 0.13.0
https://github.com/imsnif/bandwhich/releases/tag/0.13.0
(cherry picked from commit 35c0d9da9b)
2020-04-05 19:58:56 +02:00
Maximilian Bosch
0d4f92d789 mautrix-whatsapp: 2020-03-26 -> 2020-04-02
(cherry picked from commit ca0cb2c43f)
2020-04-05 17:47:19 +02:00
Vladimír Čunát
d815dc4b68 Merge #84273: gnutls: 3.6.12 -> 3.6.13 [security]
... into staging.  Fixes CVE-2020-11501.

(cherry picked from commit f91b34e53e)
2020-04-05 17:20:15 +02:00
Tristan Helmich (omniIT)
182f229ba7 graylog: 3.2.2 -> 3.2.4
(cherry picked from commit 5cb04b4377)
2020-04-05 12:54:51 +02:00
Jörg Thalheim
7601af232b itstool: use wrapPython to fix double shebang on macOS
(cherry picked from commit 02a5f3e88d1b85ff89b9307b4413aa878c753bc0)
2020-04-05 12:23:48 +02:00
Burke Libbey
6e14cf0e62 itstool: fix double-shebang issue on macOS
(cherry picked from commit 9761d5ac9fa3016c4a6ff734f0d2e652a447c11c)
2020-04-05 12:23:37 +02:00
Armin1402
92e20dc020 nexus: 3.20.1-01 -> 3.22.0-02
(cherry picked from commit e10b507ec0)
See
https://help.sonatype.com/repomanager3/release-notes/2020-release-notes
for security fixes details.
2020-04-05 02:23:54 +02:00
Pascal Bach
7c9e1ecdf5 nixos/nextcloud: prevent warning about missing X-Frame-Option
(cherry picked from commit 119a7aae50)
2020-04-05 01:39:07 +02:00
R. RyanTM
1e19a82577 apacheHttpd: 2.4.41 -> 2.4.43
(cherry picked from commit f26b2afb93)
2020-04-04 19:29:52 -04:00
Samuel Dionne-Riel
17af97f997 Merge pull request #84248 from andir/20.03/firefox
[20.03] update firefox to latests stable (secure) release
2020-04-04 18:08:00 -04:00
Tony Olagbaiye
01ac831e03 emacsPackages.lua-mode: Fix hash
for the third time...

(cherry picked from commit df594f1e45)
2020-04-04 23:12:38 +02:00
Maximilian Bosch
1d13409cb7 mautrix-telegram: 0.7.1 -> 0.7.2
https://github.com/tulir/mautrix-telegram/releases/tag/v0.7.2
(cherry picked from commit 1c54edcf8d)
2020-04-04 22:36:47 +02:00
Constantine Glen Evans
5de67dfd72 libunique: add darwin
libunique builds, and dependencies appear to build and run correctly,
in OS X.

(cherry picked from commit 45c9ad32fd)
2020-04-04 20:54:13 +02:00
Dmitry Kalinkin
feacec6a87 higan: fix darwin build
(cherry picked from commit 4c931a8217)
2020-04-04 20:53:23 +02:00
Dmitry Kalinkin
8876e5edb8 mame: add darwin support
(cherry picked from commit 39921bd43b)
2020-04-04 20:53:22 +02:00
Mario Rodas
06fe4b2528 lepton: enable on darwin
(cherry picked from commit 310b108efa)
2020-04-04 20:42:53 +02:00
Marek Mahut
b460ece5d6 cloudflare-wrangler: adding dependencies for darwin
(cherry picked from commit 6274ce11a1)
2020-04-04 20:42:48 +02:00
Nikolay Korotkiy
3c39e188d8 goldendict: enable on darwin
(cherry picked from commit 217b221eab)
2020-04-04 20:36:58 +02:00
Nikolay Korotkiy
ee4164e1da osm2pgsql: enable on darwin
(cherry picked from commit d6f5459da9)
2020-04-04 20:34:50 +02:00
rnhmjoj
ef955ecb1e riot-desktop: add gsettings schemas to the wrapper
(cherry picked from commit 1af6a1a134)
This fixes a crash when opening the file picker.
2020-04-04 20:24:54 +02:00
Eelco Dolstra
7d80362d6c kscreen: Fix #82141
https://bugs.kde.org/show_bug.cgi?id=417316
(cherry picked from commit 18539b1041)
2020-04-04 20:10:20 +02:00
Benjamin Hipple
3cd943704e Merge pull request #84224 from drewrisinger/dr-pr-backport-20.03-84223
[20.03]: python38Packages.uvloop: enable build
2020-04-04 13:45:28 -04:00
Drew Risinger
6118f04200 python3Packages.uvloop: enable on python3.8
Allow build pass by disabling test. Isolated issue to
test_sockets.py::TestAIOSockets::test_sock_close_add_reader_race.
This test is supposed to be skipped, but it isn't for some reason,
so we disable it instead.
See uvloop#284 (https://github.com/MagicStack/uvloop/pull/284)
for full details. Don't know why this test isn't properly skipped.

(cherry picked from commit 364909d535)
2020-04-04 13:18:29 -04:00
Maximilian Bosch
564d9c03b3 cargo-make: 0.30.1 -> 0.30.2
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.2
(cherry picked from commit 268f71cfd7)
2020-04-04 15:57:08 +02:00
Andreas Rammhold
30e54a0680 firefox-devedition-bin: 73.0b3 -> 75.0b12 2020-04-04 13:19:06 +02:00
Andreas Rammhold
22f3fc175e firefox-beta-bin: 73.0.b3 -> 75.0b11 2020-04-04 13:19:06 +02:00
Andreas Rammhold
4fccf16c2b firefox-bin: 74.0 -> 74.0.1 2020-04-04 13:19:06 +02:00
Andreas Rammhold
d44c85f518 firefox-esr: 68.6.0esr -> 68.6.1esr 2020-04-04 13:19:06 +02:00
Andreas Rammhold
5e9c65ae18 firefox: 73.0.1 -> 74.0.1 2020-04-04 13:18:59 +02:00
Andreas Rammhold
5fd70607c7 sqlite_3_31_1: init at 3.31.1
This is a backport to support building stable firefox version on the
stable release channel. Firefox has some very strict requirements on
it's dependencies. Since we do not want to use bundled versions of
dependencies this backport is required fore Firefox >=74.
2020-04-04 13:18:58 +02:00
Andreas Rammhold
c3a43d94ff nss_3_51: init at 3.51
This is a backport to support building stable firefox version on the
stable release channel. Firefox has some very strict requirements on
it's dependencies. Since we do not want to use bundled versions of
dependencies this backport is required fore Firefox >=74.
2020-04-04 13:18:58 +02:00
Andreas Rammhold
f9c866e5a4 firefox: update for version 74 2020-04-04 13:18:58 +02:00
Michael Weiss
8532dd179c Merge pull request #84094 from DieGoldeneEnte/llvm10-backport-20.03
[20.03] llvmPackages_10: init at 10.0.0
2020-04-04 12:34:20 +02:00
Benjamin Hipple
4dc8447c55 Merge pull request #84202 from mmilata/sympa-outgoing-20.03
[20.03] nixos/sympa: fix outgoing emails, update package version
2020-04-03 21:43:14 -04:00
Justin Humm
eeeb2bf803 nixos/release-notes: mention that dhcpcd stopped giving IPv4 addresses to bridges by default
This is an backward incompatible change from upstream dhcpcd [0], as
this could have easily locked me out of my box.

As dhcpcd doesn't allow to use only a blacklist (denyinterfaces in
dhcpcd.conf) of devices and use all remaining devices, while explicitly
allowing some interfaces like bridges, I think the best option would be
to not change anything about it and just educate the users here about
that edge case and how to solve it.

[0] https://roy.marples.name/archives/dhcpcd-discuss/0002621.html
2020-04-04 01:44:46 +02:00
Florian Klink
e46f456d79 Merge pull request #83601 from andir/20.03-buildRustCrate-fixes
[20.03] buildRustCrate fixes backports
2020-04-04 01:43:32 +02:00
Benjamin Hipple
aa3c504e20 Merge pull request #84184 from romildo/upd.freeoffice
[20.03] freeoffice: 973 -> 976
2020-04-03 19:21:33 -04:00
Benjamin Hipple
e8610d7a41 Merge pull request #84216 from drewrisinger/dr-pr-backport-20.03-84197
[20.03] python3Packages.pint: 0.9 -> 0.11
2020-04-03 19:21:18 -04:00
Drew Risinger
a1d1b7a227 datasette: 0.35 -> 0.39
(cherry picked from commit fb252907f5)
2020-04-03 18:12:01 -04:00
Drew Risinger
029276f654 pythonPackages.pint: 0.9 -> 0.11
(cherry picked from commit 4b822bbd23)
2020-04-03 18:11:49 -04:00
Bastian Köcher
ef33b9fc08 nixos/wg-quick: Fix after wireguard got upstreamed
(cherry picked from commit 644d643d68)
2020-04-03 23:01:38 +02:00
Lengyel Balazs
8224137bba fix wireguard service as well after it got upstreamed.
(cherry picked from commit 50fb52d4e1)
2020-04-03 23:01:37 +02:00
Daiderd Jordan
1c32029731 Merge pull request #80890 from LnL7/darwin-ldflags
darwin: fix NIX_LDFLAGS usages
2020-04-03 22:53:19 +02:00
Mario Rodas
f94171437b bazel: fix linker flags for darwin
(cherry picked from commit d1ee615f1c)
2020-04-03 22:27:18 +02:00
Jason Felice
66932665d5 plan9port: fix linker flags for macosx
(cherry picked from commit 4d2a8257ed)
(cherry picked from commit 7724ef793a)
2020-04-03 22:27:14 +02:00
Rohan Hart
449c060d12 lutris: custom wine installations require libkrb5
fixes the error: symbol k5_os_mutex_destroy version krb5support_0_MIT not defined in file libkrb5support.so.0

(cherry picked from commit 41fe7dbedf)
2020-04-03 13:06:44 -07:00
Maximilian Bosch
995229d130 grocy: 2.6.1 -> 2.6.2
https://github.com/grocy/grocy/releases/tag/v2.6.2
(cherry picked from commit 1d7a795fcd)
2020-04-03 21:59:31 +02:00
Frederik Rietdijk
e79a142e58 Merge release-20.03 into staging-20.03 2020-04-03 21:55:55 +02:00
Maximilian Bosch
0abd4fd0c3 Merge pull request #83628 from Ma27/mongodb-20.03
[20.03] mongodb: update
2020-04-03 21:48:55 +02:00
Martin Milata
5edcadc735 nixos/sympa: fix outgoing messaging
Because ProtectKernelModules implies NoNewPrivileges, postfix's sendmail
executable, which is setgid, wasn't able to send mail.

(cherry picked from commit fdc36e2c89)
2020-04-03 20:14:23 +02:00
Martin Milata
b95cf62bd0 sympa: build with --enable-fhs
Update module accordingly.

(cherry picked from commit 8f632b404f)
2020-04-03 20:14:22 +02:00
Martin Milata
769a5ccbaf sympa: 6.2.52 -> 6.2.54
(cherry picked from commit adc7388930)
2020-04-03 20:14:22 +02:00
Florian Klink
e89b1063fb Merge pull request #84164 from Izorkin/mariadb-tokudb-20.03
[20.03] mariadb: backport updates
2020-04-03 15:52:26 +02:00
Izorkin
c0c04ea70d mariadb: fix deps build
(cherry picked from commit 5abc729dd6)
2020-04-03 14:47:17 +02:00
Izorkin
6254058ddc mariadb: add zstd compression
(cherry picked from commit 24357432cd)
2020-04-03 14:47:17 +02:00
Izorkin
bf942675cb mariadb: add option to build server without rocksdb storage
(cherry picked from commit eafdfc8f51)
2020-04-03 14:47:17 +02:00
Izorkin
a05099d277 mariadb: add option to build server without tokudb storage
(cherry picked from commit 0296e678cf)
2020-04-03 14:47:17 +02:00
Florian Klink
a9d0d059a0 mariadb: remove withoutClient
When used as a global override, it breaks most of the options in the
mysql module, such as ensureDatabases, ensureUsers, initialDatabases,
initialScript.

We could use `.client` there, but if the reasoning behind this was
closure size reduction, we now end up with the same (or a bigger)
runtime closure and more complexity.

Apart from the options exposed by the mysql module, the client is also
likely to be required for local backups or DBA tasks anyways.

Instead of dealing with all the increased complexity of this for no
arguable benefit, let's just remove the `withoutClient` argument.
Storage space on mysql servers shouldn't be that much of an issue.

Closes #82428.

(cherry picked from commit 4b8d66aa72)
2020-04-03 14:47:17 +02:00
Izorkin
95c2e022cf mariadb: add needed packages
(cherry picked from commit 982a23de94)
2020-04-03 14:47:12 +02:00
Izorkin
988bb1f365 mariadb: build server with NUMA
(cherry picked from commit c6d159d696)
2020-04-03 14:47:01 +02:00
Eelco Dolstra
b255cd7f7f Don't pin 'nixpkgs' in the system registry by default
Nixpkgs takes up a lot of disk space so we shouldn't do this by
default.

(cherry picked from commit 469f14ef0f)
2020-04-03 14:42:29 +02:00
Dennis Gosnell
c778e137bd Merge pull request #84181 from schmittlauch/fixHoogleStable
[backport] haskell shellFor: Fix hoogle
2020-04-03 21:20:15 +09:00
José Romildo Malaquias
26df648c5f freeoffice: 974 -> 976
Cherry picked from PR #83495

(cherry picked from commit 55b6146535)
2020-04-03 08:59:23 -03:00
Daniël de Kok
a1d49d6c69 freeoffice: 973 -> 974
Cherry picked from PR #82038

Changelog:

https://www.freeoffice.com/en/download/servicepacks
(cherry picked from commit 44085e3501)
2020-04-03 08:56:53 -03:00
Eelco Dolstra
cf0855c899 nix-daemon.nix: Add option nix.registry
This allows you to specify the system-wide flake registry. One use is
to pin 'nixpkgs' to the Nixpkgs version used to build the system:

  nix.registry.nixpkgs.flake = nixpkgs;

where 'nixpkgs' is a flake input. This ensures that commands like

  $ nix run nixpkgs#hello

pull in a minimum of additional store paths.

You can also use this to redirect flakes, e.g.

  nix.registry.nixpkgs.to = {
    type = "github";
    owner = "my-org";
    repo = "my-nixpkgs";
  };

(cherry picked from commit 74e7ef35fe)
2020-04-03 13:48:03 +02:00
John Ericson
c565d7cc16 haskell shellFor: Fix hoogle
(cherry picked from commit 1c07ee7925)
2020-04-03 13:38:27 +02:00
Michael Weiss
2e3190538b chromium: 80.0.3987.162 -> 80.0.3987.163
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop.html

Note: This update contains only two fixes [0]. The fix that reverts a
feature which caused a crash spike on 80.0.3987.162 [1] seems important
for us (though the commit doesn't provide any data on the crash spike).

[0]: https://chromium.googlesource.com/chromium/src/+log/80.0.3987.162..80.0.3987.163?pretty=fuller
[1]: fc11c43603

(cherry picked from commit cbd13f3c55)
Backport of #84174.
2020-04-03 11:22:10 +02:00
Eelco Dolstra
5bf91db519 packagekit: Don't depend on nix unless enableNixBackend = true
(cherry picked from commit 9737f24919)
2020-04-02 22:16:52 +02:00
Florian Klink
3b3831957f go_1_14: 1.14 -> 1.14.1
This contains at least https://github.com/golang/go/issues/37807, which
currently causes some of our go binaries to just fail when booted with
older kernels.

See https://github.com/golang/go/issues/37436 for context.

(cherry picked from commit da2146ddeb)
2020-04-02 20:39:07 +01:00
Maximilian Bosch
50bfd35a05 matrix-synapse: 1.12.0 -> 1.12.1
https://github.com/matrix-org/synapse/releases/tag/v1.12.1
(cherry picked from commit 83c59cb9b6)
2020-04-02 21:13:57 +02:00
Tim Steinbach
8bbceb7c00 linux: 4.9.217 -> 4.9.218 2020-04-02 14:06:15 -04:00
Tim Steinbach
306226b378 linux: 4.4.217 -> 4.4.218 2020-04-02 14:06:15 -04:00
Tim Steinbach
1c38dc5df0 linux: 4.14.174 -> 4.14.175 2020-04-02 14:06:15 -04:00
volth
c8baff29a4 scallion: use openssl 1.0
it does not work with openssl 1.1 (upstream issue https://github.com/lachesis/scallion/issues/113)

(cherry picked from commit 8195e7eb93)
2020-04-02 16:37:07 +01:00
Dmitry Kalinkin
c8d2553996 texlive.combine: set TEXMFCNF in binary wrapper
This helps kpathsea to find texmf.cnf in some cases. For example,
dvipng was trying to look for it in
/nix/store/<hash>-texlive-dvipng.bin-2019/ instead of
/nix/store/<hash>-texlive-combined-full-2019/.

(cherry picked from commit 91c9f2ab5c)
cc #83816
2020-04-02 11:28:55 -04:00
Silvan Mosberger
e071ed1dc2 Merge pull request #84114 from mmilata/moinmoin-b42-20.03
nixos/moinmoin: fix maintainer reference
2020-04-02 17:11:01 +02:00
Martin Milata
866017f7eb nixos/moinmoin: fix maintainer reference
(cherry picked from commit f35d65850e)
2020-04-02 17:07:40 +02:00
Tim Steinbach
c9f15e246e linux: 5.5.14 -> 5.5.15 2020-04-02 10:26:16 -04:00
Tim Steinbach
d4cd5a8b45 linux: 5.4.29 -> 5.4.30 2020-04-02 10:26:16 -04:00
Tim Steinbach
fea9f4e002 linux: 4.19.113 -> 4.19.114 2020-04-02 10:26:16 -04:00
Michael Weiss
69975012f6 chromiumDev: Remove a patch that is already applied
This fixes the patch phase.
I missed this problem in #83956.

(cherry picked from commit 36c7123709)
2020-04-02 15:35:17 +02:00
Michael Weiss
bb34ef369e chromium: 80.0.3987.149 -> 80.0.3987.162
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_31.html

This update includes 8 security fixes.

CVEs:
CVE-2020-6450 CVE-2020-6451 CVE-2020-6452

(cherry picked from commit 6b7528c940)
2020-04-02 15:35:17 +02:00
Artemis Tosini
b36c9faf0f chromium: Add option to enable ozone (for Wayland)
(cherry picked from commit b3e1a1bbbb)
2020-04-02 15:34:59 +02:00
Peter Simons
e7c0dc6c8b chromium: I accidentally added the webrtc patch into the wrong section
(cherry picked from commit b3c2908825)
2020-04-02 15:34:28 +02:00
Peter Simons
5c8fdaacaf chromium: fix webrtc interaction with pulseaudio
The webrtc code suffered from a race condition when used
with Pulseaudio. This lead to audio input breaking every
couple of minutes during a webrtc session.

(cherry picked from commit 81b18c3711)
2020-04-02 15:34:08 +02:00
Jörg Thalheim
e3cf1bd817 Merge pull request #82350 from Mic92/haproxy
[backport-20.03] nixos/haproxy: Revive the haproxy user and group
2020-04-02 13:40:08 +01:00
Vladimír Čunát
0e5ef8c470 openssl: 1.1.1d -> 1.1.1f
https://github.com/pyca/pyopenssl/issues/899#issuecomment-607709065
The tests in python3.pkgs.pyopenssl succeed! (re-checked on 20.03)
Fixing this problem we experienced is listed as the only major change:
https://www.openssl.org/news/openssl-1.1.1-notes.html

(cherry picked from commit 6c8692feb4)
2020-04-02 11:54:49 +02:00
Gabor Greif
28239c7ca5 llvmPackages_10: init at 10.0.0
Backport of llvmPackages_10 since Chromium 83 will depend on it.
See https://github.com/NixOS/nixpkgs/pull/83350#issuecomment-605994185

llvmPackages_10: copy llvmPackages_9

* starting with rc2
* make `lldb` compilable again on Darwin
* separate out manpage creation for `lldb` into a new derivation
* minor tweaks to the patching of sources,
  some of which are backportable to earlier versions

(cherry picked from commit f111c6f9ce)

llvmPackages_10: rc2 -> rc3

http://lists.llvm.org/pipermail/llvm-dev/2020-March/139729.html

Additionally cherry-picked 3 commits from `llvm-project/master`:
- llvm/llvm-project@d21664c
- llvm/llvm-project@3a0f6e6
- llvm/llvm-project@87dac7d

such that clang can automatically pick up the polly plugin from the
`llvm-polly` build.

(cherry picked from commit 3a84353edb)

llvmPackages_10: rc3 -> rc4

Only needed to update hashes and the version.
Updated comment for extension handling patch

(cherry picked from commit 0ec3f4e26b)

llvmPackages_10: removed extra polly-build

There is no good reason to have separate builds for polly and no-polly
versions. wwwwwThe reason for the two versions was (as far as I can
tell) to defer rebuilds (see ed60483257).
Polly is now enabled by default.

(cherry picked from commit e9aa8770ea)

llvmPackges_10: rc4 -> rc5

updated versino and hashes for new rc

(cherry picked from commit cdee144dfc)

llvmPackages_10: rc5 -> release

updated hashes and url
updated comment regarding version/release_version to make it clearer

(cherry picked from commit 4665b2a9a2)
2020-04-02 11:42:16 +02:00
Danylo Hlynskyi
1bdc619f4b postgresql-wal-receiver: fix test for Pg12 (#80268)
Fixes https://github.com/NixOS/nixpkgs/issues/80060

(cherry picked from commit 56c4800e7f)
2020-04-02 12:25:56 +03:00
Vladimír Čunát
0d5664aa8f Merge branch 'release-20.03' into staging-20.03 2020-04-02 10:09:44 +02:00
Vladimír Čunát
5e24f4b3b3 openssl(_1_1): patch CVE-2019-1551
fetchpatch can't be used here and fetchurl from GitHub
like in PR #82928 has the risk of breaking the hash later;
fortunately the patches aren't too large.

(cherry picked from commit 2071e3be28)
2020-04-02 09:58:38 +02:00
Benjamin Hipple
c922cdefa8 Merge pull request #84002 from bhipple/bp/hobbes
[20.03] hobbes: init at 2020-03-10
2020-04-01 23:47:00 -04:00
John Ericson
7c56c5fe6b Merge pull request #84031 from obsidiansystems/consistent-bazel-ref
bazel-*: Consistently self reference
2020-04-01 19:34:52 -04:00
Jan Tojnar
9412ae37b0 Revert "make-options-doc: fix string context issues"
This reverts commit 3c15d578d4.

See https://github.com/NixOS/nixpkgs/issues/83863

(cherry picked from commit cab6b019b1)
2020-04-02 01:33:19 +02:00
Jonathan Ringer
98c6f66507 Revert "nixos/geoclue2: set location.provider to geoclue2"
This reverts commit f8a78afd5c.

(cherry picked from commit 3459038852)
2020-04-02 00:57:25 +02:00
Maximilian Bosch
137d76902b gitea: 1.11.3 -> 1.11.4
https://github.com/go-gitea/gitea/releases/tag/v1.11.4
(cherry picked from commit 38f4e7c6ea)
2020-04-01 23:24:20 +02:00
Maximilian Bosch
e39c7b99c8 linuxPackages.wireguard: 0.0.20200318 -> 1.0.20200401
https://lists.zx2c4.com/pipermail/wireguard/2020-April/005237.html

Resolves #84009

(cherry picked from commit b503b2c75f)
2020-04-01 22:45:19 +02:00
zowoq
734b84c441 bubblewrap: 0.4.0 -> 0.4.1
https://github.com/containers/bubblewrap/releases/tag/v0.4.1
(cherry picked from commit d67539de8a)
2020-04-01 19:45:03 +02:00
Eelco Dolstra
21dbb69ee6 kdeApplications: 19.12.1 -> 19.12.3
(cherry picked from commit 24519c87e8)
2020-04-01 19:00:42 +02:00
Thomaz Leite
609bf4b674 hobbes: mark as broken on Darwin
(cherry picked from commit 2ac8f8faeb)
2020-04-01 12:35:03 -04:00
Thomaz Leite
538929bde7 hobbes: init at unstable-2020-03-10
(cherry picked from commit 704e60443a)
2020-04-01 12:34:55 -04:00
Thomaz Leite
b18e7d7dc5 maintainers: add thmzlt
(cherry picked from commit 063795f3f5)
2020-04-01 12:34:42 -04:00
Jörg Thalheim
32992a68cf Merge pull request #83991 from charles-dyfis-net/curaengine-fix-openmp-compat-backport20.03
[20.03] curaLulzbot: Fix build breakage around OpenMP compatibility
2020-04-01 16:51:42 +01:00
Charles Duffy
a7f8187f09 curaLulzbot: Fix build breakage around OpenMP compatibility
(cherry picked from commit 68d14b3756)
2020-04-01 10:34:05 -05:00
Maximilian Bosch
dffbac03fd riot-desktop: 1.5.14 -> 1.5.15
https://github.com/vector-im/riot-web/releases/tag/v1.5.15
(cherry picked from commit d7c0018c79)
2020-04-01 17:03:00 +02:00
Maximilian Bosch
a449185598 riot-web: 1.5.14 -> 1.5.15
https://github.com/vector-im/riot-web/releases/tag/v1.5.15
(cherry picked from commit 04a6f80ff4)
2020-04-01 17:03:00 +02:00
Tim Steinbach
19693ddc2e linux_latest-libre: 17387 -> 17402
(cherry picked from commit ef3f3f2728)
2020-04-01 10:59:49 -04:00
Daniel Șerbănescu
c978b1bc1b linux-libre: added --force flag for deblobbing.
(cherry picked from commit 8431497dd2)
2020-04-01 10:59:35 -04:00
Tim Steinbach
f12b9d4e35 linux_latest-libre: 17322 -> 17387
(cherry picked from commit f0d17c2a17)
2020-04-01 10:59:22 -04:00
Tim Steinbach
c4998a4198 linux: 5.5.13 -> 5.5.14 2020-04-01 10:58:12 -04:00
Tim Steinbach
d96290cdf8 linux: 5.4.28 -> 5.4.29 2020-04-01 10:58:12 -04:00
Tim Steinbach
465eb7e75b jenkins: 2.204.5 -> 2.222.1
(cherry picked from commit be792c92ec)
2020-04-01 10:58:00 -04:00
Tim Steinbach
9100c67b27 jenkins: 2.204.4 -> 2.204.5
(cherry picked from commit 16eb11b5d3)
2020-04-01 10:58:00 -04:00
Tim Steinbach
a085e5c5f5 jenkins: 2.204.3 -> 2.204.4
(cherry picked from commit 03003d433c)
2020-04-01 10:58:00 -04:00
Tim Steinbach
b832f28e26 jenkins: 2.204.2 -> 2.204.3
(cherry picked from commit 2cc00e2e8a)
2020-04-01 10:58:00 -04:00
Mario Rodas
7f82e22f70 ruby_2_7: 2.7.0 -> 2.7.1
Changelog: https://www.ruby-lang.org/en/news/2020/03/31/ruby-2-7-1-released/
(cherry picked from commit a7f1e9f1ef)
2020-04-01 12:39:09 +00:00
Mario Rodas
8ea9745e8f ruby_2_6: 2.6.5 -> 2.6.6
Changelog: https://www.ruby-lang.org/en/news/2020/03/31/ruby-2-6-6-released/
(cherry picked from commit b312ecf34e)
2020-04-01 12:39:07 +00:00
Mario Rodas
4556842a4e ruby_2_5: 2.5.7 -> 2.5.8
Changelog: https://www.ruby-lang.org/en/news/2020/03/31/ruby-2-5-8-released/
(cherry picked from commit 99b09d6b8f)
2020-04-01 12:39:06 +00:00
Mario Rodas
959a1a3e16 ruby: update RVM patchsets
(cherry picked from commit dd24a2f2a0)
2020-04-01 12:39:03 +00:00
worldofpeace
33c19df80d qgnomeplatform: hardcode gsettings schemas
Fixes #81866

(cherry picked from commit 0ea686647f)
2020-04-01 02:16:45 -04:00
worldofpeace
bbb647549e nixos/geoclue2: set location.provider to geoclue2
(cherry picked from commit 4859c19a162218bad41cd320d101a296e1460855)
2020-04-01 01:31:52 -04:00
worldofpeace
347e9b3d65 elementary-planner: 2.1.1 -> 2.2.14
(cherry picked from commit 35fcdb5191)
2020-04-01 01:09:09 -04:00
worldofpeace
35b289344b lollypop: 1.2.23 -> 1.2.32
(cherry picked from commit 9c43840d2de44691bb4e8a94d7b9b41901e09b31)
2020-04-01 00:24:58 -04:00
Benjamin Koch
2bdd1f3a8d nixos/nextcloud: avoid loading imagick extension more than once
This avoids the following error message:
  Module 'imagick' already loaded at Unknown#0

(cherry picked from commit db32158bbd)
2020-04-01 02:57:01 +02:00
Symphorien Gibol
f1fcd3040f nixos/tests/os-prober.nix: fix out of memory
(cherry picked from commit 6a2f64a542)
2020-04-01 01:04:18 +02:00
Symphorien Gibol
fe6052f24b vmTools.diskImageFuns.debian9i386: update source url
referenced packets were removed from the mirrors

Fixes #77396 #80041

(cherry picked from commit 671dc2a5ca)
2020-04-01 01:04:11 +02:00
danbst
5d671c7c3c doc/postgresql: apply xmlformat
(cherry picked from commit a723672c20)
2020-03-31 23:54:39 +02:00
danbst
0f5b21ef72 nixos/postgresql: add upgrade documentation
(cherry picked from commit 759fd9b0b0)
2020-03-31 23:54:29 +02:00
Maximilian Bosch
55b0101dff nixos/acme: don't depend on multi-user.target inside a container
On boot, a container doesn't have an uplink and would run into a timeout
while waiting for cert renewal[1].

[1] https://github.com/NixOS/nixpkgs/pull/81371#issuecomment-605526099

(cherry picked from commit 1a5289f803)
2020-03-31 19:15:47 +02:00
John Ericson
48e07b529f Merge pull request #83882 from jmillerpdt/bugfix/tensorflow-mkl
pythonPackages.tensorflow: fix for bazel settings for intel mkl, dnnl for 20.03
2020-03-31 12:51:35 -04:00
ajs124
07dc1c743e memcached: 1.5.22 -> 1.6.2
fixes remote DoS/possibly code execution, as described in
https://github.com/memcached/memcached/issues/629

(cherry picked from commit 58a491aa80)
2020-03-31 18:25:49 +02:00
Benjamin Hipple
81c29c1be0 python27Packages.python-otr: mark as broken
See inline comment for details.

https://hydra.nixos.org/build/115510612

CC @NixOS/nixos-release-managers

ZHF: #80379
(cherry picked from commit c77bd38764)
2020-03-31 11:38:26 +01:00
Benjamin Hipple
e15c9281a5 python27Packages.application: 2.7.0 -> 2.8.0 and fix build
The build is currently broken due to failure to build `darcs` to fetch the src
package. The homepage is already their GitHub repo, and it appears to be the
active src of development anyways. See #83718

I came across this while debugging this failure:
https://hydra.nixos.org/build/115510612

Note that the `application` dependency *does* succeed on Hydra, because it's
already on local disk in Hydra's store, but I cannot rebuild locally because it
has prefer local builds.
https://hydra.nixos.org/build/115512559

This package is not reproducible on 20.03 or buildable outside of Hydra, so I
intend to backport the fix.

CC @NixOS/nixos-release-managers

ZHF: #80379
(cherry picked from commit 2c5fe63fbe)
2020-03-31 11:38:24 +01:00
rnhmjoj
75d9ade69e nix-script: 2015-09-22 -> 2020-03-23
(cherry picked from commit 8ef9611645)
2020-03-31 11:40:11 +02:00
R. RyanTM
509bdef90c pirate-get: 0.3.4 -> 0.3.5
(cherry picked from commit 365eb878a9)
This update contains an important fix.
2020-03-31 11:37:51 +02:00
Nick Hu
f2417ef677 zotero: make wrapGAppsHook work
(cherry picked from commit 4665e31ffd)
cc #83806
2020-03-30 22:37:17 -04:00
zowoq
b57eabee9f flatpak: 1.6.2 -> 1.6.3
https://github.com/flatpak/flatpak/releases/tag/1.6.3
(cherry picked from commit 72aceab6ef)
2020-03-31 02:15:34 +02:00
Maximilian Bosch
5a6e4ee2dd Merge pull request #83715 from tokudan/20.03/nextcloud1803
[20.03] nextcloud: 18.0.2 -> 18.0.3
2020-03-31 01:48:12 +02:00
Maximilian Bosch
76312413cb riot-desktop: 1.5.13 -> 1.5.14
https://github.com/vector-im/riot-web/releases/tag/v1.5.14
(cherry picked from commit 574ebdfa848efaf29bf28734eea4519ddb3a4c0e)
2020-03-31 00:09:37 +02:00
Maximilian Bosch
bb7abdfb88 riot-web: 1.5.13 -> 1.5.14
https://github.com/vector-im/riot-web/releases/tag/v1.5.14
(cherry picked from commit 740dcea640c49778dd7c6246731c6632ab5bb270)
2020-03-31 00:09:37 +02:00
John Ericson
2ca3f24f21 Merge branch 'add-tensorflow-2' into release-20.03 2020-03-30 20:35:31 +00:00
John Ericson
f2c8b07e36 tensorflow_2: Mark as broken for now
The other bits are good and worth keeping, however.
2020-03-30 20:34:05 +00:00
John Ericson
6ca72b60f2 Merge remote-tracking branch 'upstream/release-20.03' into add-tensorflow-2 2020-03-30 17:47:59 +00:00
Benjamin Hipple
08bd717049 Merge pull request #83774 from drewrisinger/release-20.03
[20.03] pythonPackages.scikit-build: fix python3.8 bug
2020-03-30 13:32:06 -04:00
adisbladis
90529eee7f pulseaudio: Enable bluetooth support by default
It only increases the closure size by 0.5M and users who do not set
the NixOS option `hardware.pulseaudio.package = pkgs.pulseaudioFull;`
will be stumped by their bluetooth audio not working.

(cherry picked from commit e41f3d9ef3)
2020-03-30 15:35:52 +01:00
Robin Gloster
bec49f93cc libvirt: fix escapeShellArg usage
Co-Authored-By: conferno <conferno@camfex.cz>
(cherry picked from commit b80edca6be)
2020-03-30 15:19:56 +02:00
Izorkin
91dd0647b6 libvirt: 5.4.0 -> 5.9.0
(cherry picked from commit 9336b15a88)
2020-03-30 15:19:36 +02:00
volth
8ad32ccee2 perlPackages.SysVirt: use upstream tag
(cherry picked from commit ddbac2e185)
2020-03-30 15:19:36 +02:00
volth
1affb42569 nixos/scripted-networking: fix bridge setup when libvirtd uses socket activation
(cherry picked from commit 687aa06c70)
2020-03-30 15:19:35 +02:00
volth
d0ab24e4fa libvirt: 6.0.0 -> 6.1.0, fix module
(cherry picked from commit d8664c78b1)
2020-03-30 15:19:35 +02:00
wedens
3388701ad8 libvirt: 5.4.0 -> 6.0.0
(cherry picked from commit 24c8d75874)
2020-03-30 15:19:35 +02:00
Drew Risinger
53264c9e35 pythonPackages.scikit-build: fix python3.8 bug
Python3.8 removes ``platform.linux_distribution()`` call,
must use ``pythonPackages.distro`` to get same information.
Closes #83305
Upstream PR: https://www.github.com/scikit-build/scikit-build/pull/458
Also formatting.

(cherry picked from commit c8dd834189)
2020-03-30 08:56:59 -04:00
Michele Guerini Rocco
8137763956 Merge pull request #83726 from davidak/backport
[20.03] Backport small doc improvements
2020-03-30 11:16:55 +02:00
Daniël de Kok
42001e5613 skypeforlinux: support app indicator
In contrast to e.g. Telegram or Slack, Skype does not show an app
indicator in the GNOME tray. This is quite annoying, since Skype will
continue to run in the background when its main window is closed, but
there is no way to access it.

This change adds libappindicator-gtk3 to the rpath to enable app
indicator support.
2020-03-30 09:52:01 +01:00
Vincent Laporte
0c666693d5 ocamlPackages.batteries: 2.11.0 → 3.0.0
(cherry picked from commit 86d1378d3e)
2020-03-30 10:06:24 +02:00
Joachim Breitner
ef0d4659da ghc-8.4.4.nix: Do not use git.haskell.org
which was deprecated in 2018 and is now gone for good. I guess many
won’t notice because the nix-cache kept the files around?

(cherry picked from commit
b872b8a200 and 29ca177c68)
2020-03-30 10:02:24 +02:00
Michael Lingelbach
5187b4105e opencv4: Enable nvidia-optical-flow-sdk when building with cuda
(cherry picked from commit dc1a15e7bd)
2020-03-30 02:37:13 -04:00
Michael Lingelbach
5c4ed65ad7 nvidia-optical-flow-sdk: init at 79c6cee80a2df9a196f20afd6b598a9810964c32
(cherry picked from commit 41b012907d)
2020-03-30 02:37:13 -04:00
Benjamin Hipple
bdaa840230 Merge pull request #81647 from acairncross/monosat-py38-backport
[20.03] python3Packages.monosat: Fix Python 3.8 build
2020-03-29 23:36:46 -04:00
davidak
9f99a89ee1 nixos/phpfpm: add example to socket
(cherry picked from commit c7e4c3b5a3)
2020-03-30 01:28:13 +02:00
davidak
680d4ceaa2 Doc: Fix typo
(cherry picked from commit dc434b0704)
2020-03-30 01:27:33 +02:00
Daniel Frank
a7ee0ab412 nextcloud: 18.0.2 -> 18.0.3
(cherry picked from commit 2496942c7a)
2020-03-29 23:59:48 +02:00
Antoine Eiche
4b5e5fce5a nixos/nextcloud: add bcmap, mp4 and webm in nginx configuration
This is used by the `firstrunwizard` and has been added in the nginx
configuration documentation of the latest
manual (cda627b7c8/admin_manual/installation/nginx.rst).

(cherry picked from commit 24ee2e8dc0)
2020-03-29 22:08:39 +02:00
Eelco Dolstra
2f0590907c make-tarball.nix: Strip source directory from packages.json
https://github.com/NixOS/nixos-homepage/issues/372
(cherry picked from commit 4e554ad1bc)
2020-03-29 20:04:33 +02:00
José Romildo Malaquias
098a0182a0 xfce.xfce4-whiskermenu-plugin: 2.3.3 -> 2.4.3
(cherry picked from commit 459a94ffa7)
2020-03-29 13:08:33 -04:00
José Romildo Malaquias
e8c651defd xfce.xfce4-hardware-monitor-plugin: fix url (unmaintained)
(cherry picked from commit 0dc23eaf61)
2020-03-29 13:08:33 -04:00
José Romildo Malaquias
83b7dde861 nixos.xfce: set desktopNames
(cherry picked from commit e9d707cf8e)
2020-03-29 12:58:45 -04:00
José Romildo Malaquias
9108778523 nixos.display-managers: use new attribute for desktop names
(cherry picked from commit fb47c6fbac)
2020-03-29 12:58:45 -04:00
Benjamin Hipple
87d71b46d2 Merge pull request #83682 from xfix/ftputil-zhf
[20.03] pythonPackages.ftputil: fix build
2020-03-29 12:01:42 -04:00
Konrad Borowski
ce667d569b pythonPackages.ftputil: fix build
Some tests assume execution before 2020.

(cherry picked from commit cfb435732a)
2020-03-29 15:07:58 +02:00
Jeff Labonte
2d0d227b23 brave: 1.5.112 -> 1.5.115
Update the checkum and the version

(cherry picked from commit fa5fc4993e)
Reason: Browser must be kept up-to-date
2020-03-29 14:08:13 +02:00
Peter Kolloch
040f611609 buildRustCrate: Add tests for checking files in outputs.
...and remove superfluous dependency files (*.d).
...and copy dSYM directories on Mac OS when in release=false mode.

(cherry picked from commit 782b304dba)
2020-03-29 13:03:28 +02:00
Andreas Rammhold
32cbd89e22 buildRustCrateTests: Fix link order test on darwin
As it turns out Darwin does most of the things differently then "normal"
systems. They are using a different shared library extension and require
an obscure commandline parameter that has to be added to every build
system out there. That issue seems to be with clang on Darwin as on
Linux that flag isn't required to build the very same tests (when using
clang).

After adjusting these two details the tests are running fine on the
darwin box that I was able to obtain.

(cherry picked from commit c8de31baa6)
2020-03-29 13:03:10 +02:00
Vincent Laporte
f7ffc4476d coqPackages.coqhammer: 1.1 → 1.1.1
(cherry picked from commit db5bde2342)
2020-03-29 11:03:07 +02:00
Vladimír Čunát
2ffa0a33f3 Merge #83013: exiv2: patch CVE-2019-20421
(cherry picked from commit 6d28c1893d)
2020-03-29 09:42:51 +02:00
Vincent Laporte
e41711cda2 coqPackages.paramcoq: 1.1.1 → 1.1.2
(cherry picked from commit 2773498fc0)
2020-03-29 07:49:09 +02:00
worldofpeace
4ebb91a1c8 Merge pull request #83564 from bhipple/bp/ntlm-auth
[20.03] pythonPackages.ntlm-auth: 1.0.3 -> 1.4.0 to fix build
2020-03-28 22:03:21 -04:00
Jan Tojnar
10e40a07ad hydra-unstable: Fix eval with allowAliases = false
* Catalyst::Plugin::Unicode::Encoding has been merged into Catalyst::Runtime
* Test::More is apparently part of Perl core modules since 5.6.2

(cherry picked from commit dc88e94ff1)
2020-03-29 03:03:52 +02:00
Maximilian Bosch
cd388a5c0e Merge pull request #82521 from Xe/libdap-hash-fix
development/libraries/libdap: fix hash
2020-03-29 01:30:21 +01:00
Maximilian Bosch
834fb02c9d nixos/tests/mongodb: also test mongodb-3_4
(cherry picked from commit 2c133fbb4b)
2020-03-29 01:12:16 +01:00
Maximilian Bosch
7e1b6e4a7b Merge pull request #83606 from scaredmushroom/tor-browser-bundle-bin_release-20.03
[20.03] tor-browser-bundle-bin: 9.0.6 -> 9.0.7
2020-03-29 01:11:20 +01:00
Benjamin Hipple
99a2ed5a55 pythonPackages.ntlm-auth: 1.0.3 -> 1.4.0 to fix build
On master and 20.03, this is failing to build on `python 3.8`.

https://hydra.nixos.org/build/115517329
https://hydra.nixos.org/build/114714922

CC @NixOS/nixos-release-managers
ZHF: #80379

Co-Authored-By: Niklas Hambüchen <mail@nh2.me>
(cherry picked from commit 97f09ff09f)
2020-03-28 20:10:18 -04:00
Benjamin Hipple
c8e2f6d337 Merge pull request #83631 from bhipple/bp/pywinrm
[20.03] pythonPackages.pywinrm: missing dependency
2020-03-28 20:09:50 -04:00
Kevin Amado
f21665a5dc pythonPackages.pywinrm: missing dependency
- Keberos is a dependency that you really want included in the pkg,
  this is also needed to run the test suite by default

(cherry picked from commit 36a1d1023a)
2020-03-28 19:35:22 -04:00
Maximilian Bosch
dabdd3a06d hydra: 2020-02-06 -> 2020-03-{24,27}
Upgrades Hydra to the latest master/flake branch. To perform this
upgrade, it's needed to do a non-trivial db-migration which provides a
massive performance-improvement[1].

The basic ideas behind multi-step upgrades of services between NixOS versions
have been gathered already[2]. For further context it's recommended to
read this first.

Basically, the following steps are needed:

* Upgrade to a non-breaking version of Hydra with the db-changes
  (columns are still nullable here). If `system.stateVersion` is set to
  something older than 20.03, the package will be selected
  automatically, otherwise `pkgs.hydra-migration` needs to be used.

* Run `hydra-backfill-ids` on the server.

* Deploy either `pkgs.hydra-unstable` (for Hydra master) or
  `pkgs.hydra-flakes` (for flakes-support) to activate the optimization.

The steps are also documented in the release-notes and in the module
using `warnings`.

`pkgs.hydra` has been removed as latest Hydra doesn't compile with
`pkgs.nixStable` and to ensure a graceful migration using the newly
introduced packages.

To verify the approach, a simple vm-test has been added which verifies
the migration steps.

[1] https://github.com/NixOS/hydra/pull/711
[2] https://github.com/NixOS/nixpkgs/pull/82353#issuecomment-598269471

(cherry picked from commit bd5324c4fc)
2020-03-29 00:26:15 +01:00
Fabian Möller
50de0ac554 mariadb-connector-c: add mysqlclient.pc pkgconfig symlink
(cherry picked from commit 349a991bfb)
2020-03-29 00:12:21 +01:00
worldofpeace
e1d8a61431 riot-desktop: fix StartupWMClass
It seems the quoting breaks it just like in da587daae5

(cherry picked from commit e50bb280cbf5339ed671b0a7208e6aba4002c713)
(cherry picked from commit f8ccef5edb)
2020-03-28 18:38:46 -04:00
Konrad Borowski
8f623faf2d nixos/tests/hibernate: disable for platforms other than x86_64
Due to 9pnet_virtio bugs, /nix is no longer available after
hibernation. It happens to work on x86_64, but not on other
platforms.

(cherry picked from commit d85fb28414)
2020-03-28 18:22:44 -04:00
worldofpeace
bde5b846f7 Merge pull request #83593 from bhipple/bp/zetup
[20.03] python38Packages.zetup: fix build
2020-03-28 18:15:41 -04:00
Maximilian Bosch
cd36c1d76e nixos/release-notes: mention that mongodb is unfree now
(cherry picked from commit 27121521b8)
2020-03-28 21:29:01 +01:00
Maximilian Bosch
7cf4906ab9 nixos/release-notes: mention mongodb update
(cherry picked from commit b65ff5d455)
2020-03-28 21:29:00 +01:00
Maximilian Bosch
07fb01965e nixos/tests/mongodb: rewrite with python
perl-based VM tests are deprecated.

(cherry picked from commit 2934f04641)
2020-03-28 21:29:00 +01:00
Maximilian Bosch
56bfb0d8ff mongodb: builds on aarch64 as well
(cherry picked from commit 80e6da7bd3)
2020-03-28 21:29:00 +01:00
Thibault Gagnaux
00d69b87a4 mongodb: 3.4.22 -> 3.4.24 & fix ssl
Reverts previous ssl fix commit and updates the mongodb version which fixes the ssl compile problem on darwin.

(cherry picked from commit c2eee6ecdb)
2020-03-28 21:29:00 +01:00
Nathan Smyth
ef9bd8e244 mongodb-4_0: 4.0.11 -> 4.0.12
(cherry picked from commit de69821b54)
2020-03-28 21:28:59 +01:00
Nathan Smyth
2cba56ec37 nixos/tests/mongodb: test against mongodb versions 3.4, 3.6, 4.0
Now has tests for 3.4, 3.6, 4.0. Has some duplication, but it appears to
work on my machine.

(cherry picked from commit 44641ed00b)
2020-03-28 21:28:59 +01:00
Nathan Smyth
83d71242f3 mongodb: 3.4.20 -> 3.4.22, 3.6.12 -> 3.6.13, 4.0.9 -> 4.0.11
(cherry picked from commit 165d8bda82)
2020-03-28 21:28:59 +01:00
Nathan Smyth
54d2944172 mongodb: split packages to expose 3.4, 3.6 and 4.0
(cherry picked from commit 97c4dff158)
2020-03-28 21:28:58 +01:00
Nathan Smyth
ac23e5039c mongodb: 3.4.10 -> 4.0.4
fix: Adding libtool to allow darwin compiles

Libtool seems to be required for mongodb to compile on darwin.

fix: Marking MongoDB as broken on aarch64

fix: Adding libtools to the pkg imports

Update mongodb to 4.0.4

(cherry picked from commit e9bec1adf6)
2020-03-28 21:28:58 +01:00
Maximilian Bosch
7a7952bce6 cargo-make: 0.30.0 -> 0.30.1
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.1
(cherry picked from commit 5a7d2e18fe)
2020-03-28 19:08:50 +01:00
Michael Weiss
25d25cd0d2 Merge pull request #83562 from nh2/release-20.03-issue-41918-chromium-swiftshader-by-default
[20.03] chromium: Enable swiftshader by default
2020-03-28 17:15:11 +01:00
cap
b9e710cf98 tor-browser-bundle-bin: 9.0.6 -> 9.0.7 2020-03-28 17:02:16 +01:00
Symphorien Gibol
9408b0cf38 buildRustCrateTests: add regression test for link order
(cherry picked from commit 2f7fb1c497)
2020-03-28 16:08:45 +01:00
Symphorien Gibol
259787549a buildRustCrate: don't sort link flags
Linkage order is significant and sorting can result in link errors.

(cherry picked from commit d8b853799d)
2020-03-28 16:08:38 +01:00
Niklas Hambüchen
af8edbf7c7 Merge pull request #83596 from bhipple/bp/torch
[20.03] treewide: remove torch and related packages; add throw aliases
2020-03-28 16:08:05 +01:00
Alyssa Ross
eb7d4502e1 buildRustCrate: fewer backslashes
This is a slight readability boost, I think.

(cherry picked from commit 7533876312)
2020-03-28 16:07:19 +01:00
Daniël de Kok
fcb8dc70f3 buildRustCrate: sort linker options in-place
(cherry picked from commit 412c72d20f)
2020-03-28 16:07:12 +01:00
Daniël de Kok
ed3dc87160 buildRustCrate: only link build deps into build script
According to the Cargo documentation:

> The build script does not have access to the dependencies listed in
> the dependencies or dev-dependencies section (they’re not built
> yet!). Also, build dependencies are not available to the package
> itself unless also explicitly added in the [dependencies] table.

https://doc.rust-lang.org/cargo/reference/build-scripts.html

This change separates linkage of regular dependencies and build
dependencies.

(cherry picked from commit ea6e048c37)
2020-03-28 16:07:06 +01:00
Peter Kolloch
0965206200 build-support/rust/buildRustCrate: Search for matching Cargo.toml in sub directories
This is what cargo does for git repositories.

See related issues:

* https://github.com/kolloch/crate2nix/issues/53
* https://github.com/kolloch/crate2nix/issues/33

(cherry picked from commit 8a6638daa9)
2020-03-28 16:07:01 +01:00
Peter Kolloch
7d8d24efe7 buildRustCrate: refactor colored logging
* Make errors include the crate name and make them much more prominent.
* Move more code into lib.sh
* Already source generated logging code and lib.sh in configure

(cherry picked from commit 04e7462ee6)
2020-03-28 16:06:56 +01:00
Andreas Rammhold
be561c771c buildRustCrate: remove superfluous dependency overrides
By overriding each dependency on every level of the dependency tree we
are creating a lot of unnecessary instances of the same derivation

Looking at the output size of `nix-instantiate --trace-function-calls
-vvvv …` and the execution time I got about a 10x improvement after
applying this change.

It was probably good intentions that lead to these overrides but in
practice no tooling (that I know of) really needs this. `carnix` and
`crate2nix` are fine without those overrides. Furthermore I believe that
it is the job of the tooling around `buildRustCrate` to provide a
coherent set of overrides. By not enforcing all of the overrides, debug
flags, verbosity, … to be the same throughout the closure we also allow
consumers to override specific aspects of the crates. Some (older?)
crates might need different `crateOverrides` then newer crates with the
same name. Currently such situations can not (easily) be implemented
with the override in-place.

(cherry picked from commit be5597fc9d)
2020-03-28 16:06:49 +01:00
Andreas Rammhold
1febd68e84 buildRustCrate: remap the current build dir to / for (more) reproducible builds
(cherry picked from commit 56e11bc8df)
2020-03-28 16:06:29 +01:00
Benjamin Hipple
b88ff468e9 Merge pull request #83566 from mmilata/rt-build-fix-20.03
[20.03] rt: fix build error
2020-03-28 10:24:35 -04:00
Benjamin Hipple
4ea297d46d Merge pull request #83565 from mmilata/perl-crypt-ssleay-0.73_06-20.03
[20.03] perlPackages.CryptSSLeay: 0.72 -> 0.73_06
2020-03-28 10:21:50 -04:00
Benjamin Hipple
4a3f221d05 aliases.nix: add aliases for removed torch packages
We've removed the abandoned and broken torch project as part of https://github.com/NixOS/nixpkgs/issues/71888

This commit adds aliases for:

- https://github.com/NixOS/nixpkgs/pull/81173
- https://github.com/NixOS/nixpkgs/pull/83568

(cherry picked from commit a80ed9f72a)
2020-03-28 10:04:21 -04:00
Benjamin Hipple
8f246dbc1b treewide: remove torch and related packages
See #71888 for details.

(cherry picked from commit 698ec44e74)
2020-03-28 10:03:18 -04:00
Benjamin Hipple
e1381d0956 python38Packages.zetup: fix build
Currently fails to build on python 3.8 due to an overly restrictive version bound.

ZHF: #80379

CC @NixOS/nixos-release-managers

(cherry picked from commit a65e052e4c)
2020-03-28 09:41:58 -04:00
rnhmjoj
b0c285807d antimony: 2019-10-30 -> 2020-03-28
(cherry picked from commit 9c7c0e148c)

ZHF: #80379
Fix build.
2020-03-28 10:36:45 +01:00
Robin Gloster
8ad6e4edf1 Merge pull request #81045 from B4dM4n/backport-mariadb-pkgconfig-link
[20.03] mariadb-connector-c: add mysqlclient.pc pkgconfig symlink
2020-03-28 09:30:44 +00:00
ajs124
24b17c2a97 atlassian-confluence: 7.2.1 -> 7.3.4
(cherry picked from commit 5dbeb69154)
2020-03-28 10:29:32 +01:00
vasy
f1c1247b87 atlassian-jira: 8.7.1 -> 8.8.0 (#83218)
fix not starting service when jdk is jdk11

(cherry picked from commit 758f81df44)
2020-03-28 10:26:27 +01:00
R. RyanTM
d7d7a34508 atlassian-jira: 8.7.0 -> 8.7.1
(cherry picked from commit 26a31f8c62)
2020-03-28 10:26:27 +01:00
Antoine Eiche
d87fea74bd nixos/alertmanager: start after the network-online target
If the host network stack is slow to start, the alertmanager fails to
start with this error message:

    caller=main.go:256 msg="unable to initialize gossip mesh" err="create memberlist: Failed to get final advertise address: No private IP address found, and explicit IP not provided"

This bug can be reproduced by shutting down the network stack and
restarting the alertmanager.

Note I don't know why I didn't hit this issue with previous
alertmanager releases.

(cherry picked from commit 39621bb8de)
2020-03-28 09:30:49 +01:00
worldofpeace
cdf5eca5b5 Merge pull request #83567 from nh2/release-20.03-remove_lua_torch
[20.03] torchPackages, torch-repl: remove
2020-03-28 01:38:18 -04:00
worldofpeace
b8b0d0adb0 Merge pull request #83563 from bhipple/bp/rpcs3
[20.03] rpcs3: 0.0.6-8187-790962425 -> 0.0.8-9300-341fdf7eb
2020-03-28 01:28:23 -04:00
worldofpeace
22dba9fe07 Merge pull request #83557 from bhipple/bp/airflow
[20.03] python3Packages.apache-airflow: fix dependencies
2020-03-28 01:24:19 -04:00
worldofpeace
e2340b8075 Merge pull request #83574 from bhipple/bp/effect
[20.03] pythonPackages.effect: fix build by marking py3 only
2020-03-28 01:22:19 -04:00
Dennis Gosnell
adc01b589b Merge pull request #83572 from nh2/release-20.03-hspec-core-disable-tests
[20.03] haskellPackages.hspec-core: Disable tests on i686
2020-03-28 14:11:49 +09:00
John Ericson
592a34de3f Merge pull request #83533 from bhipple/bp/mkl
[20.03] mkl: 2019.5.281 -> 2020.0.166 (Linux only)
2020-03-27 23:47:20 -04:00
Benjamin Hipple
235ee73ee6 pythonPackages.effect: fix build by marking py3 only
Upstream only supports python >= 3.6:
https://github.com/python-effect/effect/#effect

CC @NixOS/nixos-release-managers

ZHF: #80379
(cherry picked from commit 3b7b98ce1e)
2020-03-27 23:15:44 -04:00
Niklas Hambüchen
1f6b1cbae4 haskellPackages.hspec-core: Disable tests on i686.
The tests have x86_64 results hardcoded, see
https://github.com/hspec/hspec/issues/431.

(cherry picked from commit 59e77d45b234162e2a6b804fe9c1462e6089afe8)
2020-03-28 04:06:20 +01:00
Matthieu Coudron
18c0784b89 torchPackages, torch-repl: remove
See https://github.com/NixOS/nixpkgs/issues/71888
and https://github.com/NixOS/nixpkgs/issues/56398

To sump up, development has moved on to other technologies than lua:
https://github.com/torch/torch7#development-status
and the current packages are broken anyway.

(cherry picked from commit 05b6836816)
2020-03-28 03:17:14 +01:00
Stig Palmquist
f33613906f perlPackages.CryptSSLeay: 0.72 -> 0.73_06
dependencies:
perlPackages.BytesRandomSecure: init at 0.29
perlPackages.CryptRandomSeed: init at 0.03
perlPackages.CryptRandomTESHA2: init at 0.01

(cherry picked from commit 3aade16ff3)
2020-03-28 03:02:29 +01:00
Stig Palmquist
fd6c92eb86 rt: fix build error
ZHF: #80379
https://hydra.nixos.org/build/113061284

Added requiredPerlModules as suggested for similar problem as described for
similar problem here:
https://github.com/NixOS/nixpkgs/issues/72783#issuecomment-549817011

(cherry picked from commit 3e50e26e7d)
2020-03-28 02:59:48 +01:00
aszlig
35fe837b62 nginx: Fix ETag patch to ignore realpath(3) error
While our ETag patch works pretty fine if it comes to serving data off
store paths, it unfortunately broke something that might be a bit more
common, namely when using regexes to extract path components of
location directives for example.

Recently, @devhell has reported a bug with a nginx location directive
like this:

  location ~^/\~([a-z0-9_]+)(/.*)?$" {
    alias /home/$1/public_html$2;
  }

While this might look harmless at first glance, it does however cause
issues with our ETag patch. The alias directive gets broken up by nginx
like this:

  *2 http script copy: "/home/"
  *2 http script capture: "foo"
  *2 http script copy: "/public_html/"
  *2 http script capture: "bar.txt"

In our patch however, we use realpath(3) to get the canonicalised path
from ngx_http_core_loc_conf_s.root, which returns the *configured* value
from the root or alias directive. So in the example above, realpath(3)
boils down to the following syscalls:

  lstat("/home", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0
  lstat("/home/$1", 0x7ffd08da6f60) = -1 ENOENT (No such file or directory)

During my review[1] of the initial patch, I didn't actually notice that
what we're doing here is returning NGX_ERROR if the realpath(3) call
fails, which in turn causes an HTTP 500 error.

Since our patch actually made the canonicalisation (and thus additional
syscalls) necessary, we really shouldn't introduce an additional error
so let's - at least for now - silently skip return value if realpath(3)
has failed.

However since we're using the unaltered root from the config we have
another issue, consider this root:

  /nix/store/...-abcde/$1

Calling realpath(3) on this path will fail (except if there's a file
called "$1" of course), so even this fix is not enough because it
results in the ETag not being set to the store path hash.

While this is very ugly and we should fix this very soon, it's not as
serious as getting HTTP 500 errors for serving static files.

I added a small NixOS VM test, which uses the example above as a
regression test.

It seems that my memory is failing these days, since apparently I *knew*
about this issue since digging for existing issues in nixpkgs, I found
this similar pull request which I even reviewed:

https://github.com/NixOS/nixpkgs/pull/66532

However, since the comments weren't addressed and the author hasn't
responded to the pull request, I decided to keep this very commit and do
a follow-up pull request.

[1]: https://github.com/NixOS/nixpkgs/pull/48337

Signed-off-by: aszlig <aszlig@nix.build>
Reported-by: @devhell
Acked-by: @7c6f434c
Acked-by: @yorickvP
Merges: https://github.com/NixOS/nixpkgs/pull/80671
Fixes: https://github.com/NixOS/nixpkgs/pull/66532
(cherry picked from commit e1d63ada02)
2020-03-28 02:59:35 +01:00
Christoph Neidahl
8e4c0dd26e rpcs3: 0.0.6-8187-790962425 -> 0.0.8-9300-341fdf7eb
(cherry picked from commit f028498f63)
2020-03-27 21:57:41 -04:00
Niklas Hambüchen
d59be297de chromium: Enable swiftshader by default.
This makes it possible to use chromium headless with WebGL
(e.g. for webdriver tests) without having to rebuild from source.

The upstram default is to enable, thus simply removing our disabling switch.

Also fixes #41918.

(cherry picked from commit 015bb28ae1)
2020-03-28 02:52:31 +01:00
worldofpeace
16d4f17a6f Merge pull request #83553 from bhipple/bp/gym
[20.03] python27Packages.gym: 0.15.4 -> 0.16.0 to fix build
2020-03-27 21:42:41 -04:00
worldofpeace
7780ba4eb9 Merge pull request #83558 from bhipple/bp/pounce
[20.03] pounce: 1.0p1 -> 1.1 to fix build
2020-03-27 21:41:32 -04:00
Alyssa Ross
34b75d1172 pounce: 1.0p1 -> 1.1
(cherry picked from commit 88e4258df4)
2020-03-27 21:24:03 -04:00
Jonathan Ringer
862c3c2d24 python3Packages.apache-airflow: fix dependencies
(cherry picked from commit b4b0bc9d38)
2020-03-27 21:16:09 -04:00
R. RyanTM
9bd852f026 python27Packages.gym: 0.15.4 -> 0.16.0
Fixes broken build by backporting https://github.com/NixOS/nixpkgs/pull/81577
and previous update.

CC @NixOS/nixos-release-managers

ZHF: #80379

(cherry picked from commit 908c6e8214a3933d43f55f5c4ae6df0572c34568)
2020-03-27 20:58:52 -04:00
worldofpeace
348880312e Merge pull request #83550 from bhipple/bp/ion
[20.03] ion: 1.0.5 -> unstable-2020-03-22
2020-03-27 20:30:28 -04:00
Benjamin Hipple
409e70d6c5 ion: 1.0.5 -> unstable-2020-03-22
The app is still maintained upstream, but they aren't cutting releases on
crates.io anymore:
https://crates.io/crates/ion-shell

This fixes the build with the latest Rust toolchain by upgrading to the current
commit off the project's `master`.

ZHF: #80379

(cherry picked from commit 16cdff0711)
2020-03-27 20:18:01 -04:00
adisbladis
d940214174 poetry2nix: 1.7.0 -> 1.7.1 2020-03-27 23:46:07 +00:00
adisbladis
176cb5cc87 poetry2nix: 1.6.1 -> 1.7.0 2020-03-27 22:53:38 +00:00
Roberto Di Remigio
d22cd2bccf mkl: 2019.5.281 -> 2020.0.166 (Linux only)
(cherry picked from commit 335e097352)
2020-03-27 17:39:02 -04:00
Benjamin Hipple
a6f3555ccb pythonPackages.distributed: remove bad check dependency on pytest-faulthandler
(cherry picked from commit acfe7e0dbc)
2020-03-27 14:10:00 -07:00
Benjamin Hipple
353494841b python2Packages.pytest-faulthandler: remove package
This has been upstreamed into pytest itself as of pytest 5.0, which we have:
https://github.com/pytest-dev/pytest-faulthandler

Since it should no longer be used, let's remove from nix.

(cherry picked from commit f5ffd143d6)
2020-03-27 14:10:00 -07:00
Benjamin Hipple
e158eccf9b python2Packages.faulthandler: 3.1 -> 3.2 and fix build
It is currently failing on master and 20.03. I spent some time reading the src
code but was not able to figure out why the env var activation is not working.
Since this is currently failing, and since it's dying alongside python 2 anyways
I propose we just disable the 1 failing test.

There's some more information inline in the comment if someone wants to fix this
or dig further.

(cherry picked from commit 643d10295d)
2020-03-27 14:10:00 -07:00
toonn
97d3d1ec7f wire-desktop: linux 3.15.2922 -> 3.16.2923
(cherry picked from commit 55ce589f18)
2020-03-27 19:23:10 +01:00
toonn
cf77a5fdc1 wire-desktop: linux 3.12.2916 -> 3.15.2922
(cherry picked from commit 39b39690fa)
2020-03-27 19:23:10 +01:00
toonn
7730ed9da4 wire-desktop: mac 3.12.3490 -> 3.15.3621
(cherry picked from commit 43f245d6d9)
2020-03-27 19:23:09 +01:00
Lancelot SIX
d0f67fb5ed qgis: 3.10.1 -> 3.10.4
(cherry picked from commit 8e8efc7ace)
2020-03-27 10:44:08 -07:00
Lancelot SIX
f735cce584 pythonPackages.pyproj: 2.2.2 -> 2.6.0
(cherry picked from commit 6cd915b21f)
2020-03-27 10:44:08 -07:00
Lancelot SIX
1b0b8ef9b1 proj: 6.1.1 -> 6.3.1
(cherry picked from commit 4f6fc6dc62)
2020-03-27 10:44:08 -07:00
adisbladis
e8d490f4c1 poetry: 1.0.3 -> 1.0.5 2020-03-27 14:56:09 +00:00
adisbladis
2037514ecb poetry2nix: Add hooks 2020-03-27 14:54:22 +00:00
adisbladis
713aa6d70d poetry2nix: 1.1.0 -> 1.6.1 2020-03-27 14:52:12 +00:00
Florian Klink
71f2773f8a gitlab: 12.8.7 -> 12.8.8
(cherry picked from commit 8ab04fd87b)
2020-03-27 13:41:16 +01:00
Lancelot SIX
85055b3ab7 ptyhon3Packages.django-compat: fix 2020-03-27 10:36:54 +01:00
Dmitry Kalinkin
5ffc821846 perlPackages.CPAN: fix patch download
Fixes: 153b0db9 ('perlPackages.CPAN: apply patch to fix changed YAML module default')
Closes: #81480
(cherry picked from commit fa73723305)
2020-03-27 04:06:47 -04:00
gnidorah
294445af03 vk-messenger: 4.5.2 -> 5.0.1
(cherry picked from commit c694fcfb3e)
cc #81127
2020-03-27 03:32:12 -04:00
Vincent Laporte
fdbefdc474 ocaml: 4.09.0 → 4.09.1
(cherry picked from commit 4a3edb4bd7)
2020-03-27 08:07:03 +01:00
Benjamin Hipple
834ad820cc Merge pull request #82515 from Xe/fix-b3sum
tools/security/b3sum: fix cargo hash
2020-03-26 21:04:07 -04:00
Maximilian Bosch
ea57fc5d63 iwd: 1.4 -> 1.6
(cherry picked from commit 0e69720f34)
2020-03-27 01:32:25 +01:00
Maximilian Bosch
68c3a4f23c ell: 0.27 -> 0.30
(cherry picked from commit 79cc0c7e9f)
2020-03-27 01:32:20 +01:00
Maximilian Bosch
c2db74f11a mautrix-whatsapp: 2020-02-09 -> 2020-03-26
(cherry picked from commit 5bfc1d5110)
2020-03-26 23:47:18 +01:00
Michael Weiss
c10c44a633 signal-desktop: 1.32.2 -> 1.32.3
(cherry picked from commit 38aa1cad7f)
2020-03-26 22:17:20 +01:00
Servilio Afre Puentes
b2c8626d61 emacs-modes: build MELPA package sets without null packages
The current algorithm creates attributes with null values for packages
with no source in a variant of MELPA. Though will satify dependencies
they produce no files, and though a build that transitively depends on
one them will be successful, Emacs won't find them and any code
depending on them won't work.

The solution with minimal code change would have been filtering the
list of results from melpaDerivation by comparing the value against
null, but that leads to an infinite recursion.

This commit also moves legacy renames from the shared to the unstable
set, as the corresponding null value elements won't exist in the
stable set anymore.

The test used for the problem was:

  $ nix-build --show-trace ./default.nix -A emacs26Packages.melpaStablePackages.findr
  error: expression does not evaluate to a derivation (or a set or list of those)

The expected output, obtained with this commit is:

  $ nix-build --show-trace ./default.nix -A emacs26Packages.melpaStablePackages.findr
  error: attribute 'findr' in selection path 'emacs26Packages.melpaStablePackages.findr' not found
2020-03-26 16:32:11 -04:00
worldofpeace
8d0010b08b networkmanager: 1.22.8 -> 1.22.10
(cherry picked from commit 4feb4cf707)
2020-03-26 13:39:55 -04:00
Domen Kožar
41875cf33e ghc: 8.10.0.20200123 -> 8.10.1
(cherry picked from commit 59c58f3360)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-26 17:54:27 +01:00
Jan Tojnar
f6ab55b31c mysql-workbench: 8.0.15 → 8.0.19
* https://dev.mysql.com/doc/relnotes/workbench/en/news-8-0-16.html
* https://dev.mysql.com/doc/relnotes/workbench/en/news-8-0-17.html
* https://dev.mysql.com/doc/relnotes/workbench/en/news-8-0-18.html
* https://dev.mysql.com/doc/relnotes/workbench/en/news-8-0-19.html

The release notes contain the following:

Important Note: MySQL Workbench 8.0.19 is unable to open a new connection to MySQL Server from the home screen if the server is not started and you cannot start a server by using the Workbench Administration feature. Administrative and SQL editing tasks require an online server for the duration of this issue. Feature tasks that you performed with an offline server in previous releases now return an error message indicating that the server is unreachable.

but it is clearly better than having it broken.

(cherry picked from commit 070b49ed00)
2020-03-26 17:18:47 +01:00
Jan Tojnar
f5e8ef656f libmysqlconnectorcpp: 1.1.9 → 8.0.19
This has been seriously outdated:

* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-1-1-10.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-1-1-11.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-1-1-12.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-1-1-13.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-2-0-1.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-2-0-2.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-2-0-3.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-2-0-4.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-5.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-6.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-7.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-8-through-10.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-11.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-12.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-13.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-14.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-15.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-16.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-17.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-18.html
* https://dev.mysql.com/doc/relnotes/connector-cpp/en/news-8-0-19.html

Expression changes:

* Format with nixpkgs-fmt.
* Move cmake to nativeBuildInputs.
* Use OpenSSL from the system as using the bundled version is now optional.
* Use MysQL 8.0 since this is supposed to be used with that version.
* Explicitly enable the now legacy JDBC library used by mysql-workbench.
* Remove unnecessary MYSQL_LIB_DIR flag. MySQL will be found automatically.
    * We just need the build script know it is not a static library.

(cherry picked from commit 23d69911f3)
2020-03-26 17:18:47 +01:00
Jan Tojnar
4c122542ce mysql-workbench: format with nixpkgs-fmt
(cherry picked from commit eacf018ea7)
2020-03-26 17:18:47 +01:00
worldofpeace
a3a02d6cd4 Merge pull request #83392 from Ma27/nixos-container-nsenter-20.03
Revert "nixos-container: use systemd-run instead of nsenter"
2020-03-26 11:01:53 -04:00
Arian van Putten
01c61f3923 wire-desktop: Fix StartupWMClass
With quotes it doesn't match the Wire's screen, causing the window to not be grouped under its icon in Gnome.

(cherry picked from commit da587daae5)
2020-03-26 10:57:37 -04:00
Maximilian Bosch
d148bb00cf nixos/nextcloud: implement a safe upgrade-path between 19.09 and 20.03
It's impossible to move two major-versions forward when upgrading
Nextcloud. This is an issue when comming from 19.09 (using Nextcloud 16)
and trying to upgrade to 20.03 (using Nextcloud 18 by default).

This patch implements the measurements discussed in #82056 and #82353 to
improve the update process and to circumvent similar issues in the
future:

* `pkgs.nextcloud` has been removed in favor of versioned attributes
  (currently `pkgs.nextcloud17` and `pkgs.nextcloud18`). With that
  approach we can safely backport major-releases in the future to
  simplify those upgrade-paths and we can select one of the
  major-releases as default depending on the configuration (helpful to
  decide whether e.g. `pkgs.nextcloud17` or `pkgs.nextcloud18` should be
  used on 20.03 and `master` atm).

* If `system.stateVersion` is older than `20.03`, `nextcloud17` will be
  used (which is one major-release behind v16 from 19.09). When using a
  package older than the latest major-release available (currently v18),
  the evaluation will cause a warning which describes the issue and
  suggests next steps.

  To make those package-selections easier, a new option to define the
  package to be used for the service (namely
  `services.nextcloud.package`) was introduced.

* If `pkgs.nextcloud` exists (e.g. due to an overlay which was used to
  provide more recent Nextcloud versions on older NixOS-releases), an
  evaluation error will be thrown by default: this is to make sure that
  `services.nextcloud.package` doesn't use an older version by accident
  after checking the state-version. If `pkgs.nextcloud` is added
  manually, it needs to be declared explicitly in
  `services.nextcloud.package`.

* The `nixos/nextcloud`-documentation contains a
  "Maintainer information"-chapter  which describes how to roll out new
  Nextcloud releases and how to deal with old (and probably unsafe)
  versions.

Closes #82056

(cherry picked from commit 702f645aa8)
2020-03-26 13:23:20 +01:00
Maximilian Bosch
b249ffa449 wasm-bindgen-cli: 0.2.59 -> 0.2.60
https://github.com/rustwasm/wasm-bindgen/releases/tag/0.2.60
(cherry picked from commit c3392946b1)
2020-03-26 13:23:19 +01:00
Michael Weiss
4a82119cce signal-desktop: 1.32.1 -> 1.32.2
(cherry picked from commit 5c4735947d)
2020-03-26 12:18:45 +01:00
Vincent Laporte
d947d2863c coqPackages.mathcomp_1_10: init at 1.10.0
(cherry picked from commit 229dc013b3)
2020-03-26 08:23:13 +01:00
Vladimír Čunát
84f1b23670 Merge branch 'staging-20.03' into release-20.03 2020-03-26 07:22:05 +01:00
Benjamin Hipple
34e93f4eff Merge pull request #83330 from JeffLabonte/20.03_update_protonvpn_ng_2.2.0-with_fix
[20.03] protonvpn-cli-ng: 2.2.0 -> 2.2.2
2020-03-26 00:58:41 -04:00
Maximilian Bosch
7f1ba606ac Revert "nixos-container: use systemd-run instead of nsenter"
This reverts commit 7cb100b683.

This appears to break at least the `container`-backend of `nixops`: when
running `switch-to-configuration` within `nixos-container run`, the
running `systemd`-instance gets reloaded which appears to kill the
`systemd-run` command and causes `nixos-container run` to hang.

The full issue is reported in the original PR[1].

[1] https://github.com/NixOS/nixpkgs/pull/67332#issuecomment-604145869
2020-03-26 01:30:31 +01:00
John Ericson
3a009bd5da Merge branch 'tensorflow-versions' into release-20.03
There were a number of fixes that were not backported. I made a branch
with those cherry-picked fixes to be merged into both 20.03 and master
(not changing master), to ensure the two release branches didn't diverge
when they shouldn't.

I like this "apply the fixes to the comment ancester and then merge
both" approach because it makes it much easier to avoid backporting
issues. I suspect I'll be making more fixes to both in the future.
2020-03-25 20:30:46 +00:00
Tim Steinbach
6c29c8b67b linux: 5.5.11 -> 5.5.13 2020-03-25 13:09:57 -04:00
Tim Steinbach
09bb10dcde linux: 5.4.27 -> 5.4.28 2020-03-25 13:09:57 -04:00
Tim Steinbach
7a543ea318 linux: 4.19.112 -> 4.19.113 2020-03-25 13:09:57 -04:00
John Ericson
49a0313e92 Merge branch 'tenserflow-versions' into release-20.03 2020-03-25 11:49:16 -04:00
Domen Kožar
c1dd41699f add openapi-generator-cli-unstable
(cherry picked from commit cefe9b2dac)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-25 16:40:58 +01:00
Marek Fajkus
3cfa4cc98b elmPackages.elm-coverage: init at 0.0.3
(cherry picked from commit baf37aabad)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-25 16:13:20 +01:00
Marek Fajkus
0e8a3aae44 elmPackages.elmi-to-json: 1.2.0 -> 1.3.0
(cherry picked from commit d52fdecab1)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-25 16:05:52 +01:00
Marek Fajkus
b8ac3310b7 elmPackages.elm-instrument: Init at 0.0.7
(cherry picked from commit f387b85540)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-25 16:03:37 +01:00
Aaron VonderHaar
107a1c661d elm-format: 0.8.2 -> 0.8.3
(cherry picked from commit 0fa9ef1ee2)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-25 16:03:13 +01:00
Kim Lindberger
d4ea7ae076 gitlab: 12.8.6 -> 12.8.7 (#82838) (#83353)
https://about.gitlab.com/releases/2020/03/16/gitlab-12-8-7-released/
(cherry picked from commit 3a173c1d75)
2020-03-25 13:23:28 +01:00
Leif Metcalf
c6839e5ae8 Update git clone command example
(cherry picked from commit c3f8e598ed)
2020-03-25 09:34:45 +00:00
Vincent Laporte
a1b8dae54a alt-ergo: 2.3.0 → 2.3.1
(cherry picked from commit 618bca7054)
2020-03-25 07:31:05 +01:00
Jeff Labonte
b02da56acc protonvpn-cli-ng: 2.2.0 -> 2.2.2
Some changes were made after final review of the package. There was a
missing runtime dependency that was discovered after merge of the
backport

(cherry picked from commit 9fe4a634c1)
Reason: The dependency can make the package work or not
2020-03-24 21:02:49 -04:00
Eelco Dolstra
b898371cfa nixos/release-small.nix: Export options job
(cherry picked from commit e51c7f60cb)
2020-03-24 23:40:58 +01:00
Eelco Dolstra
921f7ac484 Compress optionsJSON using brotli
(cherry picked from commit 4052f9b849)
2020-03-24 23:40:58 +01:00
Eelco Dolstra
ce72d90a2f Add packages.json to the tarball job
Moved from nixos-homepage.

(cherry picked from commit d6ec410a47)
2020-03-24 23:40:58 +01:00
Florian Klink
234bc36b34 Merge pull request #83254 from aanderse/mysql80-backport
nixos/mysql: fix service so it works with mysql80 package [20.03 backport]
2020-03-24 23:39:17 +01:00
Reno Reckling
8831dbcbfc i3lock-fancy: Fix wrong path to mktemp
mktemp was not correctly replaced in this package. Leading to
"command not found: mktemp" error.

(cherry picked from commit 55fb13e5e1)
2020-03-24 22:07:21 +01:00
zowoq
a0cd08530b youtube-dl: 2020.03.08 -> 2020.03.24
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.03.24
(cherry picked from commit d6273a5934)
2020-03-24 21:30:59 +01:00
Benjamin Hipple
331f7b376a pythonPackages.flake8-future-import: 0.4.5 -> 0.4.6 and fix build
The build is currently broken on master and 20.03. This upgrades to the latest
version and also disables the bad py2 test. I spent a long time trying to figure
out what the issue is, but since it's disabled upstream on python3 anyways let's
just skip it on python2 as well.

ZHF: #80379
(cherry picked from commit e9979380cf325912ccbd2c945a7963d667f1b76d)
2020-03-24 10:23:48 -07:00
Mario Rodas
976fd6a592 Merge #82081: swiProlog: openssl 1.0.2 -> openssl 1.1
(cherry picked from commit ffad9c724f)
This is unbreaking the package.
2020-03-24 16:55:58 +01:00
Vladimír Čunát
6f87869e08 Merge #82728: racket: enable building on aarch64
(cherry picked from commit a533068c3e)
Build re-tested on 20.03.
2020-03-24 16:25:34 +01:00
Maximilian Bosch
cac363c661 prometheus-wireguard-exporter: 3.2.2 -> 3.2.4
https://github.com/MindFlavor/prometheus_wireguard_exporter/releases/tag/3.2.3
https://github.com/MindFlavor/prometheus_wireguard_exporter/releases/tag/3.2.4
(cherry picked from commit b79a474044)
2020-03-24 13:44:58 +01:00
worldofpeace
b85f4d0da7 pantheon.switchboard-with-plugs: fix wrapping
Since #81475 this caused the wrapper to be empty of entries from
wrapGAppsHook because the wrapGAppsHook function doesn't add
them anymore, and was moved to gappsWrapperArgsHook. Instead
of just running that in postBuild it's more future proof to make this
use stdenv.mkDerivation because we want to mess around with the
generic builder.

(cherry picked from commit a9e7e93311)
2020-03-24 03:14:02 -04:00
worldofpeace
1217a6c391 pantheon.wingpanel-with-indicators: fix wrapping
Since #81475 this caused the wrapper to be empty of entries from
wrapGAppsHook because the wrapGAppsHook function doesn't add
them anymore, and was moved to gappsWrapperArgsHook. Instead
of just running that in postBuild it's more future proof to make this
use stdenv.mkDerivation because we want to mess around with the
generic builder.

(cherry picked from commit db41c787f4)
2020-03-24 03:14:01 -04:00
Benjamin Hipple
4c77bcbd03 pythonPackages.mkl-service: 2.1.0 -> 2.3.0
Release notes: https://github.com/IntelPython/mkl-service/releases

(cherry picked from commit bd42541989bdf62428c7551c07a2cf04e1c05baa)
2020-03-23 19:27:33 -07:00
Aaron Andersen
c5ce98f83f nixos/mysql: test with mysql80 package
(cherry picked from commit 6c47902e01)
2020-03-23 20:13:55 -04:00
Aaron Andersen
e4067514ff nixos/mysql: fix service so it works with mysql80 package
(cherry picked from commit 3474b55614)
2020-03-23 20:13:48 -04:00
worldofpeace
017f050351 Merge pull request #83012 from bcdarwin/release-20.03
python38Packages.rope: disable for Python>=3.8
2020-03-23 17:29:46 -04:00
Graham Christensen
d76b379771 Merge pull request #82827 from danderson/release-20.03
tailscale: init at 0.97-0 [20.03 backport]
2020-03-23 17:11:31 -04:00
ajs124
905316df4a matrix-synapse: 1.11.1 -> 1.12.0
(cherry picked from commit 425efa54ef)
2020-03-23 21:44:28 +01:00
ajs124
fa02997264 python: Twisted: 19.10.0 -> 20.3.0
(cherry picked from commit dff1df7c21)
2020-03-23 21:44:27 +01:00
David Anderson
752d9766a1 tailscale: switch version and git ref to use a tag.
The tag points to the same commit hash, so the binary
is unchanged.

Signed-off-by: David Anderson <dave@natulte.net>
(cherry picked from commit 3fa813e820)
2020-03-23 12:47:51 -07:00
David Anderson
1fceda471b tailscale: 0.96-33 -> 0.97-0.
Fixes a severe bug with subnet routing.

Signed-off-by: David Anderson <dave@natulte.net>
(cherry picked from commit f61f686dfea53a0e5bb3faf0a5307dcc8f8d03aa)
2020-03-23 12:47:51 -07:00
Martin Baillie
6ce36ff037 tailscale: init at 0.96-33
Signed-off-by: Martin Baillie <martin@baillie.email>
(cherry picked from commit 6e055c9f4a)
2020-03-23 12:47:51 -07:00
Ben Darwin
bb81a6f037 python38Packages.rope: disable for Python>=3.8
- browsing the github page suggests the upcoming 0.17 release should support 3.8

(cherry picked from commit 3d0410e769)
2020-03-23 14:09:14 -04:00
Maximilian Bosch
f62e075744 cargo-make: 0.29.0 -> 0.30.0
https://github.com/sagiegurari/cargo-make/releases/tag/0.30.0
(cherry picked from commit 2c7299fc1c)
2020-03-23 18:55:26 +01:00
worldofpeace
fd11f3af1e Merge pull request #83184 from marcus7070/release-20.03
[20.03] python3Packages.spyder: add v3.x
2020-03-23 13:35:09 -04:00
Gabor Greif
add3780631 ghc-8.8.3: really use ld.gold (port #80466)
(cherry picked from commit ff6aeefb91)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-23 18:00:30 +01:00
Gabor Greif
4120ab34ce ghc: add 8.8.3
https://mail.haskell.org/pipermail/ghc-devs/2020-February/018643.html
(cherry picked from commit c8554c0574)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-23 18:00:30 +01:00
Vincent Laporte
155574f7e3 OCaml: do not depend on X11 for OCaml ≥ 4.09
(cherry picked from commit 80a7615300)
2020-03-23 17:23:00 +01:00
R. RyanTM
b2c79253b1 pantheon.elementary-music: 5.0.4 -> 5.0.5
(cherry picked from commit c7e617f683)
2020-03-23 11:31:19 -04:00
Matthew Bauer
1ee4f0e7cd Merge pull request #83204 from hamishmack/release-20.03
openssl: Fix openssl for musl [20.03 backport]
2020-03-23 10:52:35 -04:00
Hamish Mackenzie
6345a8c326 openssl: Fix openssl for musl [20.03 backport]
This is a backport of #82708
2020-03-23 23:24:50 +13:00
Christian Kögler
1a8cc0727d vdr-xineliboutput: 2.1.0 -> 2.2.0
(cherry picked from commit b7dad4977c)
2020-03-23 11:17:49 +01:00
Christian Kögler
2762ade637 vdr-xinelinboutput: fix pkg-config for opengl
Up to including nixos-19.09 configure fall back and included right
libraries. Since nixos-20.03 pkg-config returns a valid value for opengl, but
opengl misses glx symbols.

(cherry picked from commit d315b3d267)
2020-03-23 11:17:41 +01:00
Marcus Boyd
ee106b926e cq-editor: use spyder_3
(cherry picked from commit d8a7d1f665c0cba02cccd95fdc88f318c87c7979)
2020-03-23 16:17:02 +10:30
Marcus Boyd
c5f397f3db python3Packages.spyder_3: Added spyder_3
cq-editor currently requires spyder v3.x

(cherry picked from commit c5ceb64a5d5c90f3b411c824a762f34cf75c9fb3)
2020-03-23 16:16:56 +10:30
Marcus Boyd
088ae2c920 python3Packages.spyder-kernels: Add spyder-kernels_0_5
Previously top-level/python-packages.nix called spyder-kernels v0.5 for
Py2k. Now both v0.5 and v1.8 (default.nix) are in pythonPackages, as
required by cq-editor and spyder v4 respectively.
v0.5 also now comes from GitHub instead of PyPi, with checks enabled.

(cherry picked from commit a1f45198148197dbf2a460be17a7fb50686b1b4e)
2020-03-23 16:03:54 +10:30
Maximilian Bosch
67e523c519 xterm: 351 -> 353
https://invisible-island.net/xterm/xterm.log.html#xterm_353
(cherry picked from commit 72dca3638d)
2020-03-23 01:27:12 +01:00
Maximilian Bosch
f5455342d1 EmptyEpsilon: 2020.02.18 -> 2020.03.22
https://github.com/daid/EmptyEpsilon/releases/tag/EE-2020.03.22
(cherry picked from commit 049aede558)
2020-03-22 23:24:10 +01:00
Christian Kögler
db4300a4d7 kodi: fix lirc support
* adapted to the way kodi finds the lircd socket
* added lirc package to build support for lirc

(cherry picked from commit 8f12a72488)
2020-03-22 21:31:28 +01:00
Christian Kögler
bdd53db942 redo-apenwarr: 0.42 -> 0.42a; use python3 and fixed building manpage
Removed dependency to mkdoc, which is only needed to build the webpage.

(cherry picked from commit 4c9bd5d52a)
2020-03-22 21:23:59 +01:00
Maximilian Bosch
1d12859c0c fd: 7.4.0 -> 7.5.0
https://github.com/sharkdp/fd/releases/tag/v7.5.0
(cherry picked from commit 6c48c7b81f)
2020-03-22 19:56:41 +01:00
Dmitry Kalinkin
1332522e00 Merge pull request #82065 from veprbl/pr/glibc_prlimit64_20.03
[20.03] glibc: provide fallback for kernels with missing prlimit64
2020-03-22 14:23:58 -04:00
Greg Price
5b02b91f76 python39Full: fix to use Python 3.9 rather than 3.8
Looks like this was a typo when python39 was added in 648152fdb.

(cherry picked from commit c93acee712)
2020-03-22 18:16:40 +01:00
Graham Christensen
75b00dd838 Merge pull request #83147 from bhipple/bp/ami
[20.03] nixos-ami: update nvme_core.io_timeout for linux kernel >= 4.15
2020-03-22 12:56:56 -04:00
Benjamin Hipple
835366947c nixos-ami: update nvme_core.io_timeout for linux kernel >= 4.15
NixOS 20.03 is built on kernel 5.4 and 19.09 is on 4.19, so we should update
this option to the highest value possible, per linked upstream instructions from
Amazon.

(cherry picked from commit 129176452c)
2020-03-22 12:40:41 -04:00
Tim Steinbach
d847a4fe4c linux: 5.5.9 -> 5.5.11 2020-03-22 12:16:43 -04:00
Tim Steinbach
3c6a5be58c linux: 5.4.25 -> 5.4.27 2020-03-22 12:16:43 -04:00
Tim Steinbach
7ad61255e5 linux: 4.9.216 -> 4.9.217 2020-03-22 12:16:43 -04:00
Tim Steinbach
e00104da05 linux: 4.4.216 -> 4.4.217 2020-03-22 12:16:43 -04:00
Tim Steinbach
d91fc12cca linux: 4.19.109 -> 4.19.112 2020-03-22 12:16:43 -04:00
Tim Steinbach
dcdb46cfc5 linux: 4.14.173 -> 4.14.174 2020-03-22 12:16:43 -04:00
Maximilian Bosch
ec145bfbdd nixos/ssmtp: declare all option renames manually
While renaming `networking.defaultMailServer` directly to
`services.ssmtp` is shorter and probably clearer, it causes eval errors
due to the second rename (directDelivery -> enable) when using e.g. `lib.mkForce`.

For instance,

``` nix
{ lib, ... }: {
  networking.defaultMailServer = {
    hostName = "localhost";
    directDelivery = lib.mkForce true;
    domain = "example.org";
  };
}
```

would break with the following (rather confusing) error:

```
error: The option value `services.ssmtp.enable' in `/home/ma27/Projects/nixpkgs/nixos/modules/programs/ssmtp.nix' is not of type `boolean'.
(use '--show-trace' to show detailed location information)
```

(cherry picked from commit fc316f7b31)
2020-03-22 15:57:56 +01:00
rnhmjoj
d566176553 monero-gui: 0.15.0.1 -> 0.15.0.4
(cherry picked from commit 3c93f1ba96)
2020-03-22 10:23:04 +01:00
rnhmjoj
0e41c2c51d monero: use a compatible protobuf version
(cherry picked from commit ddabb09c35)
2020-03-22 10:23:04 +01:00
Vincent Laporte
fe67af81d2 ocamlPackages.parmap: 1.1 → 1.1.1
(cherry picked from commit a8dafd2731)
2020-03-22 07:04:52 +01:00
Sergey Lukjanov
df820c7da5 grafana: add Frostman to maintainers
(cherry picked from commit 9e98d47fb2)
2020-03-21 21:42:00 +01:00
Sergey Lukjanov
d5fff78b5b grafana: 6.7.0 -> 6.7.1
(cherry picked from commit bf453da8e8)
2020-03-21 21:42:00 +01:00
Sergey Lukjanov
8b42fbc4c0 grafana: 6.6.2 -> 6.7.0
(cherry picked from commit 913e6b5c7b)
2020-03-21 21:42:00 +01:00
R. RyanTM
b323c010d7 darktable: 3.0.0 -> 3.0.1
(cherry picked from commit eb3690c462)
2020-03-21 13:08:35 +01:00
Timo Kaufmann
359934fe0b Merge pull request #82415 from timokau/symmetrica-3.0.1-20.03
[20.03] symmetrica: 2.0 -> 3.0.1
2020-03-21 11:45:59 +00:00
Michele Guerini Rocco
167492500b Merge pull request #82758 from wd15/fastapi-0.49.0
[20.03] python37Packages.fastapi: 0.45.0 -> 0.49.0
2020-03-21 10:41:01 +01:00
Maximilian Bosch
1ec2cf2168 gitea: 1.10.3 -> 1.11.3
Updates `gitea` to the latest version available[1]. Also ensured that
upgrading from `gitea-1.9` (used on NixOS 19.09) to `1.11.3` works
seamlessly.

The derivation required a few more changes this time since `gitea` uses
`npm` now to build the frontend[2]. When using the default tarball from
GitHub, we'd have to build the frontend manually. By fetching a custom
tarball published on every release, we get a prebuilt frontend
(as it was the case on previous versions) and build the backend only from
source.

Co-authored-by: kolaente <k@knt.li>
Closes #80175

[1] https://github.com/go-gitea/gitea/releases/tag/v1.11.3
[2] https://github.com/go-gitea/gitea/issues/10253

(cherry picked from commit cbceee8e97)
2020-03-20 23:08:49 +01:00
Maximilian Bosch
af477bc4ce neomutt: 20200313 -> 20200320
https://github.com/neomutt/neomutt/releases/tag/20200320
(cherry picked from commit 78104ad2da)
2020-03-20 15:08:48 +01:00
Eelco Dolstra
81fa5f4501 nixos-option: Disable on Nix >= 2.4 because it doesn't compile
This is needed when using the overlay from the Nix flake.

(cherry picked from commit a0a61c3e34)
2020-03-20 14:55:26 +01:00
Vincent Laporte
4362edf3c3 ocamlPackages.camlp5: 7.10 → 7.11
(cherry picked from commit 8dddd8a07f)
2020-03-20 09:10:55 +01:00
Maximilian Bosch
1494f8753a wireguard-tools: 1.0.20200206 -> 1.0.20200319
https://lists.zx2c4.com/pipermail/wireguard/2020-March/005191.html
(cherry picked from commit 19ceeb6de0)
2020-03-20 00:54:28 +01:00
Jan Tojnar
e8701fe486 flatpak: remove malcontent
It is not ready yet.

See: https://github.com/NixOS/nixpkgs/issues/81284
2020-03-20 00:21:10 +01:00
Aaron Andersen
97f65b2de9 Merge pull request #82848 from aanderse/zhf/rsyslog
rsyslog: remove libksi from default build because it is broken [20.03 backport]
2020-03-19 19:07:48 -04:00
Maximilian Bosch
25d8140287 thefuck: 3.29 -> 3.30
https://github.com/nvbn/thefuck/releases/tag/3.30
(cherry picked from commit b51d4e588d)
2020-03-19 21:29:47 +01:00
Michael Weiss
b3ee6e46df chromium: 80.0.3987.132 -> 80.0.3987.149
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html

This update includes 13 security fixes.

CVEs:
CVE-2020-6422 CVE-2020-6424 CVE-2020-6425 CVE-2020-6426 CVE-2020-6427
CVE-2020-6428 CVE-2020-6429 CVE-2019-20503 CVE-2020-6449

Note: The release of version 81 is currently on pause:
https://chromereleases.googleblog.com/2020/03/upcoming-chrome-and-chrome-os-releases.html
(cherry picked from commit fe60ff7a99)
Backport of #82874.
2020-03-19 20:24:35 +01:00
Jonathan Ringer
d1121dfa8c texworks: fix qt build
(cherry picked from commit aaefb947ea)
2020-03-19 12:07:27 -07:00
Maximilian Bosch
6c90920c93 cargo-make: 0.27.0 -> 0.29.0
https://github.com/sagiegurari/cargo-make/releases/tag/0.28.0
https://github.com/sagiegurari/cargo-make/releases/tag/0.29.0
(cherry picked from commit 29b495d4d7)
2020-03-19 18:28:35 +01:00
John Ericson
b41d1d9167 Merge pull request #82943 from obsidiansystems/armv6-embedded
Armv6 embedded
2020-03-19 13:13:51 -04:00
Florian Klink
e26bc8445a nixos/zerotierone: switch from manually generating the .link file to use the module
Previously, systemd.network.links was only respected with networkd
enabled, but it's really udev taking care of links, no matter if
networkd is enabled or not.

With our module fixed, there's no need to manually manage the text file
anymore.

This was originally applied in 3d1079a20d,
but was reverted due to 1115959a8d causing
evaluation errors on hydra.

(cherry picked from commit 4e53f84c79)
2020-03-19 15:33:32 +01:00
Florian Klink
c4611d8f20 nixos/networkd: respect systemd.network.links also with disabled systemd-networkd
This mirrors the behaviour of systemd - It's udev that parses `.link`
files, not `systemd-networkd`.

This was originally applied in 36ef112a47,
but was reverted due to 1115959a8d causing
evaluation errors on hydra.

(cherry picked from commit 355c58e485)

nixos/manual: fix build

(cherry picked from commit d96bd3394b)
2020-03-19 15:33:24 +01:00
Jörg Thalheim
82ab717ea0 Merge pull request #82896 from JeffLabonte/20_03_backport-protonvpn-cli-ng
[20.03] backport protonvpn cli ng 2.2.0 -> 2.2.2
2020-03-19 12:12:04 +00:00
Robert Hensing
d6e406ddae Merge pull request #82933 from hercules-ci/backport-20.03-82897
lib/options: Only recurse into visible sub options (backport to 20.03)
2020-03-19 11:48:18 +01:00
Silvan Mosberger
970ea9616f lib/options: Only recurse into visible sub options
(cherry picked from commit f195625227)
2020-03-19 11:27:17 +01:00
Maximilian Bosch
b2935fbece linuxPackages.wireguard: 0.0.20200215 -> 0.0.20200318
https://lists.zx2c4.com/pipermail/wireguard/2020-March/005188.html
(cherry picked from commit e758e95c1d)
2020-03-19 09:32:34 +01:00
LeshaInc
d0357c141c blender: build with OpenImageDenoise support
(cherry picked from commit 3c54b996ca)
2020-03-19 00:30:37 -04:00
LeshaInc
0984610c0c openimagedenoise: init at 1.1.0
(cherry picked from commit 2cc3a34d4a)
2020-03-19 00:30:12 -04:00
R. RyanTM
a02a11f739 blender: 2.82 -> 2.82a (#82450)
(cherry picked from commit 4d8cac34f7)
2020-03-19 00:29:26 -04:00
Jeff Labonte
294fd3c0f5 brave: 1.4.96 -> 1.5.112
Keep brave updated to the latest release

(cherry picked from commit 418e3e41cf22753911c5f474d8bd89252ec76ce0)
Reasons: Keep the browser up-to-date as much as possible.
2020-03-18 20:10:25 -07:00
Jeff Labonte
71d2a85a70 protonvpn-cli-ng: 2.2.0 -> 2.2.2
Simply keep up to date the cli since it is used to connect to a VPN.

(cherry picked from commit eb96574e9df3aba387c4abe902b154398271becf)
Reason: A tool to communicate with a VPN provider should be kept
up-to-date
2020-03-18 20:16:30 -04:00
Benno Fünfstück
c5a9ee84cb nixos/release-combined.nix: fix tested for aarch64
This removes tests from the tested aggregate on aarch64 which are not
available for that platform.
2020-03-18 22:36:49 +01:00
Christoph Bauer
6bbdce2b15 pwsafe -> 1.9.0
fixes the broken build
there is a problem with wxGTK 3.1.2
maybe related to
https://github.com/pwsafe/pwsafe/blob/master/src/ui/wxWidgets/TreeCtrl.cpp
line 107
So I use wxGTK30

file is a new depedency

(cherry picked from commit 0b2047d712)
2020-03-18 21:25:55 +00:00
John Ericson
7562a06e85 Merge pull request #82248 from Ericson2314/fetchsvn-cross
fetchsvn: Fix for cross
2020-03-18 17:15:41 -04:00
Benno Fünfstück
6d73360a89 nixos/release-combined.nix: fix eval for aarch64
The release-20.03-aarch64 jobset on hydra only evals for aarch64, so the
x86_64 jobs do not exists. We need to make sure that the tested job only
aggregates jobs that actually exist.

This commit solves the issue by generating the tested job constituents
names based on the supported systems.
2020-03-18 21:44:32 +01:00
Aaron Andersen
96e221d6db rsyslog: remove libksi from default build because it is broken
(cherry picked from commit bdd33bc3aa)
2020-03-18 08:26:18 -04:00
Eelco Dolstra
16dd1df081 Merge pull request #82333 from edolstra/fix-lcov
Backport lcov fixes to 20.03
2020-03-18 11:57:13 +01:00
Dennis Gosnell
e2dfbcd4fd Merge pull request #82780 from erictapen/nixos-20.03-binary-strict
[20.03] haskellPackages.binary-strict: 0.4.8.4 -> 0.4.8.5
2020-03-18 11:18:37 +09:00
Vladislav Zavialov
af1b8e409d toggldesktop: use mkDerivation from Qt (#81720)
(cherry picked from commit bfcb19197b)
2020-03-17 22:08:19 -04:00
Dmitry Kalinkin
20fb1ce97c kicad: don't build versions with 3d on Hydra
The hydraPlatforms have to be set on the kicad package itself, that can be
checked using:

  echo ":p { inherit kicad kicad-small kicad-unstable; }" | nix repl ./pkgs/top-level/release.nix

This commit disables build of all kicad variants that require downloading
packages3d, which currently fail on hydra with the "Output limit exceeded"
status. This leaves Hydra with only building the kicad-small, which will allow
us to cache the build of kicad-base as well as all libraries except of
packages3d.

(cherry picked from commit ebe5f10794)
2020-03-17 18:52:51 -04:00
Dmitry Kalinkin
d9bb3a3711 Merge remote-tracking branch 'origin/release-20.03' into staging-20.03 2020-03-17 17:15:28 -04:00
Dmitry Kalinkin
ec0923f983 Merge pull request #82676 from veprbl/pr/texlive_2019_final_20.03
[20.03] texlive: 2019 -> 2019-final
2020-03-17 17:10:57 -04:00
mehlon
1a7a473831 tor-browser-bundle-bin: 9.0.5 -> 9.0.6
(cherry picked from commit 4b80e8a59f)
2020-03-17 18:00:23 +01:00
Maximilian Bosch
c55a47832d riot-web: 1.5.12 -> 1.5.13
(cherry picked from commit 09f55f8f17)
2020-03-17 16:13:41 +01:00
Maximilian Bosch
4e245c8fe7 riot-desktop: 1.5.12 -> 1.5.13
(cherry picked from commit bb9822be79)
2020-03-17 16:13:41 +01:00
Robert Hensing
a9c8e5bb18 Merge pull request #82782 from hercules-ci/backport-20.03-81292-fix-service-runner-quotes
Backport to 20.03 pr 81292: fix service runner quotes
2020-03-17 15:53:33 +01:00
Robert Hensing
284a8e95f7 nixos/service-runner.nix: Allow quotes in commands + test
(cherry picked from commit 43521ac965)
2020-03-17 15:16:32 +01:00
Justin Humm
8583ad1425 haskellPackages.binary-strict: 0.4.8.4 -> 0.4.8.5
This fixes the build, also of

- eths-rlp
- vorbiscomment
- webify

which depend on binary-strict. Everything else that depends on
binary-strict remains broken, so this commit shouldn't break anything
that wasn't broken yet.
2020-03-17 14:43:28 +01:00
Vladimír Čunát
9cc7ab153c Revert "tests/networking: remove pkgs.lib usages."
This reverts commit cde800dbd7.  See:
https://github.com/NixOS/nixpkgs/pull/82310#issuecomment-598920297
2020-03-17 09:02:03 +01:00
Vladimír Čunát
2a9c405b7e Revert "nixos/zerotierone: switch from manually generating..."
This reverts commit f549fbfd97.  See:
https://github.com/NixOS/nixpkgs/pull/82310#issuecomment-598920297
2020-03-17 08:49:22 +01:00
Vladimír Čunát
de1c9c0453 Revert "nixos/networkd: respect systemd.network.links [...]"
This reverts commit 4b2151b9fa.  See:
https://github.com/NixOS/nixpkgs/pull/82310#issuecomment-598920297
2020-03-17 08:35:47 +01:00
Dennis Gosnell
a8ec4936ae Merge pull request #82703 from erictapen/nixos-20.03-hakyll-contrib-hyphenation-jailbreak
[nixos-20.03] haskellPackages.hakyll-contrib-hyphenation: jailbreak
2020-03-17 09:54:09 +09:00
Aaron Andersen
b3f89ad996 Merge pull request #82761 from aanderse/tomcat
tomcat: 7.0.92 -> 7.0.100, 8.5.42 -> 8.5.51, 9.0.21 -> 9.0.31 [20.03 backport]
2020-03-16 20:16:53 -04:00
Aaron Andersen
a27e86399c tomcat9: 9.0.21 -> 9.0.31
(cherry picked from commit 46e7580f24)
2020-03-16 20:05:28 -04:00
Aaron Andersen
26a5a71da5 tomcat8: 8.5.42 -> 8.5.51
(cherry picked from commit 22f24f7859)
2020-03-16 20:04:59 -04:00
Aaron Andersen
0dde8f4c5f tomcat7: 7.0.92 -> 7.0.100
(cherry picked from commit 78b0222cb2)
2020-03-16 20:04:45 -04:00
Dmitry Kalinkin
ff2febd334 nuweb: fix after texlive update
(cherry picked from commit 2217b1d77c)
2020-03-16 18:11:28 -04:00
Daniel Wheeler
55fee4d66f python37Packages.fastapi: 0.45.0 -> 0.49.0
- Add peewee to test environment as now required.

 - Remove pyproject.toml patching as no longer required.
2020-03-16 17:53:32 -04:00
Daniel Wheeler
9d99c49138 python37Packages.starlette: 0.13.0 -> 0.12.9
- Reverting the version of Starlette as FastAPI can not use anything
   greater than 0.12.12. FastAPI is Starlette's only dependent.

 - Use fetchurl instead of fetchPypi as this is now the preferred
   method. This also makes the tests pass and, thus, the build, which
   was failing.
2020-03-16 17:53:32 -04:00
Justin Humm
4a36d2d862 haskellPackages.hakyll-contrib-hyphenation: jailbreak
Latest upstream commit is from 2015 [0], so I guess it's the easiest to
jailbreak it (as it builds that way).

[0] https://bitbucket.org/rvlm/hakyll-contrib-hyphenation/src/master/
2020-03-16 21:57:45 +01:00
Sander van der Burg
db52e1a7f2 base16-builder: regenerate with node2nix 1.8.0 and add supplement.json to fix build 2020-03-16 21:22:47 +01:00
Sander van der Burg
ba3ef05e92 nodePackages: regenerate with node2nix 1.8.0 2020-03-16 21:15:53 +01:00
Martin Milata
feb386f6eb libxml2: add patch for CVE-2019-20388
(cherry picked from commit 291c73568a)
/cc roundup #79725
2020-03-16 19:44:29 +01:00
Vladimír Čunát
10debb86b7 Merge branch 'staging-20.03' into release-20.03 2020-03-16 19:38:24 +01:00
Robert Hensing
db75eb4257 Merge pull request #82741 from hercules-ci/backport-20.03-80102
dockerTools.buildLayeredImage: store all paths passed in final layer (backport)
2020-03-16 19:07:13 +01:00
Richard Wallace
3781ac873f dockerTools.buildLayeredImage: store all paths passed in final layer
Fixes #78744

My previous change broke when there are more packages than the maximum
number of layers. I had assumed that the `store-path-to-layer.sh` was
only ever passed a single store path, but that is not the case if
there are multiple packages going into the final layer. To fix this, we
loop through the paths going into the final layer, appending them to the
tar file and making sure they end up at the right path.
2020-03-16 18:43:26 +01:00
Matteo Scarlata
27eca64552 unison: fix build with ocamlPackages_4_09 (#82619)
Fixes #61867 and #61505, bumps the ocaml version unison is built
against to 4.08. The patches included here appear in the trunk version
of unison, but were not backported to 2.51.2.

(cherry picked from commit 3355e8d1ca)
2020-03-16 13:17:29 +01:00
Maximilian Bosch
23139ff62f nixos/doc/matrix-synapse: refactor
* Linkify all service options used in the code-examples.
* Demonstrated the use of `riot-web.override {}`.
* Moved the example how to configure a postgresql-database for
  `matrix-synapse` to this document from the 20.03 release-notes.

(cherry picked from commit 849e16888f)
2020-03-16 11:01:55 +01:00
Maximilian Bosch
ba6271a49c matrix-synapse: 1.9.1 -> 1.11.1
https://github.com/matrix-org/synapse/releases/tag/v1.10.0
https://github.com/matrix-org/synapse/releases/tag/v1.10.1
https://github.com/matrix-org/synapse/releases/tag/v1.11.0
https://github.com/matrix-org/synapse/releases/tag/v1.11.1
(cherry picked from commit 8be61f7a36)
2020-03-16 11:01:53 +01:00
Maximilian Bosch
7f8e302fb6 python3Packages.signedjson: 1.0.0 -> 1.1.0
(cherry picked from commit 500375e338)
2020-03-16 11:01:04 +01:00
Vladimír Čunát
c09c926ee8 bind: 9.14.10 -> 9.14.11 (small bugfix)
I see just a single small bugfix in the news:
https://downloads.isc.org/isc/bind9/9.14.11/RELEASE-NOTES-bind-9.14.11.html

(cherry picked from commit 47f61c9d7f)
2020-03-16 09:18:23 +01:00
Florian Klink
2acb89d120 Merge pull request #82061 from tokudan/20.03/nextcloud1801
[20.03] nextcloud: 18.0.0 -> 18.0.2 [security]
2020-03-16 00:22:41 +01:00
Matteo Scarlata
006b4b1a4a virtualbox: 6.0.14 -> 6.1.4
Update Virtualbox to its latest version. This allows compilation against
kernel >= 5.4 to succeed without further patches (see #74260, build
would fail for linux-5.5.5 to 5.5.9).

(cherry picked from commit 3132c237b181244f3c5d128e5195f538ddffb38e)
2020-03-15 23:28:24 +01:00
Maximilian Bosch
aa481358c6 aircrack-ng: 1.5.2 -> 1.6
(cherry picked from commit 9729f30667)
2020-03-15 22:35:34 +01:00
Dmitry Kalinkin
3d1fdac251 texlive: use versioned tarballs
Announced in [1], versioned tarballs allow to make sure that a
specific version is fetched. This does not guarantee that all previous
versions are retained on the main mirrors.

Logically, we would want to first try to download versioned tarballs
from any mirror and only then try the unversioned ones. But right now
we only have two mirrors and only some of the tarballs are versioned
in texlive-2019, so the order is changed to not hammer the weak
tug.org mirror.

[1] https://tug.org/pipermail/tex-live/2019-September/044086.html

(cherry picked from commit 9f44a61f39)
2020-03-15 15:14:35 -04:00
Dmitry Kalinkin
53e3bc5d92 texlive/pkgs.nix: add revision
(cherry picked from commit 9c4212cb9f)
2020-03-15 15:14:35 -04:00
Dmitry Kalinkin
08aec1877e texlive: 2019 -> 2019-final
The biber package is now at 2.14, but TextBibTeX is still required.

Few changes were needed for newly introduced scripts-extra path. This
broke some of our old tricks which were relying on having writable
script directories. The changes to the script locations made buildEnv
create symlinks to the script directories instead of directories of
symlinks to scripts. The changes to texlinks.sh and texlive/TeXLive
perl path were made because of this.

(cherry picked from commit 9752593eb0)
2020-03-15 15:14:34 -04:00
Dmitry Kalinkin
65613ec2bf texlive: reimplement fixHashes.sh in GNU Awk
The shell script doesn't work very well in non-GNU environments like
darwin. This provides an implementation that uses just a single GNU tool
- gawk, thus reduces number of points of failure.

(cherry picked from commit d9fb53ddd6)
2020-03-15 15:14:34 -04:00
Timo Kaufmann
960f849545 Merge pull request #82648 from timokau/retdec-fix-20.03
[20.03] retdec: fix build
2020-03-15 13:58:57 +00:00
Léo Gaspard
a4bf572a9f xfce4-12: remove alias
(cherry picked from commit 175f9ef4f8)
2020-03-15 12:01:21 +01:00
Timo Kaufmann
13f4c4a0bf retdec: fix build
The build was broken by the gcc9 update. Pinning to gcc8 for now.

(cherry picked from commit e5642d405e)
2020-03-15 12:00:57 +01:00
Martin Milata
2dab4c10c4 lz4: 1.9.1 -> 1.9.2 (PR #82437)
Fixes: https://nvd.nist.gov/vuln/detail/CVE-2019-17543
Release notes: https://github.com/lz4/lz4/releases/tag/v1.9.2

(cherry picked from commit 18ac6ba903)
2020-03-15 09:53:29 +01:00
Martin Milata
d32805ec33 libssh: 0.8.7 -> 0.8.8
Fixes CVE-2019-14889, issue #77264.
Release notes: https://www.libssh.org/2019/12/10/libssh-0-9-3-and-libssh-0-8-8-security-release/

(cherry picked from commit 7ef8a42ab2)
2020-03-15 09:37:00 +01:00
David Guibert
a2a2fae53b users.groups.disnix instead of a list
related to #63103.

(cherry picked from commit bbc2cd89ef)
2020-03-14 23:18:01 +01:00
Josef Kemetmüller
c2e347cfc4 python37Packages.vtk: Fix build (#82336)
(cherry picked from commit de36c3b073)
2020-03-14 14:13:49 -04:00
Martin Milata
137bac6f24 openjpeg: add patch for CVE-2020-8112
(cherry picked from commit 41d8bb133efeade8d25a634ca68c32f0f62f6a41)
2020-03-14 16:57:04 +00:00
Martin Milata
021d5b650e openjpeg: add patch for CVE-2020-6851
(cherry picked from commit 773462c3aacdd2eb50457c7949dae6dd91e3684d)
2020-03-14 16:57:04 +00:00
Tim Steinbach
caabb48cf5 linux: 5.4.24 -> 5.4.25 2020-03-14 05:05:13 -04:00
taku0
cdbeba4c51 thunderbird-bin: 68.5.0 -> 68.6.0
(cherry picked from commit 833031704d)
2020-03-14 03:43:01 +00:00
taku0
ad6461d0bc thunderbird: 68.5.0 -> 68.6.0
(cherry picked from commit 243cd9f754)
2020-03-14 03:43:01 +00:00
Maximilian Bosch
8ff2a03284 binaryen: 89 -> 91, emscripten: 1.38.28 -> 1.39.1
(cherry picked from commit 386a50f729)
2020-03-14 02:42:01 +01:00
Christine Dodrill
aa61e722b0 development/libraries/libdap: fix hash 2020-03-13 20:49:48 -04:00
Christine Dodrill
f5c2ed464f tools/security/b3sum: fix cargo hash 2020-03-13 20:02:40 -04:00
Mario Rodas
d793073f41 Merge pull request #82448 from bhipple/bp/bluez
[20.03][Security] bluez: 5.52 -> 5.53 for CVE-2020-0556
2020-03-13 18:54:22 -05:00
Ben Darwin
bc3a69760d ocamlPackages_latest.phylogenetics: dune2/fix meta
(cherry picked from commit fd9b40d076)

cc #81160
2020-03-13 18:53:08 -04:00
Vincent Laporte
6626072bc5 OCaml: default to version 4.08
(cherry picked from commit 7b33cbdbf5)
2020-03-13 22:51:39 +01:00
Vincent Laporte
423e25aa9c ocamlPackages.earley: disable for OCaml ≥ 4.08
(cherry picked from commit bdcba83153)
2020-03-13 22:51:39 +01:00
Vincent Laporte
b23eec8994 ocamlPackages.earlybird: disable for OCaml ≥ 4.08
(cherry picked from commit 4ada24a02c)
2020-03-13 22:51:39 +01:00
Vincent Laporte
cc9c739ab0 ocamlPackages.ocf: disable for OCaml ≥ 4.08
(cherry picked from commit 4ce4db473c)
2020-03-13 22:51:39 +01:00
Vincent Laporte
dc38fbc680 ocamlPackages.wasm: disable for OCaml ≥ 4.08
(cherry picked from commit bab3588e4e)
2020-03-13 22:51:39 +01:00
Vincent Laporte
748e8893e3 unison: move out of ocamlPackages
(cherry picked from commit 4adfbe6c7b)
2020-03-13 22:42:05 +01:00
Vincent Laporte
70d505b900 ocamlPackages.sedlex_2: fix build with OCaml ≥ 4.08
(cherry picked from commit e73a9e6b95)
2020-03-13 22:32:12 +01:00
Maximilian Bosch
e60df57174 Merge pull request #82470 from Mindavi/backport/afl-glibc-bugfix
afl: Fix afl-qemu build by applying patches for glibc-2.30
2020-03-13 21:39:09 +01:00
Maximilian Bosch
24bf8b393f wikicurses: install man pages
(cherry picked from commit 04ea9dc275)
2020-03-13 21:15:59 +01:00
Maximilian Bosch
bebc254a95 wikicurses: fix build
The package doesn't have a testsuite, but fails as the checkPhase is
missing appropriate locale configuration (usually taken from
`pkgs.glibcLocales`). Entirely disabling the `checkPhase` for now as
it's basically a no-op.

ZHF: #80379
See also https://hydra.nixos.org/build/114125176

(cherry picked from commit 1505633e2f)
2020-03-13 21:15:59 +01:00
Maximilian Bosch
ca1b7ea9c1 ipfs: 0.4.22 -> 0.4.23
(cherry picked from commit c882314075)
2020-03-13 21:15:59 +01:00
Maximilian Bosch
60a1fdebfd inotify-tools: 3.20.1 -> 3.20.2.2
(cherry picked from commit 69d7cc5508)
2020-03-13 21:15:58 +01:00
Daniel Frank
3d0dcfebdf Nextcloud: 18.0.1 -> 18.0.2
(cherry picked from commit c4aadbca1417fc3d1d82b2a2db2beba258fd77c6)
2020-03-13 20:43:52 +01:00
Maximilian Bosch
295a1a03ca neomutt: 20191207 -> 20200313
https://github.com/neomutt/neomutt/releases/tag/20200313
(cherry picked from commit dda6dfed26)
2020-03-13 16:57:29 +01:00
Benjamin Hipple
0fc28d7b31 bluez: 5.52 -> 5.53 for CVE-2020-0556
See here for details:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00352.html

(cherry picked from commit 8f8b6459e9f38bc21df4976265f96b4541b917ec)
2020-03-13 10:54:35 -04:00
Mario Rodas
deb92e7672 Merge pull request #82485 from helsinki-systems/bp-bump-libksi
[20.03] libksi: Bump openssl dependency for rsyslogd
2020-03-13 09:21:57 -05:00
Janne Heß
1ac1caf6c7 libksi: Bump openssl dependency for rsyslogd
(cherry picked from commit fdccb96eeae1d5c0bab3ebfb5c99c794670628df)
2020-03-13 13:11:59 +01:00
Rick van Schijndel
e6c68edbde afl: Fix afl-qemu build by applying new patches
These patches are gathered from different sources,
such as https://patchwork.kernel.org/patch/10862231/ for the
`gettid` patch.
Another patch comes from the issue in the AFL repository.
The ultimate goal is to get these patches upstream as well,
so we don't keep these general patches only within nixos.

A PR is created against Google/AFL
https://github.com/google/AFL/pull/79,
but it might take a while before it's landed, considering the history
of the project (there are more PRs open).

ZHF: #80379

Fixes issue #82232
2020-03-13 09:45:33 +01:00
R. RyanTM
a0adbb1bdb libarchive: 3.4.1 -> 3.4.2
Fixes CVE-2020-9308.

(cherry picked from commit 13a03f402c)
2020-03-12 20:44:26 +00:00
Timo Kaufmann
04f75b1739 symmetrica: 2.0 -> 3.0.1
This switches to the sagemath fork, since the original upstream is no
longer maintained and sagemath has effectively maintained symmetrica
through patches for a while now. The update fixes one bug in particular
that has caused failures in the sagemath test suite:

https://github.com/NixOS/nixpkgs/issues/81449
https://trac.sagemath.org/ticket/15312
https://trac.sagemath.org/ticket/29061

Regarding the licensing change:

7cf91b3800
(cherry picked from commit 0c875c28c6)
2020-03-12 16:35:29 +01:00
adisbladis
3bf5bf6dd0 Merge pull request #82403 from eyJhb/flexget-transmission-release2003
[backport 20.03] flexget: readd transmissionrpc
2020-03-12 13:08:33 +00:00
Florian Klink
9827729ebd Merge pull request #82375 from flokli/20.03-gitlab-12.8.6
[20.03] gitlab 12.8.5 -> 12.8.6
2020-03-12 06:02:04 -07:00
eyjhbb@gmail.com
71a0ae43f0 flexget: readd transmissionrpc
(cherry picked from commit f88cd71e96)
2020-03-12 13:58:02 +01:00
Florian Klink
94767b4432 gitaly: 12.8.5 -> 12.8.6
(cherry picked from commit 281bd03242)
2020-03-12 12:54:56 +01:00
Frederik Rietdijk
1659274588 bepasty: use correct version of xstatic-bootstrap
(cherry picked from commit 73fa45693c)
2020-03-12 11:21:00 +01:00
Daniel Frank
fa88f6a526 firefox-bin: 73.0 -> 74.0 (from PR #82257)
(cherry picked from commit 8899c72990)
Brief testing showed no issues.
2020-03-12 11:20:14 +01:00
Tim Steinbach
d4544ed681 linux: 5.5.8 -> 5.5.9 2020-03-12 05:59:29 -04:00
Tim Steinbach
56dcf4f368 linux: 4.9.215 -> 4.9.216 2020-03-12 05:59:29 -04:00
Tim Steinbach
c44be3bbb3 linux: 4.4.215 -> 4.4.216 2020-03-12 05:59:28 -04:00
Tim Steinbach
580138d913 linux: 4.19.108 -> 4.19.109 2020-03-12 05:59:28 -04:00
Tim Steinbach
098e5a78d9 linux: 4.14.172 -> 4.14.173 2020-03-12 05:59:27 -04:00
Andreas Rammhold
730453919b Merge #82275: firefox-esr-68: 68.5.0esr -> 68.6.0esr
(cherry picked from commit fd04c3afbb)
It contains some "high impact" security fixes; announcement:
https://www.mozilla.org/en-US/firefox/68.6.0/releasenotes/

Brief testing on 20.03 shows no issues for me.
2020-03-12 10:39:44 +01:00
Vincent Laporte
5fe81d4a27 ocaml-ng.ocamlPackages_4_10.ocaml: 4.10.0+rc2 → 4.10.0
(cherry picked from commit 3fe7a65e23)
2020-03-12 06:47:38 +01:00
Vincent Laporte
14aacd5e72 ocaml-ng.ocamlPackages_4_10.ocaml: 4.10.0+rc1 → 4.10.0+rc2
(cherry picked from commit ca6391a7c4)
2020-03-12 06:47:38 +01:00
Vincent Laporte
a0deb2010e ocaml-ng.ocamlPackages_4_10.ocaml: 4.10.0+β2 → 4.10.0+rc1
(cherry picked from commit eef4b5175f)
2020-03-12 06:47:38 +01:00
Florian Klink
1df0c691b9 gitlab: 12.8.5 -> 12.8.6
https://about.gitlab.com/releases/2020/03/11/critical-security-release-gitlab-12-dot-8-dot-6-released/
(cherry picked from commit ab3b836350)
2020-03-12 03:06:35 +01:00
Florian Klink
988169988e gitlab: update script: unset GOROOT
or vgo2nix might not be able to resolve some dependencies.

(cherry picked from commit d2061f024c)
2020-03-12 03:06:34 +01:00
devhell
2ba4461001 tests: Fix signal-desktop
This test fails due to OOM on the VM. Setting the memory of the VM to
1024 lets the test succeed.

Cc: @flokli
(cherry picked from commit 534f1337c1)
2020-03-12 01:53:34 +01:00
Benjamin Hipple
fb783f0501 rainicorn: remove broken package that has been abandoned upstream
(cherry picked from commit 9326cd34062c9f58b95ac7306df2c42382dbee78)
2020-03-12 00:36:54 +00:00
Benjamin Hipple
a3c82719c3 leftwm: 0.1.10 -> 0.2.2 (#82365)
(cherry picked from commit feb9b1b406833f9dafee3aa8072b533f90e22973)
2020-03-12 00:29:18 +00:00
Benjamin Hipple
a14b7859a1 [20.03] Mark git-dit as broken
(cherry picked from commit f908cf4de86f5db899e73f0062d6351934245731)
2020-03-12 00:22:17 +00:00
nyanloutre
f6b7dc6fef nixos/vsftpd: fix missing default pam_service_name
9458ec4 removed the ftp pam service which was used by default by vsftpd

(cherry picked from commit 7ab00c48d8)
2020-03-11 22:30:13 +00:00
talyz
8d243e1ff5 nixos/haproxy: Revive the haproxy user and group
Running haproxy with "DynamicUser = true" doesn't really work, since
it prohibits specifying a TLS certificate bundle with limited
permissions. This revives the haproxy user and group, but makes them
dynamically allocated by NixOS, rather than statically allocated. It
also adds options to specify which user and group haproxy runs as.

(cherry picked from commit bb7ad853fb)
2020-03-11 22:25:26 +00:00
Maximilian Bosch
4a3c691beb treewide: remove myself from a few packages I don't use anymore
(cherry picked from commit b7cdb64ac2)
2020-03-11 23:07:05 +01:00
Maximilian Bosch
16d052df1f python3Packages.tesseract: 0.3.2 -> 0.3.3
(cherry picked from commit 24b6b8fd46)
2020-03-11 23:06:34 +01:00
Elis Hirwing
b15139179f php72: 7.2.27 -> 7.2.28
Changelog: https://www.php.net/ChangeLog-7.php#7.2.28
(cherry picked from commit 5bf47ab9bb)
2020-03-11 21:18:21 +01:00
Elis Hirwing
b53b0a01d6 php73: 7.3.14 -> 7.3.15
Changelog: https://www.php.net/ChangeLog-7.php#7.3.15
(cherry picked from commit 8f4cb37116)
2020-03-11 21:18:04 +01:00
Maximilian Bosch
1937173092 Merge pull request #81744 from Ma27/backport-remaining-initrd-fix
[20.03] nixos/initrd-network: always run postCommands
2020-03-11 21:05:44 +01:00
Martin Milata
0759da4ee6 nixos: fix module paths in rename.nix
(cherry picked from commit d08ede042b)
2020-03-11 19:36:16 +01:00
Josef Kemetmüller
bc0586b7be lcov: Fix patch checksums
The previously committed checksums seem to have been mistakenly taken
directly from fetchurl without fetchpatch normalization.

(cherry picked from commit adfb8a039b)
2020-03-11 18:41:14 +01:00
Eelco Dolstra
4f721661b2 lcov: Support gcc 9
https://github.com/linux-test-project/lcov/issues/58
https://github.com/Homebrew/homebrew-core/pull/50070
(cherry picked from commit 74c82056c9)
2020-03-11 18:37:36 +01:00
Cyril Cohen
c07561faec coqPackages.hierarchy-builder: init at 0.9.0
(cherry picked from commit cf210c082d)
2020-03-11 17:19:43 +01:00
Cyril Cohen
7c4a7a78ff elpi: 1.7.0 -> 1.10.2; coq-elpi: 1.1 -> 1.3
(cherry picked from commit 66a7f5d4e2)
2020-03-11 17:19:34 +01:00
Maximilian Bosch
2d149fcaf3 Merge pull request #82152 from fadenb/20.03_graylog
[20.03] graylog: 3.2.0 -> 3.2.2
2020-03-11 15:58:02 +01:00
Cole Mickens
42df26245c cfdyndns: v0.0.1 -> v0.0.3
(cherry picked from commit 669fdccf8b)
2020-03-10 14:43:05 -07:00
Sarah Brofeldt
fede49f5e3 Merge pull request #80441 from johanot/kubernetes-1-17
[20.03] kubernetes: 1.16.5 -> 1.17.3
2020-03-11 12:50:34 +01:00
Johan Thomsen
5ee843ec01 kubernetes: 1.16.5 -> 1.17.3
(cherry picked from commit 66556afb5a)
2020-03-11 09:51:11 +01:00
Andreas Rammhold
ed5fef0117 ppp: apply patch for CVE-2020-8597
This fixes a potential buffer overflow in the eap_{request,response}
functions.

(cherry picked from commit 142c3153f7)
2020-03-10 21:12:32 +01:00
Andreas Rammhold
f3fc8ac925 ppp: 2.4.7 -> 2.4.8
(cherry picked from commit caffd51048)
2020-03-10 21:12:31 +01:00
Daniel Gorin
1cf2c15f18 Fix missing default-policy.json in skopeo
We started having issues with `pkgs.dockerTools.pullImage`, were it
would fail with:

```
FATA[0000] Error loading trust policy: open /etc/containers/policy.json: no such file or directory
```

It turns out that since `skopeo` was bumped to `0.1.40`, it was
accidentally no longer being built with a default policy.

This may happen again, see https://github.com/containers/skopeo/issues/787

(cherry picked from commit a646f4b454)
2020-03-10 16:56:14 +00:00
Vincent Laporte
bdf8162b94 coqPackages.dpdgraph: enable for Coq ≥ 8.9
(cherry picked from commit 659e89e21b)
2020-03-10 17:47:04 +01:00
Mario Rodas
afeaca75cf Merge pull request #82223 from pacien/alot-0.9-patch-composition-20.03
[20.03] alot: add patch for email composition
2020-03-10 06:34:20 -05:00
Michael Weiss
3f9b623c91 chromium: Update the VA-API patch (fix #81909)
(cherry picked from commit 735707ef0c)
2020-03-10 11:28:22 +01:00
Adam Sandberg Ericsson
20fa9f307f ghc: really use ld.gold
(cherry picked from commit 9a5ecf1212)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-10 10:20:20 +01:00
Vladimír Čunát
187a4bebe2 Merge #82191: doc: improve grammar in nixpkgs GNOME manual
(cherry picked from commit 5ea0258458)
2020-03-10 10:12:14 +01:00
Vladimír Čunát
80d27173b8 knot-dns: 2.9.2 -> 2.9.3
https://gitlab.labs.nic.cz/knot/knot-dns/-/tags/v2.9.3
(cherry picked from commit 29a7464115)
These minor updates should have no breaking changes.
2020-03-10 10:12:02 +01:00
pacien
34c9db1f13 alot: add patch for email composition
This version is not usable without this patch.
See https://github.com/pazz/alot/issues/1468.

(cherry picked from commit b6d45301de)
2020-03-10 09:23:32 +01:00
Christian Lütke-Stetzkamp
dbacfa172f licensor: Fix test in 2020
(cherry picked from commit c8299d69b0)
2020-03-10 05:27:25 +00:00
Mario Rodas
c5db275f81 Merge pull request #81463 from B4dM4n/amp-update-backport
[20.03] amp: 0.6.1 -> 0.6.2
2020-03-09 19:45:46 -05:00
Vincent Laporte
b357f9e624 Merge pull request #81882 from nomeata/js_of_ocaml-20.03
backport js_of_ocaml: 3.4.0 -> 3.5.2 (and other required changes)
2020-03-09 22:01:37 +01:00
Samuel Dionne-Riel
da92e0566d Merge pull request #82173 from samueldr/20.03/aarch64/firefox
[20.03] firefox: Fix AArch64 build
2020-03-09 16:06:03 -04:00
Samuel Dionne-Riel
6291285748 firefox: Fix AArch64 build
* The 'arm.patch' patch doesn't apply anymore.
 * The 'build-arm-libopus.patch' patch isn't required anymore.
 * See the mozilla phabricator link for the added patch.

Additionally, we are now *always* undconditionally applying all patches
to all architectures. That is, unless they have undesirable
side-effects, but those might not be fit for inclusion.

By applying all patches all the time, they'll be removed or replaced
when they stop applying.

(cherry picked from commit d4446c563d)
2020-03-09 15:12:15 -04:00
Andreas Rammhold
6a662cbf43 Merge pull request #81772 from dylex/tensorflow
tensorflow: 1.15.1 -> 1.15.2
2020-03-09 19:03:37 +01:00
Milan
7f2658be83 gitlab: 12.8.2 -> 12.8.5 (#82142)
https://about.gitlab.com/releases/2020/03/09/gitlab-12-8-5-released/
(cherry-picked from f391999026)
2020-03-09 17:25:40 +01:00
R. RyanTM
ff55699976 graylog: 3.2.0 -> 3.2.2
(cherry picked from commit 2954d5544d and 9c6b5041c5)
2020-03-09 14:41:03 +00:00
Frederik Rietdijk
d95513b710 python3Packages.acoustics: 0.2.3 -> 0.2.4
(cherry picked from commit 634ab6fc5d)
2020-03-09 14:10:03 +01:00
Mario Rodas
0b5f073245 Merge pull request #82126 from bhipple/bp/procs
[20.03] procs: 0.9.6 -> 0.9.18
2020-03-09 08:04:07 -05:00
Lancelot SIX
7010635ac2 Merge pull request #82048 from tokudan/20.03/fetchmail642
fetchmail: 6.3.26 -> 6.4.2 [security] [20.03]
2020-03-09 12:00:42 +01:00
Lancelot SIX
cd5d243899 notable: update license to unfree
Notable used to be released under AGPL-v3 until v1.5.x but is is now
nonfree.

See https://github.com/notable/notable/blob/master/SOURCE_CODE.md

(cherry picked from commit 08edf7f27c)
2020-03-09 11:48:09 +01:00
zowoq
58fa229c1e rkt: add CVEs
https://www.twistlock.com/labs-blog/breaking-out-of-coresos-rkt-3-new-cves/
(cherry picked from commit c4c936f2f7)
2020-03-09 10:12:36 +00:00
zowoq
3bc2b975fd youtube-dl: 2020.03.06 -> 2020.03.08
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.03.08
(cherry picked from commit 134f8cc84d)
2020-03-09 08:22:20 +01:00
Benjamin Hipple
e76d4a031a [20.03] procs: 0.9.6 -> 0.9.18
(cherry picked from commit c882a90bc6)
2020-03-09 01:15:52 -04:00
Benjamin Hipple
e4844bd69d btrfs-dedupe: remove broken and abandoned package
This package was last released in 2017, and no longer compiles with the latest
Rust compiler. It has just 1 commit from someone other than the original author
and appears to be a dead project.

(cherry picked from commit 27a0a1376b)
2020-03-09 00:34:39 -04:00
rnhmjoj
525ab7718b minecraft: install missing gsettings schemas
(cherry picked from commit 018a46ffe8)
2020-03-13 11:28:04 +01:00
Andrew Childs
d262f76123 nixos/activation: use eval-config's system argument for nesting
This avoids a possible surprise if the user is using `nixpkgs.system`
and `nesting.children`. `nesting.children` is expected to ignore all
parent configuration so we shouldn't propagate the user-facing option
`nixpkgs.system`. To avoid doing so, we introduce a new internal
option for holding the value passed to eval-config.nix, and use that
when recursing for nesting.

(cherry picked from commit ce416779bb)
2020-03-13 11:28:03 +01:00
Andrew Childs
4a8801a7d3 nixos/activation: propagate system to nested configurations
The current behavior lets `system` default to
`builtins.currentSystem`. The system value specified to
`eval-config.nix` has very low precedence, so this should compose
properly.

Fixes #80806

(cherry picked from commit b83164a049)
2020-03-13 11:28:03 +01:00
Andrew Childs
6e6d8a2bdb nixosTests.nesting: fix subtest scoping
(cherry picked from commit 98791845cb)
2020-03-13 11:28:02 +01:00
Vincent Laporte
c0e34873d9 ocsigen-i18n: 3.4.0 → 3.5.0
(cherry picked from commit 5e468ef981)
2020-03-13 10:56:30 +01:00
Vincent Laporte
8e7396eef8 ocamlPackages.ocp-build: fix for OCaml ≥ 4.08
(cherry picked from commit d02dc3c5fd)
2020-03-13 09:07:03 +01:00
Vincent Laporte
ee46c5500d ocamlPackages.ppx_import: 1.5-3 → 1.7.1
Support for OCaml ≥ 4.08

(cherry picked from commit db4ccde60d)
2020-03-13 08:18:56 +01:00
Vincent Laporte
f452e4e1ad acgtk: 1.5.0 → 1.5.1 (#81539)
Co-authored-by: Jon <jonringer@users.noreply.github.com>
(cherry picked from commit dcfccdfc33)
2020-03-13 06:52:45 +01:00
Maximilian Bosch
37a3c3fafb nixos/manual: fix build
(cherry picked from commit 7e978ca324)
2020-03-13 02:09:17 +01:00
Maximilian Bosch
45e699cbed nixos/python-test-driver: allow single char as hostName and fix misleading error-message
In case of invalid chars, the error-message references "perl variables"
which is not the case here as the python-based framework is used.

(cherry picked from commit 6d14bac048)
2020-03-13 01:10:17 +01:00
Sergey Lukjanov
872beff40b docker: 19.03.5 -> 19.03.8
(cherry picked from commit e1611f85c2)
(cherry picked from commit 1d0c3f148b)
2020-03-12 23:57:05 +01:00
Florian Klink
4b2151b9fa nixos/networkd: respect systemd.network.links also with disabled systemd-networkd
This mirrors the behaviour of systemd - It's udev that parses `.link`
files, not `systemd-networkd`.

(cherry picked from commit 36ef112a47)
2020-03-12 23:49:38 +01:00
Florian Klink
f549fbfd97 nixos/zerotierone: switch from manually generating the .link file to use the module
Previously, systemd.network.links was only respected with networkd
enabled, but it's really udev taking care of links, no matter if
networkd is enabled or not.

With our module fixed, there's no need to manually manage the text file
anymore.

(cherry picked from commit 3d1079a20d)
2020-03-12 23:49:38 +01:00
Félix Baylac-Jacqué
cde800dbd7 tests/networking: remove pkgs.lib usages.
(cherry picked from commit 1115959a8d)
2020-03-12 23:49:37 +01:00
Symphorien Gibol
99a3d7a86f nixos/btrfs: make autoScrub not prevent shutdown or suspend
Fixes: #79086 #79017
(cherry picked from commit 5359d90b15)
2020-03-12 22:40:26 +01:00
Maximilian Bosch
8038d4a429 r10k: 3.2.0 -> 3.4.1
(cherry picked from commit 7c078497ce)
2020-03-12 21:24:32 +01:00
Maximilian Bosch
99ca097e15 blueman: 2.1.1 -> 2.1.2
(cherry picked from commit 3fa6cd14ce)
2020-03-12 21:24:32 +01:00
Maximilian Bosch
8cad2b90a9 packer: 1.5.1 -> 1.5.4
(cherry picked from commit 9f877b97b8)
2020-03-12 21:24:32 +01:00
Maximilian Bosch
d1dc14bd9e EmptyEpsilon: 2020.01.15 -> 2020.02.18
(cherry picked from commit f7d1c8384c)
2020-03-12 21:24:31 +01:00
Murray Campbell
063c26cdea blender: use PYTHONPATH (#82341)
See [blender patch](https://developer.blender.org/D6598)

(cherry picked from commit fd614a72e9)
2020-03-12 14:45:19 -04:00
Timo Kaufmann
0b7fe7290a Merge pull request #82416 from timokau/sage-docutils-0.15-fix-20.03
[20.03] sage: fix test suite with docutils 0.15
2020-03-12 16:18:37 +00:00
Timo Kaufmann
b9cbb44067 sage: fix test suite with docutils 0.15
The better way to fix this would be to backport the upstream sphinx
patch:

faedcc48cc

Unfortunately it doesn't apply cleanly and isn't worth the effort
of backporting. Let's hope we can switch to python3 sage and the recent
sphinx version that comes with it before this becomes a problem.

(cherry picked from commit 7133577405)
2020-03-12 16:42:08 +01:00
Mario Rodas
9c26d7939c Merge pull request #82113 from bhipple/bp/ion
[20.03] ion: mark as broken
2020-03-08 23:08:00 -05:00
Mario Rodas
d02d2b0764 Merge pull request #82108 from bhipple/bp/heatseeker
[20.03] heatseeker: 1.5.1 -> 1.7.1
2020-03-08 22:30:00 -05:00
Benjamin Hipple
dde4748143 [20.03] ion: mark as broken
Backport of https://github.com/NixOS/nixpkgs/pull/82016

ZHF: #80379

(cherry picked from commit d5d648b0f6)
2020-03-08 23:10:01 -04:00
Mario Rodas
45138d3c1d Merge pull request #82106 from bhipple/bp/sit
[20.03] sit: mark as broken
2020-03-08 22:06:30 -05:00
Benjamin Hipple
da79582aaf [ZHF][20.03] heatseeker: 1.5.1 -> 1.7.1
Backport of https://github.com/NixOS/nixpkgs/pull/82017

ZHF: #80379

(cherry picked from commit 9044bdef6a)
2020-03-08 22:36:34 -04:00
Benjamin Hipple
a81880d840 [20.03] sit: mark as broken
Dependencies in the Cargo.lock fail to build due to mutable self borrows.

Backport of https://github.com/NixOS/nixpkgs/pull/82018

ZHF: https://github.com/NixOS/nixpkgs/issues/80379

(cherry picked from commit a2514c22a8)
2020-03-08 22:30:31 -04:00
Florian Klink
30cd233df1 Merge pull request #82054 from mweinelt/pr/20.03/borgbackup/1.1.11
[20.03] borgbackup: 1.1.10 → 1.1.11
2020-03-08 16:28:12 -07:00
Robert Hensing
6b21029d39 buildLayeredImage: Allow empty store, no paths to add
This is useful when buildLayeredImage is called in a generic way
that should allow simple (base) images to be built, which may not
reference any store paths.

(cherry picked from commit 6dab1b50a6)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-08 23:12:16 +01:00
Jacek Galowicz
f85b4f1df4 nixosTests.docker-tools: Port to Python 2020-03-08 23:12:07 +01:00
Antoine Eiche
c34efec88e nixosTests.docker-tools: add bulk-layer test
A regression test for https://github.com/NixOS/nixpkgs/issues/78744.

(cherry picked from commit baa78de594)
Signed-off-by: Domen Kožar <domen@dev.si>
2020-03-08 23:11:48 +01:00
Ben Wolsieffer
645522a971 buildbot: 2.6.0 -> 2.7.0 (#81406)
(cherry picked from commit 07727dbd16)

cc #81406
2020-03-08 17:42:56 -04:00
R. RyanTM
55cbe7dbaf buildbot: 2.6.0 -> 2.7.0
(cherry picked from commit 0a545f61fc)

cc #81283
2020-03-08 17:42:56 -04:00
Domen Kožar
62b2bf3f8e elm2nix: bump to 0.2 as it supports Elm 0.19.1 2020-03-08 18:43:46 +01:00
Dmitry Kalinkin
9cc2f1885f glibc: provide fallback for kernels with missing prlimit64
The current version of glibc implements support for kernels down to
3.2.0 (and we make sure to enable such support with apporopriate
--enable-kernel setting). The current RHEL6 operating system is based on
a maintained kernel based on 2.6.32 with lots of backports. We provide
basic support for this specific kernel by patching glibc to provide an
exception for this specific version of kernel. This allows for nixpkgs
software distribution to work on RHEL6 and it does so quite well with
almost no problems. There are, however, a few syscalls that are missing
in the 2.6.32 kernel, one of which is prlimit64. This commit provides a
fallback that uses an older {get,set}rlimit syscalls in cases when
prlimit64 is not available. This should streamline the experience for
nixpkgs users wanting to run it on RHEL6, namely, this fixes one of the
tests in findutils.

See also discussion in guix:
https://lists.gnu.org/archive/html/guix-devel/2018-03/msg00356.html

(cherry picked from commit 6740593bdd)
2020-03-08 13:16:50 -04:00
R. RyanTM
3a237ae22b nextcloud: 18.0.0 -> 18.0.1
(cherry picked from commit 91250fe625)
2020-03-08 17:34:33 +01:00
Daniel Schaefer
aae661cefe satallax: Fix build with GCC9
(cherry picked from commit bc56175034)
2020-03-08 16:17:35 +01:00
Maximilian Bosch
ae1b10ad0a Merge pull request #81958 from ryneeverett/backport-howard-hinnant-date-zone-info
howard-hinnant-date: allow access to zoneinfo
2020-03-08 15:56:14 +01:00
Martin Weinelt
9e8594685d borgbackup: 1.1.10 → 1.1.11
Version 1.1.11 (2020-03-08)

Compatibility notes:

    When upgrading from borg 1.0.x to 1.1.x, please note:
        read all the compatibility notes for 1.1.0*, starting from 1.1.0b1.
        borg upgrade: you do not need to and you also should not run it.
        borg might ask some security-related questions once after upgrading. You can answer them either manually or via environment variable. One known case is if you use unencrypted repositories, then it will ask about a unknown unencrypted repository one time.
        your first backup with 1.1.x might be significantly slower (it might completely read, chunk, hash a lot files) - this is due to the --files-cache mode change (and happens every time you change mode). You can avoid the one-time slowdown by using the pre-1.1.0rc4-compatible mode (but that is less safe for detecting changed files than the default). See the --files-cache docs for details.
    1.1.11 removes WSL autodetection (Windows 10 Subsystem for Linux). If WSL still has a problem with sync_file_range, you need to set BORG_WORKAROUNDS=basesyncfile in the borg process environment to work around the WSL issue.

Fixes:

    fixed potential index corruption / data loss issue due to bug in hashindex_set, #4829 Please read and follow the more detailled notes close to the top of this document.
    upgrade bundled xxhash to 0.7.3, #4891 0.7.2 is the minimum requirement for correct operations on ARMv6 in non-fixup mode, where unaligned memory accesses cause bus errors. 0.7.3 adds some speedups and libxxhash 0.7.3 even has a pkg-config file now.
    upgrade bundled lz4 to 1.9.2
    upgrade bundled zstd to 1.4.4
    fix crash when upgrading erroneous hints file, #4922
    extract:
        fix KeyError for "partial" extraction, #4607
        fix "partial" extract for hardlinked contentless file types, #4725
        fix preloading for old (0.xx) remote servers, #4652
        fix confusing output of borg extract --list --strip-components, #4934
    delete: after double-force delete, warn about necessary repair, #4704
    create: give invalid repo error msg if repo config not found, #4411
    mount: fix FUSE mount missing st_birthtime, #4763 #4767
    check: do not stumble over invalid item key, #4845
    info: if the archive doesn't exist, print a pretty message, #4793
    SecurityManager.known(): check all files, #4614
    Repository.open: use stat() to check for repo dir, #4695
    Repository.check_can_create_repository: use stat() to check, #4695
    fix invalid archive error message
    fix optional/non-optional location arg, #4541
    commit-time free space calc: ignore bad compact map entries, #4796
    ignore EACCES (errno 13) when hardlinking the old config, #4730
    --prefix / -P: fix processing, avoid argparse issue, #4769

New features:

    enable placeholder usage in all extra archive arguments
    new BORG_WORKAROUNDS mechanism, basesyncfile, #4710
    recreate: support --timestamp option, #4745
    support platforms without os.link (e.g. Android with Termux), #4901 if we don't have os.link, we just extract another copy instead of making a hardlink.
    support linux platforms without sync_file_range (e.g. Android 7 with Termux), #4905

Other:

    ignore --stats when given with --dry-run, but continue, #4373
    add some ProgressIndicator msgids to code / fix docs, #4935
    elaborate on "Calculating size" message
    argparser: always use REPOSITORY in metavar, also use more consistent help phrasing.
    check: improve error output for matching index size, see #4829
    docs:
        changelog: add advisory about hashindex_set bug #4829
        better describe BORG_SECURITY_DIR, BORG_CACHE_DIR, #4919
        infos about cache security assumptions, #4900
        add FAQ describing difference between a local repo vs. repo on a server.
        document how to test exclusion patterns without performing an actual backup
        timestamps in the files cache are now usually ctime, #4583
        fix bad reference to borg compact (does not exist in 1.1), #4660
        create: borg 1.1 is not future any more
        extract: document limitation "needs empty destination", #4598
        how to supply a passphrase, use crypto devices, #4549
        fix osxfuse github link in installation docs
        add example of exclude-norecurse rule in help patterns
        update macOS Brew link
        add note about software for automating backups, #4581
        AUTHORS: mention copyright+license for bundled msgpack
        fix various code blocks in the docs, #4708
        updated docs to cover use of temp directory on remote, #4545
        add restore docs, #4670
        add a pull backup / push restore how-to, #1552
        add FAQ how to retain original paths, #4532
        explain difference between --exclude and --pattern, #4118
        add FAQs for SSH connection issues, #3866
        improve password FAQ, #4591
        reiterate that 'file cache names are absolute' in FAQ
    tests:
        cope with ANY error when importing pytest into borg.testsuite, #4652
        fix broken test that relied on improper zlib assumptions
        test_fuse: filter out selinux xattrs, #4574
    travis / vagrant:
        misc python versions removed / changed (due to openssl 1.1 compatibility) or added (3.7 and 3.8, for better borg compatibility testing)
        binary building is on python 3.5.9 now
    vagrant:
        add new boxes: ubuntu 18.04 and 20.04, debian 10
        update boxes: openindiana, darwin, netbsd
        remove old boxes: centos 6
        darwin: updated osxfuse to 3.10.4
        use debian/ubuntu pip/virtualenv packages
        rather use python 3.6.2 than 3.6.0, fixes coverage/sqlite3 issue
        use requirements.d/development.lock.txt to avoid compat issues
    travis:
        darwin: backport some install code / order from master
        remove deprecated keyword "sudo" from travis config
        allow osx builds to fail, #4955 this is due to travis-ci frequently being so slow that the OS X builds just fail because they exceed 50 minutes and get killed by travis.

(cherry picked from commit dbff9b5479)
2020-03-08 14:32:50 +01:00
Peter Simons
9226f826b5 fetchmail: update from version 6.3.26 to 6.4.2
The new version supports OpenSSL 1.x. Should be back-ported to
release-20.03.

See https://sourceforge.net/projects/fetchmail/files/branch_6.4/
for the changelog.

(cherry picked from commit 85befe90b0)
2020-03-08 12:48:31 +01:00
Maximilian Bosch
fb34ac13e4 wasm-bindgen-cli: 0.2.58 -> 0.2.59
(cherry picked from commit 88b16119c1)
2020-03-07 23:11:47 +01:00
Michael Weiss
4e623d16e3 signal-desktop: 1.32.0 -> 1.32.1
(cherry picked from commit 01db31c4d7)
2020-03-07 21:07:01 +01:00
Daniel Fullmer
cbe553c988 zoneminder: add patch to fix improper caching
(cherry picked from commit ce34b927e0)

cc #79488
2020-03-07 13:27:07 -05:00
Daniel Fullmer
cf7dfbf87b zoneminder: fix timezone detection
(cherry picked from commit 630de551ef)

cc #79488
2020-03-07 13:27:03 -05:00
Daniel Fullmer
7f2973c12f nixos/zoneminder: update on startup if needed
(cherry picked from commit cb5da4eacb)

cc #79488
2020-03-07 13:26:58 -05:00
Daniel Fullmer
e7913b7d84 zoneminder: 1.32.3 -> 1.34.3
(cherry picked from commit 2685e457d3)

cc #79488
2020-03-07 13:26:47 -05:00
Silvan Mosberger
4b003af753 du-dust: Change derivation name from dust to du-dust
This prevents confusion by nix-env when installing packages by
derivation name, since there is another package named dust already

(cherry picked from commit ad126ee28e)
2020-03-07 15:43:20 +01:00
Silvan Mosberger
8b85be406c Merge pull request #81970 from Infinisil/dhall-nix-fix
[20.03] dhall-nix: Fix build
2020-03-07 14:46:24 +01:00
Silvan Mosberger
680f15a544 dhall-nix: Fix build 2020-03-07 14:14:02 +01:00
R. RyanTM
d61616bfe5 gnomeExtensions.appindicator: 30 -> 32 (#81309)
(cherry picked from commit e88113846c)
2020-03-07 13:09:27 +01:00
Silvan Mosberger
883217dc3f Merge pull request #81435 from mweinelt/pr/20.03/acme
[20.03] nixos/acme: backport #81369 and #81371
2020-03-07 12:12:03 +01:00
Benjamin Hipple
57fafc08f9 tree-sitter: 0.15.7 -> 0.16.4
Includes some bugfixes/cleanups to the scripts and packaging, a run of the
updater and a bump of the version.

Fixes #75863

(cherry picked from commit 9131efe52d)
2020-03-07 10:20:11 +01:00
Maximilian Bosch
f7e077a54a grocy: 2.6.0 -> 2.6.1
(cherry picked from commit d0e0acadbb)
2020-03-07 09:44:57 +01:00
Jörg Thalheim
23edc4489b Merge pull request #81902 from Mic92/nginx-ssl
[backport] nixos/nginx: use Mozilla Intermediate TLS configuration
2020-03-07 08:43:32 +00:00
Cole Helbling
e5c3c21eac howard-hinnant-date: allow access to zoneinfo
This fixes the situtation where, if `/usr/share/zoneinfo` was
inaccessible/didn't otherwise exist, `howard-hinnant-date` would
download and drop a `~/Downloads/tzdata` directory containing some
timezone information from IANA [1]. To avoid this, we make use of the
`tzdata`'s `zoneinfo`, preventing the dropping of random directories and
files.

[1] https://data.iana.org/time-zones/releases/tzdata2019c.tar.gz

(cherry picked from commit 25057960ce)

This fixes a bug which breaks the clock module. See
<https://github.com/Alexays/Waybar/issues/566>.
2020-03-07 05:16:24 +00:00
pacien
b780aefc62 riot-desktop: 1.5.10 -> 1.5.12
(cherry picked from commit abc58dc1d0)
2020-03-06 23:15:22 +01:00
pacien
44d322f488 riot-web: 1.5.10 -> 1.5.12
(cherry picked from commit 18848216ea)
2020-03-06 23:15:22 +01:00
R. RyanTM
df5c76b745 libreswan: 3.30 -> 3.31
(cherry picked from commit bce33c5d74)
2020-03-06 23:02:19 +01:00
R. RyanTM
9b9106b9b4 libreswan: 3.29 -> 3.30
(cherry picked from commit f4b1d118a4)
2020-03-06 23:00:48 +01:00
Luis Ressel
18181553e0 nixos/wireguard: Fix typo in error message
generatePrivateKey -> generatePrivateKeyFile

(cherry picked from commit b19c485b22)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2020-03-06 22:45:09 +01:00
Lancelot SIX
06652b25cf python3Pakcages.django_compat: fix
(cherry picked from commit df155637fe)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2020-03-06 22:28:02 +01:00
Lancelot SIX
6ec1e63207 python3akcages.django_compat: improve test fix
(cherry picked from commit e8d5bdb7b3)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2020-03-06 22:27:51 +01:00
Lancelot SIX
8a526e4f3a python3Packages.django_compat: fix tests and re-enable
(cherry picked from commit 75087d8882)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2020-03-06 22:27:32 +01:00
Vincent Laporte
57614a9ccd ocamlPackages.core_profiler: remove at 0.11.0
This package is broken with glibc ≥ 2.28

(cherry picked from commit 5c274c6c05)
2020-03-06 21:36:46 +01:00
Vincent Laporte
5ba4cc937c ocamlPackages.ocaml_plugin: remove at 0.11.0
This package is broken with glibc ≥ 2.28

(cherry picked from commit 9095ca22bc)
2020-03-06 21:36:46 +01:00
Vincent Laporte
f6122a2a5c ocamlPackages.conduit_p4: remove at 0.10.0
(cherry picked from commit fe0ebdf825)
2020-03-06 21:36:46 +01:00
Vincent Laporte
d8980f92d2 ocamlPackages.cohttp_p4: remove at 0.19.3
(cherry picked from commit 305dc2a199)
2020-03-06 21:36:46 +01:00
Vincent Laporte
27e412851d trv: remove at 0.1.3
(cherry picked from commit fca7f386db)
2020-03-06 21:36:46 +01:00
Sergey Lukjanov
b417adb48b snmp_exporter: 0.15.0 -> 0.17.0
(cherry picked from commit bd3319d28c)
2020-03-06 18:38:48 +01:00
Emily
65e31f98ce nixos/nginx: use Mozilla Intermediate TLS configuration
The configuration at https://ssl-config.mozilla.org/#server=nginx&config=intermediate
is reliably kept up-to-date in terms of security and compatible with a
wide range of clients. They've probably had more care and thought put
into them than our defaults, and will be easier to keep updated in
the future.

The only removed (rather than changed) configuration option here is
ssl_ecdh_curve, per https://github.com/mozilla/server-side-tls/issues/189.

Resolves #80952.

(cherry picked from commit 4ed98d69ed)
2020-03-06 14:31:53 +00:00
Alexander Bakker
2ec23b2e2f uwsgi: use pyhome instead of pythonpath for uwsgi vassals
(cherry picked from commit 7bbf7fa693)
2020-03-06 13:17:00 +00:00
Tim Steinbach
f707a0cef4 linux: 5.5.7 -> 5.5.8 2020-03-06 07:53:31 -05:00
Tim Steinbach
b5335c4e4a linux: 5.4.23 -> 5.4.24 2020-03-06 07:53:31 -05:00
Tim Steinbach
775be80b9d linux: 4.19.107 -> 4.19.108 2020-03-06 07:53:31 -05:00
Dillen Meijboom
b719c465f2 pulumi: 1.4.0 -> 1.12.0
(cherry picked from commit c4f5f95d8d)
2020-03-06 10:14:56 +00:00
Anderson Torres
253e2d9586 Merge pull request #81880 from OPNA2608/palemoon_28.8.4_cherrypick_20.03
[20.03] palemoon: 28.8.2.1 -> 28.8.4
2020-03-06 06:55:08 -03:00
WilliButz
9db4062c6c nixos/tests/prometheus-exporters: increase memory for rspamd
Before this, the test failed because rspamd did invoke the oom-killer.

(cherry picked from commit 0d832ee98e)
2020-03-06 10:37:54 +01:00
Martin Milata
ebb7ec3f04 nixos/prometheus-mail-exporter: misc fixes
- Fix misspelled option. mkRenamedOptionModule is not used because the
   option hasn't really worked before.
 - Add missing cfg.telemetryPath arg to ExecStart.
 - Fix mkdir invocation in test.

(cherry picked from commit e7ed7901a8)
2020-03-06 10:37:53 +01:00
Martin Milata
f382c70e34 nixos/prometheus-mail-exporter: fix assertion
The assertion was printed when user explicitly defined only the
configFile option.

(cherry picked from commit 3b5cf35e8b)
2020-03-06 10:37:53 +01:00
Martin Milata
bddb1723d8 nixos/prometheus-snmp-exporter: fix assertion
The assertion was printed when user explicitly defined only the
configurationPath option.

(cherry picked from commit 2a080ac434)
2020-03-06 10:37:53 +01:00
Martin Milata
6673c4f5ff nixos/prometheus-snmp-exporter: update log options
The allowed values have changed in bd3319d28c.

0.15:
      --log.level="info"        Only log messages with the given severity or above. Valid levels: [debug, info, warn, error, fatal]
      --log.format="logger:stderr"
                                Set the log target and format. Example: "logger:syslog?appname=bob&local=7" or "logger:stdout?json=true"

0.17:
      --log.level=info          Only log messages with the given severity or above. One of: [debug, info, warn, error]
      --log.format=logfmt       Output format of log messages. One of: [logfmt, json]

(cherry picked from commit 87f87fb3e9)
2020-03-06 10:37:53 +01:00
Martin Milata
c3bb46e179 nixos/prometheus-*-exporter: escape shell args
(cherry picked from commit 0ac24ccf2a)
2020-03-06 10:37:53 +01:00
zowoq
5c3564790a youtube-dl: 2020.03.01 -> 2020.03.06
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.03.06
(cherry picked from commit 815f25daed)
2020-03-06 10:31:18 +01:00
Joachim Breitner
6a8cdf74fd js_of_ocaml: 3.4.0 -> 3.5.2 (#75766)
drive-by contributions, as I was playing around with this (it has better
support for the `num` library, it seems.)

js_of_ocaml: 3.4.0 -> 3.5.2
ocamlPackages.js_of_ocaml-ppx_deriving_json: use ppxlib-0.12.0
ocamlPackages.eliom: 6.8.0 → 6.10.1
ocamlPackages.ocsigen-toolkit: 2.2.0 → 2.5.0
ocamlPackages.ocsigen-start: 2.7.0 → 2.16.1

Co-authored-by: Vincent Laporte <Vincent.Laporte@gmail.com>
(cherry picked from commit 2d2a5a9b63)
2020-03-06 10:18:32 +01:00
Vincent Laporte
0456880576 ocamlPackages.resource-pooling: 0.6 → 1.1
ocamlPackages.ocsigen-start: 1.8.0 → 2.7.0

(cherry picked from commit c589de98e2)
2020-03-06 10:18:29 +01:00
Vincent Laporte
525b0d1a8e ocamlPackages.pgocaml_ppx: init at 4.0
(cherry picked from commit 4f7484f038)
2020-03-06 10:18:24 +01:00
WilliButz
3fbd8bda3e Merge pull request #81757 from Ma27/backport-codimd
[20.03] codimd: 1.5.0 -> 1.6.0
2020-03-06 09:45:58 +01:00
Pavol Rusnak
4707311e20 libfido2: change dependency from libressl to openssl
libressl does not enable EdDSA functionality in libfido2
see https://github.com/Yubico/libfido2/issues/144

(cherry picked from commit 4135584798e428a98d0ded9dab337673bd048f05)
2020-03-06 07:11:21 +01:00
worldofpeace
c4db4e5538 Merge pull request #81793 from JeffLabonte/20_03-brave_1.4.95_to_1.4.96
[20.03] brave 1.4.95 to 1.4.96
2020-03-05 19:41:09 +00:00
worldofpeace
1f99fd2fdb Merge pull request #81718 from worldofpeace/backport-80746
[20.03] openssl_1_0_2: mark as insecure; fixes #77503 (kinda)
2020-03-05 18:41:51 +00:00
Milan
c1746708b1 gitlab: 12.8.1 -> 12.8.2 (#81803)
Includes multiple security fixes mentioned in
https://about.gitlab.com/releases/2020/03/04/gitlab-12-dot-8-dot-2-released/
(unfortunately, no CVE numbers as of yet)

 - Directory Traversal to Arbitrary File Read
 - Account Takeover Through Expired Link
 - Server Side Request Forgery Through Deprecated Service
 - Group Two-Factor Authentication Requirement Bypass
 - Stored XSS in Merge Request Pages
 - Stored XSS in Merge Request Submission Form
 - Stored XSS in File View
 - Stored XSS in Grafana Integration
 - Contribution Analytics Exposed to Non-members
 - Incorrect Access Control in Docker Registry via Deploy Tokens
 - Denial of Service via Permission Checks
 - Denial of Service in Design For Public Issue
 - GitHub Tokens Displayed in Plaintext on Integrations Page
 - Incorrect Access Control via LFS Import
 - Unescaped HTML in Header
 - Private Merge Request Titles Leaked via Widget
 - Project Namespace Exposed via Vulnerability Feedback Endpoint
 - Denial of Service Through Recursive Requests
 - Project Authorization Not Being Updated
 - Incorrect Permission Level For Group Invites
 - Disclosure of Private Group Epic Information
 - User IP Address Exposed via Badge images
 - Update postgresql (GitLab Omnibus)

(cherry-picked from commit c25756f91c)
2020-03-05 17:08:55 +01:00
Tor Hedin Brønner
0b6df0b4bf nix-bash-completions: 0.6.7 -> 0.6.8 (#81019)
(cherry picked from commit 0e5d4573d4)
2020-03-05 15:09:52 +01:00
R. RyanTM
f5fa7bf2cf palemoon: 28.8.2.1 -> 28.8.4
(cherry picked from commit e633927c81)
2020-03-05 14:34:25 +01:00
Vladimír Čunát
3a820f04e1 nixos/release-notes: fix a tiny typo
(cherry picked from commit 1cf4fea33f)
2020-03-05 14:04:17 +01:00
Michael Weiss
1019f56391 signal-desktop: 1.31.0 -> 1.32.0
(cherry picked from commit 05e6cc4944)
2020-03-05 12:05:42 +01:00
Michael Weiss
a6ac7bfb1e signal-desktop: 1.30.1 -> 1.31.0
Changelog: https://github.com/signalapp/Signal-Desktop/releases/tag/v1.31.0
(cherry picked from commit 7d927677f4)
2020-03-05 12:05:36 +01:00
Jeff Labonte
093092a99a brave: 1.4.95 -> 1.4.96
Update brave from the version 1.4.95 to 1.4.96.

(cherry picked from commit 3f6d356654)
Reason: Keep the browser to the latest stable version
2020-03-04 21:35:31 -05:00
Dylan Simon
0a5ec494b5 tensorflow: 1.15.1 -> 1.15.2 2020-03-04 18:00:52 -05:00
Jan Tojnar
e544e03110 glib.setupHook: run glibPreFixupPhase before gappsWrapperArgsHook
Since we split wrapGAppsHook and move its variable initialization to preFixupPhases in #81475, it was getting run before glibPreFixupPhase which sets GSETTINGS_SCHEMAS_PATH variable gappsWrapperArgsHook depends on. Let's introduce this ugly hack to ensure glibPreFixupPhase will run before gappsWrapperArgsHook.

(cherry picked from commit 8e4f502fc6)
2020-03-04 17:41:04 -05:00
R. RyanTM
da48691741 at-spi2-atk: 2.34.1 -> 2.34.2
(cherry picked from commit deec2268c9)
2020-03-04 20:46:31 +01:00
R. RyanTM
08bcfe14ae gnome3.glade: 3.22.1 -> 3.22.2
(cherry picked from commit acc4854dac)
2020-03-04 20:36:57 +01:00
WilliButz
0419b78866 nixos/codimd: update useCDN default to false
(cherry picked from commit 68410b08be)
2020-03-04 20:24:40 +01:00
WilliButz
9cefdd7de2 codimd: 1.5.0 -> 1.6.0
(cherry picked from commit 6c2284090a)
2020-03-04 20:24:40 +01:00
Michael Weiss
487b2f74cd chromium: 80.0.3987.122 -> 80.0.3987.132
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html

This update includes 4 security fixes.

CVEs:
CVE-2020-6420

(cherry picked from commit 51b6f9c6ae)
Backport of #81704.
2020-03-04 20:13:57 +01:00
Silvan Mosberger
19a4f3f79c Merge pull request #81709 from yegortimoshenko/acme-fullchain-force-symlink-20.03
[20.03] nixos/acme: force symlink from fullchain.pem to cert.pem
2020-03-04 19:33:54 +01:00
zimbatm
eaea08b2fe Revert "defaultGemConfig: remove asciidoctor-diagram JARs" (#81737)
This reverts commit 1ac11cc1c1.

asciidoctor-diagram starts Java processes, so the JARs are necessary
on all platforms.

See https://github.com/NixOS/nixpkgs/pull/77149#issuecomment-594576339.

(cherry picked from commit 89a09456c7)
2020-03-04 19:05:15 +01:00
Maximilian Bosch
fffd09d21c nixos/tests/initrd-network-ssh: fix test
It seems as it takes a moment until the initrd-network is loaded. Please
note that this is currently only reproducible on release-20.03.
2020-03-04 18:37:19 +01:00
Franz Pletz
3c86a21d6c nixos/initrd-network: always run postCommands
As outlined in #71447, postCommands should always be run if networking
in initrd is enabled. regardless if the configuration actually
succeeded.

(cherry picked from commit 589789997f)

The backport of this patch has been requested in #79532[1]. The diff is
slightly off the original commit since some changes from
ea7d02406b were needed, however this
commit shouldn't be backported as it potentially breaks existing setups.

[1] https://github.com/NixOS/nixpkgs/pull/79532#issuecomment-593511638
2020-03-04 18:31:03 +01:00
Maximilian Bosch
7c6d9f55e0 nextcloud-client: 2.6.3 -> 2.6.4
https://github.com/nextcloud/desktop/releases/tag/v2.6.4
(cherry picked from commit 13e3fc3e06)
2020-03-04 16:19:54 +01:00
talyz
53e5e70eda gitaly: Copy gem files into bundler env instead of symlinking
This fixes issue #79374, where gitaly prints warning messages on the
client side when running push or fetch.
2020-03-04 14:37:21 +01:00
talyz
4d50664b10 bundlerEnv: Add option to copy gem files instead of symlinking
The way ruby loads gems and keeps track of their paths seems to not
always work very well when the gems are accessed through
symlinks. Ruby will then complain that the same files are loaded
multiple times; it relies on the file's full path to determine whether
the file is loaded or not.

This adds an option to simply copy all gem files into the environment
instead, which gets rid of this issue, but may instead result in major
file duplication.
2020-03-04 14:37:21 +01:00
talyz
06bd94cfb6 gitlab-shell: Change name from gitlab-shell-go to gitlab-shell
This is left over from when gitlab-shell had a ruby part and a go
part. The ruby part is now gone, so let's call the go part
gitlab-shell.
2020-03-04 14:37:21 +01:00
talyz
08582ebb7c gitlab-workhorse: 8.20.0 -> 8.21.0 2020-03-04 14:37:21 +01:00
talyz
750cf9e911 gitaly: 1.83.0 -> 12.8.1 2020-03-04 14:37:21 +01:00
talyz
894ff16021 gitlab: 12.7.6 -> 12.8.1
https://about.gitlab.com/releases/2020/02/22/gitlab-12-8-released/
https://about.gitlab.com/releases/2020/02/24/gitlab-12-8-1-released/
2020-03-04 14:37:21 +01:00
Vladimír Čunát
feaa6347ca knot-resolver: apply upstream patch
Encrypted ZFS users were affected, in particular some NixOS users
who reported the issue upstream.  /cc #81188.

(cherry picked from commit b7f5450e4d)
2020-03-04 14:01:22 +01:00
Jörg Thalheim
876085e8f7 nixos/zfs: continue trimming also if one pool fails
fixes https://github.com/NixOS/nixpkgs/issues/81602

(cherry picked from commit 557989c460e386d0abca068245806a2fbc89edf0)
2020-03-04 12:48:28 +00:00
Vladimír Čunát
7dfb4447d6 openssl_1_0_2: mark as insecure; fixes #77503 (kinda)
No vulnerabilities are know so far (to me), but still I'd go this way.
Especially for 20.03 it seems better to deprecate it before official
release happens.

Current casualties:
$ ./maintainers/scripts/rebuild-amount.sh --print HEAD HEAD^
Estimating rebuild amount by counting changed Hydra jobs.
     87 x86_64-darwin
    161 x86_64-linux

(cherry picked from commit 7cda2823be)
2020-03-04 07:40:36 -05:00
Yegor Timoshenko
08795a97f4 nixos/acme: force symlink from fullchain.pem to cert.pem
(cherry picked from commit c32da2ed9c)

Co-authored-by: emily <vcs@emily.moe>
2020-03-04 13:19:29 +03:00
adisbladis
0c3057c59d Merge pull request #81266 from Frostman/20.03-go-1.14
[20.03] go_1_14: init at 1.14 and switch to it (backport)
2020-03-04 08:25:02 +00:00
worldofpeace
87cc49a3fe Merge pull request #81082 from JeffLabonte/release/20.03-brave_1.3.118_to_1.4.95
[20.03] brave: 1.3.118 -> 1.4.95
2020-03-04 01:27:28 +00:00
Jeff Labonte
bf8a421551 brave: 1.3.118 -> 1.4.95
Update brave from 1.3.118 to 1.4.95

(cherry picked from commit fa166b77d1)
Reason: Browser should be kept up-to-date for security reasons.
2020-03-03 20:14:55 -05:00
worldofpeace
20c553be69 pantheon.wingpanel-indicator-nightlight: 2.0.2 -> 2.0.3
https://github.com/elementary/wingpanel-indicator-nightlight/releases/tag/2.0.3
(cherry picked from commit 9dc1cc507d)
2020-03-03 20:13:21 -05:00
worldofpeace
b37fcf90c4 pantheon.elementary-files: 4.4.0 -> 4.4.1
https://github.com/elementary/files/releases/tag/4.4.1
(cherry picked from commit 7f7977e296)
2020-03-03 20:13:21 -05:00
worldofpeace
bd49b6f7bf ephemeral: 6.2.1 -> 6.3.0
https://github.com/cassidyjames/ephemeral/releases/tag/6.3.0
(cherry picked from commit 0e82b0e0ed)
2020-03-03 20:13:21 -05:00
worldofpeace
5a1a248e7d lollypop: 1.2.16 -> 1.2.23
(cherry picked from commit 5d31a94b11)
2020-03-03 20:13:21 -05:00
worldofpeace
0ebcfef5fe lollypop: add missing deps
We need the GIO_EXTRA_MODULE from glib-networking

(cherry picked from commit c10c96b991)
2020-03-03 20:13:21 -05:00
obadz
201a5d8e4f Merge pull request #81669 from obadz/backport-2003-zerotier-mac-fix
[20.03] nixos/zerotierone: prevent systemd from changing MAC address
2020-03-04 01:07:58 +00:00
Daniel Fullmer
01a02ccd73 nixos/zerotierone: prevent systemd from changing MAC address
(cherry picked from commit 27b8253655)
2020-03-04 01:04:03 +00:00
worldofpeace
e8e569ce79 wrapGAppsHook: Fix #78803
Add to gappsWrapperArgs in preFixupPhases.

(cherry picked from commit 29fc27b4ac)
2020-03-03 19:35:37 -05:00
worldofpeace
e78f26b977 Merge branch 'release-20.03' into staging-20.03 2020-03-03 19:35:13 -05:00
Aiken Cairncross
6c3ab02ad0 python3Packages.monosat: Fix hash
(cherry picked from commit 3db82f6fc3)
2020-03-03 19:34:08 +00:00
Aiken Cairncross
04379d0a6a python3Packages.monosat: Fix Python 3.8 build
(cherry picked from commit 2148a154c6)
2020-03-03 19:23:57 +00:00
Dmitry Kalinkin
899cf4ba29 python3Packages.ipykernel: fix build on darwin
Also python34 is not supported:

979e6fd2db

nixpkgs doesn't provide python34 anymore, so pythonOlder "3.5" is always
true and can be removed.

(cherry picked from commit d35009ee63)

cc #80940
2020-03-03 12:51:50 -05:00
Dmitry Kalinkin
17e15615e4 tdlib: enable on darwin
(cherry picked from commit fa2546f1b9)
2020-03-03 12:45:10 -05:00
Dmitry Kalinkin
ee01f461a3 blender: fix enableNumpy option, enable it unconditionally
Workarounds https://developer.blender.org/T74304

Audaspace requires numpy, we already have to provide numpy
unconditionally via PYTHON_NUMPY_PATH.

(cherry picked from commit 27578856bf)

cc #81313
2020-03-03 09:20:54 -05:00
Jeffry Molanus
943aff5679 terraform-providers.libvirt: 0.5.1 -> 0.6.1
(cherry picked from commit c1b5cfe267)
2020-03-03 11:32:14 +00:00
Yegor Timoshenko
0f2565d518 Merge pull request #80857 from emilazy/adjust-acme-20.03
[20.03] nixos/acme: adjust renewal timer options
2020-03-03 03:49:56 +03:00
conferno
2e4a4b928b xfce.xfdashbooard: fix typo
(cherry picked from commit e0a2f0fc24)
2020-03-02 18:39:02 -05:00
Vladimír Čunát
181974248e Merge branch 'staging-20.03' into release-20.03
It's finished on Hydra: https://hydra.nixos.org/eval/1573320
2020-03-02 18:30:49 +01:00
Martin Milata
56b1c3938c qt5.qtbase: backport cmake macro fix
Backport fix of QT5_MAKE_OUTPUT_FILE CMake macro which causes FreeCAD
build failure when building with qt-5.12.7.

https://bugreports.qt.io/browse/QTBUG-81715

(cherry picked from commit 80650ae4f0)
2020-03-02 18:29:43 +01:00
Maximilian Bosch
0bdf352a05 nixos/release-notes: mention fix for predictable network-interfaces in initrd
(cherry picked from commit f4d71e2e73)
2020-03-02 17:58:44 +01:00
Franz Pletz
173c7715de nixos/initrd-network: use ipconfig from klibc
This apparently has features that the version from Arch's
mkinitcpio-nfs-utils does not have. Fixes #75314.

(cherry picked from commit d25c1a8fdc)
2020-03-02 17:18:00 +01:00
Franz Pletz
3206aa985a klibc: 2.0.4 -> 2.0.7
(cherry picked from commit 4ba8086aa1)
2020-03-02 17:17:59 +01:00
Franz Pletz
332d731a7a nixos/stage-1: fix predictable interfaces names
This makes predictable interfaces names available as soon as possible
with udev by adding the default network link units to initrd which are read
by udev. Also adds some udev rules that are needed but which would normally
loaded from the udev store path which is not included in the initrd.

(cherry picked from commit 44e289f93b)
2020-03-02 17:17:59 +01:00
Janne Heß
4e924d3a4e pkgs/bazel*: Fix path to update-srcDeps.py
Otherwise, the -small channel fails on the tarball output.

(cherry picked from commit 0723bf3b72)
2020-03-02 17:06:03 +01:00
Michael Lingelbach
7202d2cdaa tensorflow: 1.15.0 -> 1.15.1
* Apply glibc 2.3 patch
* build tensorflow with bazel_1
* Bump openssl version to 1.1

(cherry picked from commit 1dc0db8481a349dbecc572250008f4ed7f1366f3)
2020-03-02 17:07:13 +01:00
ngerstle
3c45fc8781 traefik: 1.7.14 -> 1.7.21 2020-03-02 16:48:50 +01:00
Vladimír Čunát
1f33b3d018 Merge #80714: icon-lang: fix build
(cherry picked from commit 4d954e528d)
2020-03-02 16:20:33 +01:00
Vladimír Čunát
89528af331 Merge #79026: blackmagic: v1.6.1-317-gc9c8b08 -> v1.6.1-409-g7a595ea
(cherry picked from commit 855f020404)
It didn't build before this bump.
2020-03-02 16:00:54 +01:00
Vladimír Čunát
41a6bafd41 Merge #80124: llvmPackages_5.compiler-rt: fix for glibc bump
(cherry picked from commit fb6ceb45ba)
I re-tested the build for 20.03, before and after this commit.
2020-03-02 15:49:00 +01:00
Michael Lingelbach
87fc21d6c8 Add bazel 1.2.1
(cherry picked from commit 1c4f22a5da)
2020-03-02 09:18:38 +01:00
scalavision
06e9970c44 truvari:1.3.2->1.3.4
(cherry picked from commit dbb4826457)
2020-03-02 09:16:18 +01:00
Kovacsics Robert
0edebabe92 polyml: updated maintainers
I am not sure if we still need the old packages, nothing explicitly
depends on polyml56 or polyml57 according to a grep, not sure if
external packages might (hol and isabelle depend on polyml, the latest
version).

(cherry picked from commit f4c29ebfc2)
2020-03-02 09:14:14 +01:00
Kovacsics Robert
2f0b6c2af2 polyml: fix with new libffi
New libffi doesn't have FFI_SYSV for x86/64 unix, this pulls in the
commit for the upstream version which fixes it, and ports that patch to
the 5.7 version. The 5.6 version is unchanged.

For ZHF: #80379

(cherry picked from commit f8c402ecad)
2020-03-02 09:14:14 +01:00
pacien
61cc1f0dc0 riot-web: mention incompatible config change in release notes
Mention the changes introduced in commit c9e5cca.

GitHub: closes #81416
(cherry picked from commit 6d4fd13612)
2020-03-02 03:15:10 +01:00
zowoq
e1dd2c620b youtube-dl: 2020.02.16 -> 2020.03.01
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.03.01
(cherry picked from commit 5ce2974294)
2020-03-02 01:18:56 +01:00
worldofpeace
f0ad76b504 Merge pull request #81423 from Frostman/20.03-smartmontools-7.1
[20.03] smartmontools: 7.0 -> 7.1 and devicedb updated to latest
2020-03-01 23:25:05 +00:00
Fabian Möller
f0608b08b5 amp: 0.6.1 -> 0.6.2
(cherry picked from commit 1820ce4922972cce690fbcc7e1dc3b6c239af603)
2020-03-01 21:42:34 +01:00
Sander van der Burg
698f5dbabc titaniumenv: add Titanium SDK 8.3
(cherry picked from commit c5a6a2ae5ead4249486c78d758c123ed8acfd8a9)
2020-03-01 20:24:17 +01:00
Sander van der Burg
760dc689aa androidenv: add platform SDK 29
(cherry picked from commit f5d8e5d92bd4edd2873d0c116ce8db372287a3cf)
2020-03-01 20:24:17 +01:00
worldofpeace
ae0edff42b doc/xfce: remove trailing code
(cherry picked from commit b7b46d0184)
2020-03-01 13:45:10 -05:00
Klaas van Schelven
a8c2c1d92d pythonPackages.swagger-spec-validator 2.4.3 -> 2.5.0
Includes various upstream fixes of the tests, see

* https://github.com/Yelp/swagger_spec_validator/pull/117
* https://github.com/Yelp/swagger_spec_validator/pull/121

(cherry picked from commit efa25157e9)
2020-03-01 09:02:40 -08:00
worldofpeace
ea4f8e8f31 nixos/pantheon: add docs
(cherry picked from commit 3be04570e0)
2020-03-01 11:57:28 -05:00
Florian Klink
932f2e3157 systemd: 243.4 -> 243.7
This bumps to the latest state of the systemd 242 stable, published at
https://github.com/systemd/systemd-stable/tree/v243-stable.

Should cover CVE-2020-1712.

Git Log:

f8dd0f2f15 (tag: v243.7, systemd-stable/v243-stable) Revert "Support Plugable UD-PRO8 dock"
1a5428c2ab hibernate-resume-generator: wait "infinitely" for the resume device
eb3148c468 (tag: v243.6) hwdb: update to v245-rc1
f14fa558ae Fix typo in function name
fb21e13e8e polkit: when authorizing via PK let's re-resolve callback/userdata instead of caching it
2e504c92d1 sd-bus: introduce API for re-enqueuing incoming messages
4d80c8f158 polkit: use structured initialization
54791aff01 polkit: on async pk requests, re-validate action/details
81532beddc polkit: reuse some common bus message appending code
4441844d58 bus-polkit: rename return error parameter to ret_error
31a1d569db shared: split out polkit stuff from bus-util.c → bus-polkit.c
560eb5babf test: adapt to the new capsh format
275b266bde meson: update efi path detection to gnu-efi-3.0.11
9239154545 presets: "disable" all passive targets by default
a827c41851 shared/sysctl-util: normalize repeated slashes or dots to a single value
fb1bfd6804 dhcp6: do not use T1 and T2 longer than one provided by the lease
ca43a515c6 network: fix implicit type conversion warning by GCC-10
421eca7edf bootspec: parse random-seed-mode line in loader.conf
34e21fc6de sd-boot: fix typo
df7b3a05c9 test: Synchronize journal before reading from it
9326efee71 sd-bus: fix introspection bug in signal parameter names
7bbdc56aaf efi: fix build.
486f8ca365 generator: order growfs for the root fs after systemd-remount-fs
56d442e29d loginctl: use /org/freedesktop/login1/session/auto when "lock-session" is called without argument
6ed1152282 Documentation update for x-systemd.{before,after}
dba3efa34a man: fix typo in systemd.netdev Xfrm example
6f9a8621d8 timesyncd: log louder when we refuse a server due to root distance
0637255d3b resolved: drop DNSSEC root key that is not valid anymore
9a135baa40 journal: don't use startswith() on something that is not a NUL-terminated string
1ff3972a0f test: add test for https://github.com/systemd/systemd/issues/14560
cac79b606b core: make sure StandardInput=file: doesn't get dup'ed to stdout/stderr by default
906ba9a67d pkgconf: add full generator paths
01b93e2c68 tree-wide: we forgot to destroy some bus errors
5c9455657e mount: make checks on perpetual mount units more lax
28c58beca1 core: never allow perpetual units to be masked
d3b044b3e7 typo: "May modify to" -> "May modify"
fd378d3d3c sysctl: downgrade message when we have no permission
db4fbf5c61 Clarify journald.conf MaxLevelStore documentation
c8365f71c0 logind: refuse overriding idle hint on tty sessions
cd91f567b6 cgroup: update only siblings that got realized once
c672dcd212 mount: mark an existing "mounting" unit from /proc/self/mountinfo as "just_mounted"
a592a40564 journalctl: Correctly handle combination of --reverse and --lines (fixes #1596)
0aa144ab1d journalctl: Correctly handle --show-cursor in combination with --until or --since and --reverse
3b803a5e66 core: fix re-realization of cgroup siblings
7549dd40fc core: propagate service state to socket in more load states
af6df343b2 man: describe "symlink" and "systemctl link" explicitly in UNIT FILE LOAD PATH
a3c1ce25a7 core: be more restrictive on the dependency types we allow to be created transiently
2b9ec8384c udev: don't import parent ID_FS_ data on partitions
ecd95c507c man: fix option name
0d4f06156b Support Plugable UD-PRO8 dock
7fba869abd gpt-auto: don't assume XBOOTLDR is vfat
494c281b67 man: fix documentation of IBM VIO device naming
7271fb056a man: slightly extend documentation on difference between ID_NET_NAME_ONBOARD and ID_NET_LABEL_ONBOARD
852ae28e68 boot: fix osrel parser
2613200370 udev: do not use exact match of file permission
46477397c1 network: lower the log-level of harmless message
7163b1fe86 hwdb: ignore keys added in kernel 5.5
92f90837dc systemctl: skip non-existent units in the 'cat' verb
a67227cc99 systemd.exec: document the file system for EnvironmentFile paths
cfb4c0aca5 systemd-analyze: fixed typo in documentation
017fddd998 test-condition: fix group check condition
9d5e3cb774 umount: show correct error message
252f1a5277 Revert "Drop dbus activation stub service"
20bbfac95e man: add section about user manager units
c93ef60212 man: add remote-*.targets to the bootup sequence
55e0f99689 time-util: also use 32bit hack on EOVERFLOW
7afe2ecb02 [man] note which UID ranges will get user journals
a43b67a4c9 [man] fix URL
dedb26a8d6 analyze: badness if neither of RootImage and RootDirectory exists
714c93862a initrd: make udev cleanup service confict trigger and settle too
8932407ae1 man: we support growing xfs too these days
19af11dc07 time-util: deal with systems where userspace has 64bit time_t but kernel does not
c90229d81d [import] fix stdin/stdout pipe behavior in import/export tar/raw
39910328da cryptsetup-generator: unconfuse writing of the device timeout
fc5e6c87a4 shared/install: log syntax error for invalid DefaultInstance=
409c94a407 shared/install: provide a nicer error message for invalid WantedBy=/Required= values
70e8c1978a seccomp: real syscall numbers are >= 0
a0a1977d9a seccomp: more comprehensive protection against libseccomp's __NR_xyz namespace invasion
7f936c60d5 network: set ipv6 mtu after link-up or device mtu change
b59d88cc62 man: fix typo in net-naming-scheme man page
c5e5ac0958 man: fix typos (#14304)
9a2f26564d ipv4ll: do not reset conflict counter on restart
bc9e1ebfdd Fix typo (duplicate "or")
c6cb71b7e7 network: if /sys is rw, then udev should be around
67dcdfd956 nspawn: do not fail if udev is not running
a7938a1bc6 Create parent directories when creating systemd-private subdirs
53aa44f873 network: do not return error but return UINT64_MAX if speed meter is disabled
65abf12674 core: swap priority can be negative
b1cf452ff5 systemctl: enhance message about kexec missing kernel
07a0e5b425 man: use mkswap@ instead of makeswap@
57dc017c6b journald: don't ask for the machine ID if we don't need it
ac392a57c0 journalctl: pager_close() calls fflush(stdout) anyway as first thing
ee7dfadc82 journald: remove unused field
471073f1b5 journalctl: return EOPNOTSUPP if pcre is not enabled
002ededb61 man: drop reference to machined, add one for journald instead
fd3bd4be3b pid1: make TimeoutAbortSec settable for transient units
eb2ef4d664 pid1: fix setting of DefaultTimeoutAbortSec
1d75e29b23 shared/ask-password-api: modify keyctl break value
a16b1ee7e5 cryptsetup: reduce the chance that we will be OOM killed
4836fb010a core: write out correct field name when creating transient service units
3e2c547f6d udevd: don't use monitor after manager_exit()
d42f7d45a8 Revert "udevd: fix crash when workers time out after exit is signal caught"
c9a287eee8 man/systemd.link: Add missing verb *be*
a67a3ae04b man: document all pager variables for systemctl and systemd
3a8fce3f38 core.timer: fix "systemd-analyze dump" and docs syntax inconsistencies wrt OnTimezoneChange=
fdffd284b6 core/service: downgrade "scheduling restart" message to debug
733e7f19d3 travis: add missing closing quote sign
0d7b7817fc systemd-tmpfiles: don't install timer when service isn't installed either
0e7f83cd2b pam_systemd: prolong method call timeout when allocating session

(cherry picked from commit 53488b27be)
2020-03-01 10:16:37 -05:00
worldofpeace
a57de92c5e Merge pull request #81368 from prusnak/openssh-20.03
[20.03] openssh: 8.1p1 -> 8.2p1
2020-03-01 15:14:52 +00:00
Maximilian Bosch
ebc9620c3f bandwhich: 0.11.0 -> 0.12.0
https://github.com/imsnif/bandwhich/releases/tag/0.12.0
(cherry picked from commit c3b331a777)
2020-03-01 16:01:20 +01:00
worldofpeace
699a8d4e9b libgpod: also remove mutagen
I think this was my mistake. This is also a python2 dependency
that should have been removed with pygobject.

(cherry picked from commit e50306dfe3)
2020-03-01 09:56:52 -05:00
worldofpeace
550d6afe6b ideogram: 1.3.2 -> 1.3.3
better icon https://github.com/cassidyjames/ideogram/releases/tag/1.3.3

(cherry picked from commit 4b771aa2e6)
2020-03-01 09:37:46 -05:00
worldofpeace
a345d00fb1 pantheon.elementary-gtk-theme: 5.4.1 -> 5.4.2
https://github.com/elementary/stylesheet/compare/5.4.1...5.4.2
(cherry picked from commit dab121ac69)
2020-03-01 09:37:45 -05:00
worldofpeace
a39dfc11a5 pantheon.elementary-code: 3.2.0 -> 3.3.0
https://github.com/elementary/code/releases/tag/3.3.0
(cherry picked from commit 8acbc62f4e)
2020-03-01 09:37:45 -05:00
worldofpeace
a5e230448b ipmitool: fix compile on darwin
(cherry picked from commit 82217553b0)
2020-03-01 09:10:48 -05:00
Florian Klink
5c025bcc55 ipmitool: cleanup expression
* remove no-op substitution of s6_addr16 -> s6_addr

This string doesn't exist anymore in that file.

* clean up configureFlags

(cherry picked from commit 43ec75d470)
2020-03-01 09:10:48 -05:00
Andreas Rammhold
26f4dec550 ipmitool: migrate to openssl 1.1
This adds a patch from debian to switch ipmitool to openssl 1.1.
Upstream seems to already carry a version of this but that is yet to be
part of a release.

(cherry picked from commit ad19bb5ff8)
2020-03-01 09:10:47 -05:00
R. RyanTM
93137b171c aesop: 1.2.3 -> 1.2.4
(cherry picked from commit 5668479498)
2020-03-01 09:07:29 -05:00
worldofpeace
43115ebd79 Merge pull request #81119 from tilpner/gitdaemon-usercreation-backport
[20.03] nixos/git-daemon: only create git user if it will be used
2020-03-01 14:05:24 +00:00
Martin Weinelt
a79920d539 nixos/acme: apply chmod and ownership unconditionally
Also separate directory and file permissions so the certificate files
don't end up with the executable bit.

Fixes #81335

(cherry picked from commit 3575555fa8)
2020-03-01 14:41:51 +01:00
Martin Weinelt
bbd9e39758 nixos/acme: renew after rebuild and on boot
Fixes #81069

(cherry picked from commit 5ff9441471)
2020-03-01 14:41:29 +01:00
worldofpeace
78414b688c Merge pull request #81409 from smaret/release-20.03
[ZHF] pythonPackages.astroquery 0.3.10 -> 0.4
2020-03-01 13:37:49 +00:00
worldofpeace
f8601ccd24 nixos/rngd: fix clean shutdown
It seems disabling DefaultDependencies
removes these implicit dependencies [0] that
we needed for shutdown to happen cleanly.

Fixes #80871

[0]: https://www.freedesktop.org/software/systemd/man/systemd.service.html#Default%20Dependencies

(cherry picked from commit fa76150235)
2020-03-01 06:45:29 -05:00
Sergey Lukjanov
c961031be5 smartmontools: add Frostman to maintainers
(cherry picked from commit e85f0a8970)
2020-03-01 00:22:02 -08:00
Sergey Lukjanov
5d19f2497f smartmontools: 7.0 -> 7.1 and devicedb updated to latest
(cherry picked from commit 38b0c55601)
2020-03-01 00:21:53 -08:00
xbreak
aa119502bc pythonPackages.astroquery 0.3.10 -> 0.4
Tests are disabled until pytest-astropy is updated with
pytest-astropy-header.

(cherry picked from commit a5e82af9d8)
2020-02-29 22:38:33 +01:00
Ben Wolsieffer
4f5c57745c libyamlcpp: actually build shared libraries (#81051)
(cherry picked from commit be41f703ad)
2020-02-29 15:32:17 -05:00
Ben Wolsieffer
7f4770a7c9 libyamlcpp: don't use multiple outputs
This package uses CMake's install(EXPORT ...) command which assumes that
libraries are installed in the same location as the CMake files.

(cherry picked from commit bdbbe6f34f)
2020-02-29 15:32:14 -05:00
Emily
f2c522a1af nixos/acme: adjust renewal timer options
The current weekly setting causes every NixOS server to try to renew
its certificate at midnight on the dot on Monday. This contributes to
the general problem of periodic load spikes for Let's Encrypt; NixOS
is probably not a major contributor to that problem, but we can lead by
example by picking good defaults here.

The values here were chosen after consulting with @yuriks, an SRE at
Let's Encrypt:

* Randomize the time certificates are renewed within a 24 hour period.

* Check for renewal every 24 hours, to ensure the certificate is always
  renewed before an expiry notice is sent out.

* Increase the AccuracySec (thus lowering the accuracy(!)), so that
  systemd can coalesce the renewal with other timers being run.

  (You might be worried that this would defeat the purpose of the time
  skewing, but systemd is documented as avoiding this by picking a
  random time.)

(cherry picked from commit 7b14bbd734)
2020-02-29 14:03:50 +00:00
Pavol Rusnak
811013c1a2 openssh_hpn: 7.8p1 -> 8.1p1
fix build failure

(cherry picked from commit 205f42b142)
2020-02-29 14:05:12 +01:00
Pavol Rusnak
f93be3ed16 openssh: 8.1p1 -> 8.2p1
https://www.openssh.com/txt/release-8.2

add libfido2 to enable hardware tokens support added in this release

(cherry picked from commit 44864b292f)
2020-02-29 14:05:08 +01:00
Artemis Tosini
9ea34a5bb8 libfido2: add macOS support
* pass IOKit to libfido2
* Add a patch so that cmake uses lld flags when linking
* Upgrade from 1.3.0 to 1.3.1 (based off #80781)
* Specify CMAKE_INSTALL_LIBDIR so that the demo binaries link
  correctly on macOS and libfido2.pc specifies correct arguments

(cherry picked from commit 099359afc7)
2020-02-29 14:03:04 +01:00
Marek Mahut
f06ab62d84 libfido2: evaluate systemd only on Linux
(cherry picked from commit 1ea0a243d2)
2020-02-29 14:02:58 +01:00
Marek Mahut
7f3cf25977 libfido2: linux build only
(cherry picked from commit 852d2bcfd4)
2020-02-29 14:02:54 +01:00
worldofpeace
f3fa308f33 Merge branch 'release-20.03' into staging-20.03 2020-02-29 01:02:57 -05:00
worldofpeace
d8e6050fcb Merge branch 'staging-20.03' into release-20.03 2020-02-29 00:59:37 -05:00
Michael Alan Dorman
4f8bc8e10b pam_ssh_agent_auth: fix dependency on insecure openssl
There have been a couple of patches floating around for about the last
18 months.  While they originated with FreeBSD, but they've been
adopted by Gentoo and Debian as well---and the most straightforward
way to get access to them was from the Debian repository.

(cherry picked from commit b6b3e04759)
2020-02-28 21:05:32 -05:00
worldofpeace
271707af04 Merge pull request #81337 from worldofpeace/crystal-openssl-backport
[20.03] crystal: use latest openssl
2020-02-29 02:01:12 +00:00
Yegor Timoshenko
bb2678c1e6 Merge pull request #81340 from emilazy/fix-gdouros-font-licenses-20.03
[20.03] fonts/gdouros: correct license to unfree
2020-02-29 04:03:40 +03:00
Emily
1c7e269e81 fonts/gdouros: correct license to unfree
(cherry picked from commit 05a9b7fe2a)
2020-02-29 01:00:17 +00:00
R. RyanTM
01ad75043b gnome3.gnome-characters: 3.32.1 -> 3.34.0
(cherry picked from commit c6feb8a98a)
2020-02-28 19:36:13 -05:00
worldofpeace
8ee5939798 pantheon.elementary-greeter: 5.0.1 -> 5.0.2
https://github.com/elementary/greeter/releases/tag/5.0.2
(cherry picked from commit b4943b0180)
2020-02-28 19:36:07 -05:00
worldofpeace
92233e1714 pantheon.switchboard-plug-bluetooth: 2.3.0 -> 2.3.1
https://github.com/elementary/switchboard-plug-bluetooth/releases/tag/2.3.1
(cherry picked from commit ecca257d73)
2020-02-28 19:36:07 -05:00
worldofpeace
a112634861 pantheon.sideload: 1.0.0 -> 1.0.1
https://github.com/elementary/sideload/releases/tag/1.0.1
(cherry picked from commit e85290ba54)
2020-02-28 19:36:07 -05:00
worldofpeace
1124b7cde5 pantheon.appcenter: 3..2.1 -> 3.2.2
https://github.com/elementary/appcenter/releases/tag/3.2.2
(cherry picked from commit a54dcfe076)
2020-02-28 19:36:07 -05:00
worldofpeace
53b9ac8408 Merge pull request #81310 from emilazy/fix-pypy-openssl-20.03
[20.03] pypy{,3}: use openssl_1_1
2020-02-29 00:32:13 +00:00
worldofpeace
01826800d6 crystal: use latest openssl
(cherry picked from commit e10900b068)
2020-02-28 19:13:16 -05:00
worldofpeace
276e1ee942 exiv2: fix exiv2.pc file
This fix comes from #71669.

(cherry picked from commit ff41002b80)
2020-02-28 19:11:35 -05:00
arcnmx
0efe95b6b3 elinks: build with openssl 1.1
(cherry picked from commit f9a682c0cc)
2020-02-28 19:07:16 -05:00
Tim Steinbach
8764fb751d linux: 5.5.6 -> 5.5.7 2020-02-28 15:46:17 -05:00
Tim Steinbach
16c150cf52 linux: 5.4.22 -> 5.4.23 2020-02-28 15:46:17 -05:00
Michael Weiss
60855a7c19 html-proofer: Update the dependencies (security, CVE-2020-7595)
This updates nokogiri to 1.10.8 for CVE-2020-7595 [0].

[0]: https://github.com/sparklemotion/nokogiri/issues/1992

(cherry picked from commit ad0c620a08)
2020-02-28 21:22:52 +01:00
Michael Weiss
31b4a68afe jekyll: Update the dependencies (security, CVE-2020-7595)
This updates nokogiri to 1.10.8 for CVE-2020-7595 [0].

[0]: https://github.com/sparklemotion/nokogiri/issues/1992

(cherry picked from commit 9b0defc765)
2020-02-28 21:22:52 +01:00
Michael Weiss
81a208a88c gollum: Update the dependencies (security, CVE-2020-7595)
This updates nokogiri to 1.10.8 for CVE-2020-7595 [0].

[0]: https://github.com/sparklemotion/nokogiri/issues/1992

(cherry picked from commit a0d61c0135)
2020-02-28 21:22:52 +01:00
Emily
9a1966e79e pypy{,3}: use openssl_1_1
"We now support building PyPy with OpenSSL 1.1 in our built-in _ssl
module, as well as maintaining support for previous versions."
-- https://pypy.readthedocs.io/en/latest/release-pypy2.7-v5.6.0.html

(cherry picked from commit 6d3fc35620)
2020-02-28 18:14:02 +00:00
Tim Steinbach
8dc1ffb22f linux: 4.9.214 -> 4.9.215 2020-02-28 11:11:05 -05:00
Tim Steinbach
c97e547f46 linux: 4.4.214 -> 4.4.215 2020-02-28 11:11:05 -05:00
Tim Steinbach
9239f78bbf linux: 4.19.106 -> 4.19.107 2020-02-28 11:11:05 -05:00
Tim Steinbach
0477af2036 linux: 4.14.171 -> 4.14.172 2020-02-28 11:11:05 -05:00
Mario Rodas
89536cd763 postgresqlPackages.postgis: 3.0.0 -> 3.0.1
Release notes: https://postgis.net/2020/02/20/postgis-3.0.1/

(cherry picked from commit 53a5d6918a)
2020-02-28 04:20:00 -05:00
Eelco Dolstra
87e543dad4 enable-coverage-instrumentation.sh: Fix unbound variable error
https://hydra.nixos.org/build/113299582
(cherry picked from commit 4c0821461e)
2020-02-28 12:34:59 +01:00
worldofpeace
a8dd7b2370 Merge pull request #81216 from jonringer/backport-plasma5-fix
[20.03] nixos/plasma5: Fix activation script when XDG_CONFIG_HOME is unset
2020-02-28 06:33:58 +00:00
Sergey Lukjanov
e378b239f6 grafana: switch to latest go
(cherry picked from commit c29045c0908e4512d08a0510deb52a1df7ee0bbc)
2020-02-27 21:47:39 -08:00
Sergey Lukjanov
3041889bc6 go_1_14: init at 1.14 and switch to it
(cherry picked from commit 8c4a92887fc4c827d6f2fec9c146f5a947cfec7e)
2020-02-27 21:47:29 -08:00
Thomas Tuegel
45d1f19d12 nixos/plasma5: Fix activation script when XDG_CONFIG_HOME is unset
Fixes #80713

(cherry picked from commit d3e3cc1225)
2020-02-27 14:32:51 -08:00
Michele Guerini Rocco
a2bb258c60 Merge pull request #81043 from wd15/sfepy-2019.4
[20.03] pythonPackages.sfepy: 2019.2 -> 2019.4
2020-02-27 22:26:44 +01:00
Maximilian Bosch
abbaed1165 Merge #81155: wireshark: 3.2.1 -> 3.2.2 (security)
(cherry picked from commit 250daba4be)
https://www.wireshark.org/docs/relnotes/wireshark-3.2.2.html
I re-tested it still builds.
2020-02-27 20:05:23 +01:00
Timo Kaufmann
98960342e0 Merge pull request #80735 from timokau/maven-jdk-overridable-20.09
[20.03] maven: make jdk overridable
2020-02-27 16:09:08 +00:00
Jörg Thalheim
287e7f9d60 Merge pull request #81022 from mmilata/parsoid-20.03
[20.03] nixos/parsoid: fix service by reinstating nodePackages.parsoid
2020-02-27 15:59:06 +00:00
Martin Milata
a65ea62ef6 nixos/parsoid: enable systemd sandboxing
(cherry picked from commit 9b0a9577f7)
2020-02-27 15:09:40 +01:00
Martin Milata
c83c446489 nixos/parsoid: fix package name
Original package was removed in 2b8cde0ce2.

(cherry picked from commit 3b27f4d945)
2020-02-27 15:09:40 +01:00
Martin Milata
e83eddef8a nodePackages.parsoid: init at 0.11.0
(not-really-cherry-picked from commit 9264a0fabf)
2020-02-27 15:09:40 +01:00
Maximilian Bosch
f823335caa clipman: 1.3.0 -> 1.4.0
https://github.com/yory8/clipman/releases/tag/v1.4.0
(cherry picked from commit 57f2ea5ca1)
2020-02-27 11:44:54 +01:00
Michael Weiss
be346a1f4b chromium: 80.0.3987.116 -> 80.0.3987.122
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html

This update includes 3 security fixes.

CVEs:
CVE-2020-6407 CVE-2020-6418

(cherry picked from commit 8be566d288)
Backport of #81016.
2020-02-26 19:29:29 +01:00
Jörg Thalheim
d4cb3da747 Merge #81122 nixos/kresd: never force extraFeatures = false
(cherry picked from commit 8e1350e392)
2020-02-26 17:22:18 +01:00
Michele Guerini Rocco
ef54b6081e Merge pull request #81041 from wd15/fipy-3.4.1
[20.03] pythonPackages.fipy: 3.3 -> 3.4.1
2020-02-26 15:38:52 +01:00
tilpner
ee4421d18e nixos/git-daemon: only create git user if it will be used
(cherry picked from commit 6df119a6ec)
2020-02-26 15:09:03 +01:00
Michele Guerini Rocco
9222921433 Merge pull request #81115 from smaret/release-20.03
[ZHF] pythonPackages.reproject: fix tests
2020-02-26 14:34:26 +01:00
Sébastien Maret
c65b4ef85a pythonPackages.reproject: fix tests
Co-Authored-By: Jon <jonringer@users.noreply.github.com>
(cherry picked from commit a0f50fe24b)
2020-02-26 13:22:13 +01:00
worldofpeace
8bcc32a684 Merge pull request #81080 from worldofpeace/backport-80698
[20.03] p11-kit: 0.23.19 -> 0.23.20
2020-02-26 02:06:00 -05:00
worldofpeace
8d49ebf488 Merge pull request #81064 from Thra11/release-20.03
[20.03] R: fix build on aarch64 by removing a failing test
2020-02-25 21:10:07 -05:00
Tor Hedin Brønner
ac5c544fe5 p11-kit: 0.23.19 -> 0.23.20
Small bug fix release. Fixes a bunch of flatpak issues (eg. no playback
on spotify).

news: https://github.com/p11-glue/p11-kit/releases/tag/0.23.20
(cherry picked from commit bbbb49c450)
2020-02-25 20:51:16 -05:00
worldofpeace
2424e5ff16 tikzit: use qt5's mkDerivation
(cherry picked from commit ffe40094ab)
2020-02-25 20:12:56 -05:00
worldofpeace
309dee986c qgo: use qt5's mkDerivation
(cherry picked from commit f8da067a2a)
2020-02-25 20:12:56 -05:00
worldofpeace
d343ab805d qview: use qt5's mkDerivation
(cherry picked from commit a8eba26d2c)
2020-02-25 20:12:56 -05:00
worldofpeace
7e9bdd9743 seafile-client: use qt5's mkDerivation
Fixes #80976

(cherry picked from commit 43bb5bffda)
2020-02-25 20:12:56 -05:00
Jonathan Ringer
fb211847c9 discord-canary: 0.0.98 -> 0.0.102
(cherry picked from commit da5e340f74)
2020-02-25 16:40:22 -08:00
Jonathan Ringer
bdfea8ed3d discord-ptb: 0.0.16 -> 0.0.18
(cherry picked from commit e1d05e30f8)
2020-02-25 16:40:22 -08:00
kraem
5af6c35c2e discord: 0.0.9 -> 0.0.10
(cherry picked from commit 3ec9925f21)
2020-02-25 16:40:22 -08:00
Silvan Mosberger
1de1221476 Merge pull request #80862 from emilazy/acme-fullchain-20.03
[20.03] nixos/acme: move the crt to fullchain.pem
2020-02-26 01:00:38 +01:00
Florian Klink
158cd27ae7 Merge pull request #80995 from worldofpeace/backport-80985
[20.03] perl-packages: don't use openssl_1_0_2
2020-02-25 15:12:15 -08:00
worldofpeace
c5e6fbd203 vde2: fix build with latest openssl
(cherry picked from commit 06238ced3c)
2020-02-25 14:43:27 -08:00
worldofpeace
1a450f03c9 vde2: update homepage
(cherry picked from commit e5c3bb4103)
2020-02-25 14:43:27 -08:00
Tom Hall
5675bfa44f R: fix build on aarch64 by removing a failing test
(cherry picked from commit ae9e09a2e1)

Required to fix R on aarch64, pending upstream fix
2020-02-25 22:25:42 +00:00
Tom Hall
fcf48b8583 R: Enable java support on all platforms
(cherry picked from commit 4e5aeca90b)

This is required to fix R on aarch64
2020-02-25 22:24:58 +00:00
Lancelot SIX
ae0222c27e Merge pull request #81036 from veprbl/pr/blender_2_82_backport
[20.03] blender: 2.81a -> 2.82
2020-02-25 21:50:28 +01:00
Aaron Andersen
7161eb21ca mariadb: do not delete runtime plugins from package
(cherry picked from commit 951ceca9df)
2020-02-25 20:10:21 +00:00
Fabian Möller
42cca0d8ea mariadb-connector-c: add mysqlclient.pc pkgconfig symlink
(cherry picked from commit 349a991bfb)
2020-02-25 20:18:42 +01:00
Maximilian Bosch
08b1316313 nixos/networkd: disable vrf sub-test which tests the behavior of tcp-packets
The subtest was mainly written to demonstrate the VRF-issues with a
5.x-kernel. However this breaks the entire test now as we have 5.4 as
default kernel. Disabling the test for now, I still need to find some
time to investigate.

ZHF: #80379
(cherry picked from commit 58c7a952a1)
2020-02-25 20:00:19 +01:00
Daniel Wheeler
f6fa019c4d pythonPackages.sfepy: 2019.2 -> 2019.4
- Bump the version number to fix incompatibility with Numpy 1.18.1
 - Remove broken test to fix incompatibility with Numpy 1.18.1
2020-02-25 13:39:13 -05:00
Daniel Wheeler
25a78baa88 pythonPackages.fipy: 3.3 -> 3.4.1 2020-02-25 13:23:04 -05:00
Gabriel Ebner
d0a51428a6 blender: enable alembic
(cherry picked from commit 128c99978d)

cc #80155
2020-02-25 11:44:59 -05:00
Dmitry Kalinkin
ae9aa3c0a6 blender: fix build on darwin
We don't compile blender with alembic. The linux build is able to detect
that, but this is not done for darwin. This explicitly disables alembic
to fix blender build on darwin.

(cherry picked from commit ac560382c5)

cc #80155
2020-02-25 11:44:56 -05:00
R. RyanTM
879ce0f912 blender: 2.81a -> 2.82
(cherry picked from commit 8a2c2e48b4)

cc #80155
2020-02-25 11:44:35 -05:00
Andrew Childs
69b2c24e90 liblinear: use absolute install name on Darwin (#81015)
nixpkgs prefers absolute install names. Replace the manually specified
relative install name with the standard hook.

(cherry picked from commit 1a73b69e20)

cc #81015
2020-02-25 10:32:54 -05:00
Michele Guerini Rocco
d68b004227 Merge pull request #81020 from vanschelven/backport-80699
python.pkgs.httpretty: disable flaky test
2020-02-25 15:58:04 +01:00
Klaas van Schelven
78d92b5e8c python.pkgs.httpretty: disable flaky test
As noted upstream: https://github.com/gabrielfalcao/HTTPretty/issues/376

(cherry picked from commit c597007cce)
2020-02-25 14:32:33 +01:00
Vladimír Čunát
9fbbbf7ccc Merge branch 'staging-20.03' into release-20.03 2020-02-25 14:09:16 +01:00
rnhmjoj
88c1b21c59 python2Packages.jinja2: disable tests on 32bit systems
(cherry picked from commit 655b9c3400)
2020-02-25 01:33:20 +01:00
Shea Levy
62d454c104 nix-plugins: Build against default nix.
(cherry picked from commit 403280a516)
2020-02-24 19:06:49 -05:00
worldofpeace
6c14cc10fa Merge pull request #80993 from andir/20.03/opensmtpd
[20.03] opensmtpd: bump to 6.6.4p1
2020-02-24 18:58:47 -05:00
worldofpeace
19e927a110 perl-packages: don't use openssl_1_0_2
(cherry picked from commit 1b00f471dd)
2020-02-24 18:54:17 -05:00
Andreas Rammhold
c87bd29299 opensmtpd: 6.6.3p1 -> 6.6.4p1
Release notes aren't available at this time [1] it is likely to be
related to a recent mail to oss-security (either [2] or [3]).

[1] https://www.mail-archive.com/misc@opensmtpd.org/msg04888.html
[2] https://www.openwall.com/lists/oss-security/2020/02/24/5
[3] https://www.openwall.com/lists/oss-security/2020/02/24/4

(cherry picked from commit 09725e5f9e)
2020-02-24 23:58:39 +01:00
R. RyanTM
79104fc7f7 opensmtpd: 6.6.2p1 -> 6.6.3p1
(cherry picked from commit 77da4954da)
2020-02-24 23:58:26 +01:00
worldofpeace
69a8b0af72 Merge pull request #80935 from maxxk/whitebox-tools_1.2.0-stable
[20.03] whitebox-tools: 0.16.0 -> 1.2.0
2020-02-24 17:56:26 -05:00
Graham Christensen
bf4a8583ec Merge pull request #80988 from grahamc/expect-backports
Backport  `expect` stty fix
2020-02-24 17:45:49 -05:00
Jonathan Ringer
dd327fc0c2 expect: use postPatch for stty patch
(cherry picked from commit 46a93a7fdb)
2020-02-24 17:27:01 -05:00
Bas van Dijk
f02510278c expect: patch configure after the autoreconf phase, not before it
Fixes: #79863
(cherry picked from commit b30dc0ff89)
2020-02-24 17:26:56 -05:00
worldofpeace
39f8258199 Merge pull request #80938 from maxxk/pyfribidi-fix-stable
[20.03] pythonPackages.pyfribidi: fix build
2020-02-24 17:24:19 -05:00
Michael Weiss
e464f78330 ettercap: Switch to OpenSSL 1.1.1
I noticed that Ettercap was listed in #80746.

(cherry picked from commit ee8935d635)
2020-02-24 16:34:17 -05:00
Fabian Möller
eb33682edb seasocks: remove unneeded patch
(cherry picked from commit 2bd5d8c04a)
2020-02-24 16:31:43 -05:00
Maciej Krüger
834841cd1e ettercap: fix pango not finding hb.h from harfbuzz (#75789)
(cherry picked from commit b9f7819bd3)
2020-02-24 15:50:21 -05:00
Michael Weiss
b14e4e9f26 Merge pull request #80974 from B4dM4n/backport-mysql-connector-fix-build
[20.03] pythonPackages.mysql-connector: fix build for python != python3
2020-02-24 21:13:40 +01:00
R. RyanTM
a03a590ef6 python27Packages.mockito: 1.2.0 -> 1.2.1
(cherry picked from commit 745750d685)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2020-02-24 20:34:54 +01:00
Fabian Möller
9d346c45c3 pythonPackages.mysql-connector: fix build for python != python3
(cherry picked from commit 09796a644c)
2020-02-24 19:18:11 +01:00
Michael Lingelbach
2eee73e4bb python.pkgs.pybullet: 2.6.1 -> 2.6.6
Update static-libs.patch

Add numpy to pybullet propagatedBuildInputs

Added numpy to build inputs

(cherry picked from commit c296c062232b503602c9779737c2e0e200cd732a)
2020-02-24 07:50:00 -08:00
R. RyanTM
a1b08eda7e python27Packages.django-gravatar2: 1.4.2 -> 1.4.4
(cherry picked from commit e648441eef)
Signed-off-by: Lancelot SIX <lsix@lancelotsix.com>
2020-02-24 16:00:33 +01:00
Tim Steinbach
5f71796a07 linux: 5.5.5 -> 5.5.6 2020-02-24 08:21:16 -05:00
Tim Steinbach
805c05d326 linux: 5.4.21 -> 5.4.22 2020-02-24 08:21:16 -05:00
Tim Steinbach
4b7c05ece9 linux: 4.19.105 -> 4.19.106 2020-02-24 08:21:16 -05:00
rnhmjoj
b4db2d9239 pythonPackages.pysaml2: fix tests on 32bit systems
(cherry picked from commit 60575b2fb7)
2020-02-24 12:41:04 +01:00
Eelco Dolstra
9dc6361b4d nixFlakes: 2.4pre20200207_d2032ed -> 2.4pre20200220_4a4521f
(cherry picked from commit 39892985b0)
2020-02-24 11:01:10 +01:00
Maxim Krivchikov
382f6539f5 Add patch for python2 build with clang
(cherry picked from commit a517238f9f)
2020-02-24 08:08:52 +00:00
Maxim Krivchikov
ca8053c482 pythonPackages.pyfribidi: fix build
(cherry picked from commit 4644a4c482)
2020-02-24 08:08:42 +00:00
Maxim Krivchikov
9fd35b564c whitebox-tools: 0.16.0 -> 1.2.0
(cherry picked from commit bba9b7fe6e)
Build for v0.16.0 fails in newer Rust compilers.
2020-02-24 07:38:14 +00:00
worldofpeace
68df00b0ba Merge pull request #80835 from worldofpeace/keymap-20.03
[20.03] release-combined: readd keymap tests (again)
2020-02-23 19:11:40 -05:00
worldofpeace
83d73a107d Merge pull request #80898 from xfix/kodi-fix-build-20.03
[20.03] kodi: fix build
2020-02-23 17:59:33 -05:00
Maximilian Bosch
73d246fd80 nixos/nixos-container: use custom path if specified by --nixos-path
(cherry picked from commit 31bbcc21d3)
2020-02-23 22:22:17 +01:00
Maximilian Bosch
3d9983b700 nixos/nixos-container: ensure that the state-dir is cleaned up if a build fails
(cherry picked from commit 93943acbc5)
2020-02-23 22:22:17 +01:00
Samuel Dionne-Riel
b60560ee5c runInLinuxVM: Ensure tools requiring /etc/passwd work
This includes, but is not limited to:

 * whoami
 * nix >= 2.3.1

See

 * https://github.com/NixOS/nixpkgs/issues/71157
 * https://github.com/NixOS/nixops/issues/1216
 * https://github.com/nix-community/nixops-libvirtd/issues/5

(cherry picked from commit 687e2195d8)
2020-02-23 16:10:58 -05:00
Maxim Krivchikov
25d1554fd8 pythonPackages.ldaptor: fix build
(cherry picked from commit 50f3704c2f)
2020-02-23 12:25:22 -08:00
Maxim Krivchikov
8a8a45f5db python27Packages.seaborn: remove FRidh from maintainers
(cherry picked from commit d6115b9235c49054638d7460dfe6eb7c2900f553)
2020-02-23 12:25:08 -08:00
Maxim Krivchikov
250a45e6dd pythonPackages.seaborn: use v0.9.1 for python 2
required for poretools

(cherry picked from commit 7045c74cb2abb6285867a51438f5ef13851f7cf3)
2020-02-23 12:25:08 -08:00
Konrad Borowski
aba83042f3 kodi: fix build
(cherry picked from commit 69668e93d8)
2020-02-23 17:13:39 +01:00
worldofpeace
04aca9ac24 maintainers: correct my name stylization
Out of many variations, it's almost never like that.

(cherry picked from commit c0c1f11889)
2020-02-23 09:28:00 -05:00
worldofpeace
ddbb15cc38 Merge pull request #80891 from andir/20.03/firefox
[20.03] firefox cleanup
2020-02-23 07:56:58 -05:00
tobim
7a15ea936d nixos/gdm: Fix pulseaudio tmpfiles structure (#80274)
* nixos/gdm: Fix pulseaudio tmpfiles structure

Fix the following startup failure of the sound service in the gdm
session that was introduced by #75893:
```
Feb 16 11:44:15 qp pulseaudio[1432]: W: [pulseaudio] core-util.c: Failed to open configuration file '/run/gdm/.config/pulse//daemon.conf': Not a directory
Feb 16 11:44:15 qp pulseaudio[1432]: W: [pulseaudio] daemon-conf.c: Failed to open configuration file: Not a directory
Feb 16 11:44:15 qp systemd[1380]: pulseaudio.service: Main process exited, code=exited, status=1/FAILURE
Feb 16 11:44:15 qp systemd[1380]: pulseaudio.service: Failed with result 'exit-code'.
Feb 16 11:44:15 qp systemd[1380]: Failed to start Sound Service.
```

Co-authored-by: worldofpeace <worldofpeace@protonmail.ch>
(cherry picked from commit 44a4a3839c)
2020-02-23 07:51:41 -05:00
Andreas Rammhold
8924bb957f firefox: remove unused function arguments
(cherry picked from commit 9fd425e56f)
2020-02-23 13:14:50 +01:00
Andreas Rammhold
63b384c177 firefox: remove unused patches
(cherry picked from commit a5ae1b2ffd)
2020-02-23 13:14:38 +01:00
R. RyanTM
bcdcf1402b ideogram: 1.3.0 -> 1.3.2
(cherry picked from commit 6986f40254)
2020-02-23 06:44:03 -05:00
Cassidy Dingenskirchen
81e45e839e poetry: 0.12.17 -> 1.0.3
(cherry picked from commit 011e2d3a2dee4318b5e1c994f617b40263ef5828)
2020-02-23 08:59:44 +01:00
worldofpeace
164e588cd1 Merge pull request #80589 from worldofpeace/20.03-gnome-3.34.4
[20.03] GNOME 3.34.4 (minor rebuild)
2020-02-22 23:51:19 -05:00
Emily
f5749a733f nixos/acme: move the crt to fullchain.pem
lego already bundles the chain with the certificate,[1] so the current
code, designed for simp_le, was resulting in duplicate certificate
chains, manifesting as "Chain issues: Incorrect order, Extra certs" on
the Qualys SSL Server Test.

cert.pem stays around as a symlink for backwards compatibility.

[1] 5cdc0002e9/acme/api/certificate.go (L40-L44)

(cherry picked from commit 8ecbd97f82)
2020-02-23 04:17:47 +00:00
worldofpeace
4aaee9cc33 Merge pull request #80841 from worldofpeace/nm-1.22.8-20.03
[20.03] networkmanager: 1.22.6 -> 1.22.8
2020-02-22 20:58:00 -05:00
R. RyanTM
aa14f1bb30 networkmanager: 1.22.6 -> 1.22.8
(cherry picked from commit d7ceb1738e)
2020-02-22 18:21:20 -05:00
worldofpeace
10a25647c8 Merge branch 'release-20.03' into staging-20.03 2020-02-22 18:20:13 -05:00
Izorkin
153baa2674 mariadb: 10.3.20 -> 10.3.22
(cherry picked from commit e4f17a2b17)
2020-02-22 22:19:28 +00:00
worldofpeace
59db815c55 release-combined: readd keymap tests (again)
(cherry picked from commit a539bbf1ee)
2020-02-22 17:11:37 -05:00
Jonathan Ringer
64829beee1 azure-cli: 2.0.81 -> 2.1.0
(cherry picked from commit 4dd173560d)
2020-02-22 10:23:55 -08:00
Vladimír Čunát
2a810eb282 Merge #80802: netpbm: fix typo on substituteInPlace parameters
(cherry picked from commit d7266d00b2)
2020-02-22 17:55:01 +01:00
Graham Christensen
d31e383c44 Correct revcount diff (again) using the rev-list - method hydra uses. 75f604eb2c 2020-02-22 09:30:07 -05:00
Michael Weiss
56d398840f chromium: 80.0.3987.106 -> 80.0.3987.116
(cherry picked from commit 3e9d2f80a4)
Backport of #80615.
2020-02-22 11:51:19 +01:00
rnhmjoj
142dd6cb5d pythonPackages.pytest-timeout: disable flaky test
This should fix failing NixOS tests on i686-linux.
(cherry picked from commit c4865b8933)
2020-02-22 10:21:38 +01:00
Vladimír Čunát
4655c9d915 Merge #80766: brave: 1.1.23 -> 1.3.118 (in release-20.03) 2020-02-22 08:53:48 +01:00
Jeff Labonte
90451860b9 brave: 1.1.23 -> 1.3.118
(cherry picked from commit fa560fb30c)
(cherry picked from commit 9018faac96)
2020-02-21 23:37:58 -05:00
Jeff Labonte
27ac376b6f brave: add jefflabonte to maintainer list
(cherry picked from commit 9a4a2eb1d2)
2020-02-21 23:37:58 -05:00
Jeff Labonte
c42cf79a1e maintainers: add jefflabonte
(cherry picked from commit 2f0614bdcb)
2020-02-21 23:37:58 -05:00
Dmitry Kalinkin
67c24f6f8a lhapdf.pdf_sets: fix download url
(cherry picked from commit b83257ca5f)
2020-02-21 19:37:54 -05:00
Konrad Borowski
ebbc5462f1 cmake_2_8: fix build
(cherry picked from commit 4bad7d67cd)
2020-02-21 19:39:57 +01:00
Silvan Mosberger
87d6296fdb Merge pull request #80661 from xfix/kdepim-runtime-cherrypick
[r20.03] kdepim-runtime: Remove obsolete patch to fix compilation
2020-02-21 19:37:26 +01:00
Silvan Mosberger
93626f5cd0 turses: Fix build
(cherry picked from commit cf4130c9ec)
2020-02-21 19:08:15 +01:00
Sergey Lukjanov
74c61cd83c grafana: 6.6.1 -> 6.6.2
(cherry picked from commit 5b80220d53)
2020-02-21 18:37:17 +01:00
Aaron Olson
d10a0143d0 google-cloud-sdk: fix Darwin build by only stripping local symbols (#80554)
Darwin won't strip relocatable symbols, so strip only local symbols
from cygrpc.so

See also 6ceebc441c (commitcomment-37355193)

(cherry picked from commit 9b8a14bb7e)
2020-02-21 18:29:20 +01:00
Renato Alves
07f20d0624 pysam: 0.15.3 -> 0.15.4
Also disable tests until upstream test data issues are resolved.
See link in comment in code for more information.

(cherry picked from commit bf88bf47d1)
2020-02-21 18:18:53 +01:00
Silvan Mosberger
9c7b4a0134 swift: Fix build for glibc 2.30
(cherry picked from commit 7d8a33125f)
2020-02-21 17:23:15 +01:00
Timo Kaufmann
b56f8c33ad maven: make jdk overridable
This makes it possible to use maven with different (newer) jdks.

Fixes #75630

(cherry picked from commit 0141cfefbc)
2020-02-21 15:50:59 +01:00
Gabriel Ebner
3b6ca19e20 Merge pull request #80652 from vbgl/backport-80167
[20.03] lean: 3.4.2 -> 3.5.1
2020-02-21 12:32:29 +01:00
Yorick van Pelt
37e1d40d04 nixos/buildkite-agents: fix hooksDir assertion
(cherry picked from commit 1b351f81f4)
2020-02-21 12:00:57 +01:00
Silvan Mosberger
3b9b66d265 haskellPackages.streamly-bytestring: Fix build
(cherry picked from commit cf69e612ba5e1e7b6f9987af945fcba6097d80cb)
2020-02-21 05:14:18 +01:00
Silvan Mosberger
d9decdef19 haskellPackages.store: 0.7.1 -> 0.7.2 to fix build
See https://hackage.haskell.org/package/store-0.7.2/changelog, 0.7.2 is just an
update to fix compilation with vector >= 0.12.1.1

As such this also isn't needed on master, as the new version gets there
automatically through hackage updates
2020-02-21 05:08:42 +01:00
Silvan Mosberger
b0d23cc817 haskellPackages.construct: Fix build
(cherry picked from commit 0374261b51b20361756b9340ed3b8ef693f4f359)
2020-02-21 04:54:16 +01:00
Silvan Mosberger
5d7f5250cb haskellPackages.bitwise-enum: Fix build
(cherry picked from commit 206680aa1f30817e1c49446bc1ee09b1391538f8)
2020-02-21 04:42:49 +01:00
Silvan Mosberger
e2787d7c3d haskellPackages.Chart-tests: Fix build
(cherry picked from commit 27925aae389c44bd943a19294be8b5198b793265)
2020-02-21 04:37:11 +01:00
Andreas Rammhold
b01e41ccdf Merge pull request #80673 from mweinelt/pr/20.03/weechat/2.7.1
[20.03] weechat: 2.7 -> 2.7.1
2020-02-21 00:34:16 +01:00
Martin Weinelt
9571b07ed3 weechat: 2.7 -> 2.7.1
Release notes:

irc: fix crash when receiving a malformed message 352 (who)
irc: fix crash when a new message 005 is received with longer nick prefixes
irc: fix crash when receiving a malformed message 324 (channel mode) (CVE-2020-8955)
(cherry picked from commit 2d77fc3053)
2020-02-20 23:17:05 +01:00
R. RyanTM
2ae55e765b ephemeral: 6.2.0 -> 6.2.1
(cherry picked from commit a2a6522287)
2020-02-20 16:50:02 -05:00
worldofpeace
d4c761329a gnome3.gnome-desktop: 3.34.2 -> 3.34.4
(cherry picked from commit b9180e255fbc8c9c510a7b7dd357474877e7c58c)
2020-02-20 16:41:34 -05:00
Bastian Köcher
205ab7e22a kdepim-runtime: Remove obsolete patch to fix compilation
The facebook plugin is currently disabled by upstream.

(cherry picked from commit f2c564b124)
2020-02-20 20:10:59 +01:00
Jörg Thalheim
3303392c08 Merge pull request #80551 from Frostman/20.03-tigervnc-fix
[20.03] tigervnc: fix compatibility with xorgserver 1.20.7 (backport)
2020-02-20 18:01:11 +00:00
Junyoung Clare Jang
5f7e3870e5 lean: 3.4.2 -> 3.5.1
3.4.2 is not compilable with GCC >= 9.1

(cherry picked from commit b71c03e483)
2020-02-20 18:27:28 +01:00
Cole Helbling
970694c2a7 rls: add llvm to buildInputs
The Hydra build [1] was failing because it was unable to link `LLVM-9`.
Additionally, quote the homepage URL for compliance with RFC 45.

[1] https://hydra.nixos.org/build/112823631/nixlog/2

(cherry picked from commit 2edec098de)
2020-02-20 09:07:39 -08:00
Oleksii Filonenko
645faf2851 cargo-update: 1.5.2 -> 2.5.0
(cherry picked from commit 204b722bed)
2020-02-20 08:56:50 -08:00
Silvan Mosberger
c960e800b9 Merge pull request #80620 from xfix/decorator-20.03
[r20.03] pythonPackages.decorator: fix Python 2 build
2020-02-20 17:07:55 +01:00
Graham Christensen
43ab8e86ca Merge pull request #80630 from grahamc/alacritty-xdg-open-again-19.09
alacritty: Correct xdg-open behavior
2020-02-20 08:54:33 -05:00
Tim Steinbach
f81b7f4934 linux: 5.5.4 -> 5.5.5
(cherry picked from commit 86bdbe2c9b)
2020-02-20 08:28:09 -05:00
Tim Steinbach
83ce2c331f linux: 5.4.20 -> 5.4.21
(cherry picked from commit 887d2886e3)
2020-02-20 08:28:09 -05:00
Tim Steinbach
38a5abcb9e linux: 4.19.104 -> 4.19.105
(cherry picked from commit 49b4266ad2)
2020-02-20 08:28:09 -05:00
Tim Steinbach
fadf17eec0 linux: 5.5.3 -> 5.5.4
(cherry picked from commit fe61323050)
2020-02-20 08:28:09 -05:00
Tim Steinbach
abc6edfca9 linux: 5.4.19 -> 5.4.20
(cherry picked from commit f5357bbe1f)
2020-02-20 08:28:09 -05:00
Tim Steinbach
1dbfae3343 linux: 4.9.213 -> 4.9.214
(cherry picked from commit 4c407a299f)
2020-02-20 08:28:09 -05:00
Tim Steinbach
70f097196e linux: 4.4.213 -> 4.4.214
(cherry picked from commit e2315d6a7e)
2020-02-20 08:28:09 -05:00
Tim Steinbach
fc760fa17a linux: 4.19.103 -> 4.19.104
(cherry picked from commit f350e37773)
2020-02-20 08:28:09 -05:00
Tim Steinbach
120be343e4 linux: 4.14.170 -> 4.14.171
(cherry picked from commit daee1daf5d)
2020-02-20 08:28:09 -05:00
Tim Steinbach
697da34663 linux_latest-libre: 17318 -> 17322
(cherry picked from commit 0b3dd6026e)
2020-02-20 08:28:09 -05:00
Tim Steinbach
34e78cf421 linux: 5.5.2 -> 5.5.3
(cherry picked from commit da8c2896e8)
2020-02-20 08:28:09 -05:00
Tim Steinbach
814b7d1e9f linux: 5.4.18 -> 5.4.19
(cherry picked from commit 05b407ac81)
2020-02-20 08:28:09 -05:00
Tim Steinbach
9abacf70b4 linux: 4.19.102 -> 4.19.103
(cherry picked from commit ae4b390551)
2020-02-20 08:28:09 -05:00
Graham Christensen
236a83ad1d alacritty: Correct xdg-open behavior
(cherry picked from commit a905deb826)
2020-02-20 08:13:39 -05:00
Aaron Andersen
8d8dd897a4 Merge pull request #80568 from aanderse/phpPackages.pdo_oci
phpPackages.pdo_oci: init
2020-02-20 07:22:11 -05:00
Konrad Borowski
11b63d5346 pythonPackages.decorator: fix Python 2 build
(cherry picked from commit 686274ea62)
2020-02-20 11:14:27 +01:00
worldofpeace
1d39425b13 gnome3.gnome-boxes: 3.34.3 -> 3.34.4
(cherry picked from commit f3fddcb9cc)
2020-02-19 21:01:12 -05:00
worldofpeace
06d8f5d000 gnome3.gnome-control-center: 3.34.2 -> 3.34.4
* hardcode usermod which was added absolute this release

(cherry picked from commit 1de94d59af)
2020-02-19 20:58:58 -05:00
worldofpeace
3bd65c18fb gnome3.evolution-data-server: 3.34.3 -> 3.34.4
(cherry picked from commit a5000f07a6)
2020-02-19 20:58:58 -05:00
worldofpeace
eb576d191b gnome3.iagno: 3.34.4 -> 3.34.5
(cherry picked from commit 769786b4a6)
2020-02-19 20:58:58 -05:00
worldofpeace
9d555d7d1f gnome3.gnome-tetravex: 3.34.1 -> 3.34.4
(cherry picked from commit d02a96dd6c)
2020-02-19 20:58:57 -05:00
worldofpeace
b3b38b76a9 gnome3.gnome-taquin: 3.34.3 -> 3.34.4
(cherry picked from commit 0bd27fd551)
2020-02-19 20:58:57 -05:00
worldofpeace
361b3109fe gnome3.gnome-klotski: 3.34.3 -> 3.34.4
(cherry picked from commit 34aba8056f)
2020-02-19 20:58:57 -05:00
worldofpeace
a93ca78066 gnome3.four-in-a-row: 3.34.3 -> 3.34.4
(cherry picked from commit 66472c3c24)
2020-02-19 20:58:57 -05:00
worldofpeace
59d1ee24fd gnome3.file-roller: 3.32.3 -> 3.32.4
(cherry picked from commit dfdfa745c5)
2020-02-19 20:58:57 -05:00
worldofpeace
61ab527d08 gnome3.geary: 3.34.1 -> 3.34.2
(cherry picked from commit f330f46c15)
2020-02-19 20:58:57 -05:00
worldofpeace
d242c7f387 gnome3.simple-scan: 3.34.2 -> 3.34.4
(cherry picked from commit 509e1b4763)
2020-02-19 20:58:57 -05:00
worldofpeace
2ec07a1979 gnome3.gnome-disk-utility: 3.34.0 -> 3.34.4
(cherry picked from commit 391ab233f9)
2020-02-19 20:58:56 -05:00
worldofpeace
8ceac65198 gnome3.dconf-editor: 3.34.3 -> 3.34.4
(cherry picked from commit c5590c6efa)
2020-02-19 20:58:56 -05:00
worldofpeace
f1dffeebd6 gnome3.gnome-music: 3.34.3 -> 3.34.4
(cherry picked from commit 539493f2cd)
2020-02-19 20:58:56 -05:00
worldofpeace
886758a9a2 gnome3.evolution: 3.34.3 -> 3.34.4
(cherry picked from commit 2fd97821a6)
2020-02-19 20:58:56 -05:00
worldofpeace
9e4516e7f2 meld: 3.20.1 -> 3.20.2
(cherry picked from commit 9f00427bdd)
2020-02-19 20:58:56 -05:00
worldofpeace
1bac08e698 gnome3.gnome-photos: 3.34.0 -> 3.34.1
(cherry picked from commit 7f5a2ba1ae)
2020-02-19 20:58:56 -05:00
Tor Hedin Brønner
51419ea159 epiphany: 3.34.3.1 -> 3.34.4
(cherry picked from commit 86cd4d110f)
2020-02-19 20:58:55 -05:00
Tor Hedin Brønner
dbe2a7825c gnome3.mutter: 3.34.3 -> 3.34.4
(cherry picked from commit 25f5825b0a)
2020-02-19 20:58:55 -05:00
Tor Hedin Brønner
68e82f97b7 gnome3.gnome-shell: 3.34.3 -> 3.34.4
(cherry picked from commit 7d717675bf)
2020-02-19 20:58:55 -05:00
Maximilian Bosch
af8fe52461 riot-web: 1.5.9 -> 1.5.10
https://github.com/vector-im/riot-web/releases/tag/v1.5.10
(cherry picked from commit da45483b35)
2020-02-20 02:38:34 +01:00
Franz Pletz
2b58a9f87c Merge pull request #80394 from worldofpeace/backport-riot-updates
[20.03] Backport riot updates
2020-02-20 01:26:26 +00:00
Maximilian Bosch
2fadc21e70 date: init at 2020-01-24
Needed for waybar-0.9.1.
Closes #78458

Co-authored-by: Cole Mickens <cole.mickens@gmail.com>
(cherry picked from commit 9704297c5d)
2020-02-20 01:55:03 +01:00
Maximilian Bosch
590c89b9fd waybar: 0.9.0 -> 0.9.1, fix build
ZHF: #80379
https://hydra.nixos.org/build/113067187
(cherry picked from commit 89e2a43300)
2020-02-20 01:55:03 +01:00
Michele Guerini Rocco
d9261c5352 Merge pull request #80567 from Frostman/20.03-tinydns-fix-test
[20.03] nixos/tinydns: use local dns server to fix test (backport)
2020-02-20 01:10:09 +01:00
Maximilian Bosch
30da1f8e2d roundcube: 1.4.2 -> 1.4.3
https://github.com/roundcube/roundcubemail/releases/tag/1.4.3
(cherry picked from commit 6c6d7cb2e3)
2020-02-20 00:06:13 +01:00
worldofpeace
82d2b297ae Merge pull request #80382 from hax404/20.03_tor-browser-bundle-bin
[20.03] tor-browser-bundle-bin: 9.0.4 -> 9.0.5 (backport)
2020-02-19 16:20:32 -05:00
Aaron Andersen
c8e593b800 phpPackages.pdo_oci: init
(cherry picked from commit d0e817f63f)
2020-02-19 15:43:47 -05:00
Sergey Lukjanov
6cc20cb557 nixos/tinydns: use local dns server to fix test
(cherry picked from commit c8a873560f)
2020-02-19 12:37:16 -08:00
Michele Guerini Rocco
c2bdd9e4cc Merge pull request #80418 from fgaz/zhf2003/milkytracker-backport
milkytracker: set cmake sdl variable to fix build (20.03)
2020-02-19 18:53:55 +01:00
ahiaao
c1996df90b tigervnc: fix compatibility with xorgserver 1.20.7
(cherry picked from commit f216b03d5b)
2020-02-19 09:48:14 -08:00
Daniël de Kok
bb9ffe189e python3Packages.vowpalwabbit: fix build
- Drop the Boost patch. The patch does not apply anymore and the new
  CMake infrastructure picks up boost.
- Distable setuptools reStructuredText check. This check fails, but
  is (as far as I understand) an upstream bug.
- Clean up derivation a bit.

(cherry picked from commit 0688cba0cd)
2020-02-19 12:46:30 -05:00
Evan Hanson
757c6a31c9 ugarit: fix build by using CHICKEN 4.x
Ugarit only works with CHICKEN 4, not CHICKEN 5 (which is the default
version in nixpkgs since 69ef0702), so use the compiler and egg tools
from `chickenPackages_4` for ugarit and ugarit-manifest-maker.

(cherry picked from commit a6d39ee9db)
2020-02-19 12:39:19 -05:00
Michael Fellinger
c39669bbb1 rubyWithPackages.libv8: fix compilation
(cherry picked from commit 84fa1d2fb3)
2020-02-19 12:26:59 -05:00
Konrad Borowski
c0618578bd nixos/acme: Fix a.example.com test
(cherry picked from commit a803234213)
2020-02-19 12:24:07 -05:00
Michael Fellinger
698b6a87eb crystal: remove 0.25 and 0.26
(cherry picked from commit 765f72d037)
2020-02-19 12:21:23 -05:00
Franz Pletz
5d058471a9 php74: 7.4.1 -> 7.4.2
https://www.php.net/ChangeLog-7.php#7.4.2
(cherry picked from commit ade3e99a1d)
2020-02-19 17:00:11 +01:00
Franz Pletz
f71af5c6f7 php73: 7.3.13 -> 7.3.14
https://www.php.net/ChangeLog-7.php#7.3.14
(cherry picked from commit b55ded5d8b)
2020-02-19 17:00:11 +01:00
Franz Pletz
16ed6f3119 php72: 7.2.26 -> 7.2.27
https://www.php.net/ChangeLog-7.php#7.2.27
(cherry picked from commit ed8df1d98e)
2020-02-19 17:00:11 +01:00
Sergey Lukjanov
71be729a58 go_1_13: 1.13.7 -> 1.13.8
(cherry picked from commit f703142a732ac9f637cc19100a6bf43473f8cb5f)
2020-02-19 15:24:37 +01:00
Sergey Lukjanov
0911677beb go_1_12: 1.12.16 -> 1.12.17
(cherry picked from commit bca1fa2bf227d2e306e9c8045f219b5882733f84)
2020-02-19 15:24:37 +01:00
R. RyanTM
edc746205c nixpkgs-review: 2.1.1 -> 2.2.0
(cherry picked from commit 301c706f77)
2020-02-19 14:19:05 +00:00
Maximilian Bosch
478c489418 clipman: 1.2.0 -> 1.3.0
https://github.com/yory8/clipman/releases/tag/v1.3.0
(cherry picked from commit 563baa1ea9)
2020-02-19 14:42:32 +01:00
Konrad Borowski
6121d36f47 tor: fix build
Monotonic timer test expects sleep(200ms) to take at most 1s. On
loaded systems like hydra, it's possible for such a test to take
longer than 1 second.

Tests expecting sleep(200ms) to take at least 175ms weren't removed,
because load shouldn't cause sleep to be shorter.

(cherry picked from commit 58af3177c0)
2020-02-19 13:49:48 +01:00
Jörg Thalheim
57aa6d443c Merge pull request #80477 from cole-h/clippy-backport
[20.03] Backport `clippy: add rustc.llvm to buildInputs`
2020-02-19 10:46:58 +00:00
Jörg Thalheim
676101456e Revert "zsh: don't clobber the environment of non-login shells"
This reverts commit 6a756af3e7.

Currently zshenv by default only set fpath and HELPDIR without exporting them.
A parent shell would also not set those variables usually as they are shell local.

It also sources a file called set-environment but this is protected by an
environment variable called __NIXOS_SET_ENVIRONMENT_DONE. Hence any modification
done by the parent shell should persist as long as __NIXOS_SET_ENVIRONMENT_DONE
is not unset.

This behavior deviates from what we do in bashrc and breaks common setups such
as tmux/mosh or screen.

Fixes #80437

(cherry picked from commit 55819e6c86)
2020-02-19 09:00:50 +00:00
Orivej Desh
c2846eeac5 aseprite-unfree: 1.2.11 -> 1.2.16.3
Restore the comment explaining the split between free and unfree versions
deleted in caa4e6dcb2.

(cherry picked from commit 43ee8097d9)
2020-02-19 06:21:00 +00:00
Orivej Desh
dccfb8c988 aseprite-unfree: fix build
It fails with:

src/gpu/gl/glx/GrGLMakeNativeInterface_glx.cpp:15:10: fatal error: GL/glx.h: No such file or directory
   15 | #include <GL/glx.h>

(cherry picked from commit 3ad2c20fe6)
2020-02-19 06:21:00 +00:00
Orivej Desh
929e0f0c14 aseprite: fix build with glibc 2.30
Otherwise it fails with:

In file included from /build/source/src/allegro/include/allegro/base.h:41,
                 from /build/source/src/allegro/include/allegro.h:25,
                 from /build/source/src/./she/alleg4/alleg_surface.h:11,
                 from /build/source/src/she/alleg4/alleg_surface.cpp:11:
/build/source/src/allegro/include/allegro/alcompat.h:44:22: error: conflicting declaration of C function 'fixed fadd(fixed, fixed)'
   44 |       AL_ALIAS(fixed fadd(fixed x, fixed y), fixadd(x, y))
      |                      ^~~~
/build/source/src/allegro/include/allegro/internal/alconfig.h:164:49: note: in definition of macro 'AL_ALIAS'
  164 |       static __attribute__((unused)) __inline__ DECL    \
      |                                                 ^~~~
In file included from /nix/store/y57skwl8a5vbkrjrc30ygdw9vr1p6n19-gcc-9.2.0/include/c++/9.2.0/cmath:45,
                 from /nix/store/y57skwl8a5vbkrjrc30ygdw9vr1p6n19-gcc-9.2.0/include/c++/9.2.0/math.h:36,
                 from /build/source/src/./base/base.h:13,
                 from /build/source/src/./config.h:40,
                 from /build/source/src/she/alleg4/alleg_surface.cpp:8:
/nix/store/2v6pi2wj3lcsc3j48n7flx9mgqyii1lv-glibc-2.30-dev/include/bits/mathcalls-narrow.h:24:20: note: previous declaration 'float fadd(double, double)'
   24 | __MATHCALL_NARROW (__MATHCALL_NAME (add), __MATHCALL_REDIR_NAME (add), 2);
      |                    ^~~~~~~~~~~~~~~

(cherry picked from commit 0ded378b10)
2020-02-19 06:19:43 +00:00
Stig Palmquist
4df09b00cd perlPackages.{CryptCurve25519,MathGMP}: fixed build failures
ZHF: #80379
https://hydra.nixos.org/build/112817446
https://hydra.nixos.org/build/112813918
https://hydra.nixos.org/build/112814931
https://hydra.nixos.org/build/112833536
https://hydra.nixos.org/build/112804942
https://hydra.nixos.org/build/112809869

perlPackages.CryptCurve25519: apply patch from gentoo to fix fmul conflicting
types build breakage.
https://gitweb.gentoo.org/repo/gentoo.git/commit/dev-perl/Crypt-Curve25519?id=e07299f804a8376bb5bf85d28916e0a360199f3e

perlPackages.MathGMP: 2.19 -> 2.20
Updated to latest upstream, which passes tests. This is a dependency of
perlPackages.NetSSH

(cherry picked from commit a43d20b8b4)

cc #80476
2020-02-18 22:23:56 -05:00
Stig Palmquist
8154fd4878 perlPackages.CPAN: apply patch to fix changed YAML module default
ZHF: #80379
https://hydra.nixos.org/build/112819370
https://hydra.nixos.org/build/112832567

A default has changed in YAML, breaking the latest release of CPAN. This commit
applies a A patch from the PR fixing the problem.

https://github.com/andk/cpanpm/pull/133

(cherry picked from commit 153b0db967)
cc #80471
2020-02-18 22:23:12 -05:00
worldofpeace
ebf4836e04 flatpak: use correct p11-kit output
Fixes #80452

(cherry picked from commit 02213fdff2)
2020-02-18 18:15:09 -05:00
Cole Helbling
028effdd17 clippy: add rustc.llvm to buildInputs
The Hydra build [1] failed because it was unable to link to `LLVM9`; add
`llvmShared` to `passthru` in order to stay up to date with required
LLVM versions. Also quote the homepage URLs, since that's preferred.

[1] https://hydra.nixos.org/build/112989779/nixlog/1

(cherry picked from commit 502c0ee899)
2020-02-18 14:10:44 -08:00
Konrad Borowski
7dde515909 cargo-geiger: fix build with rust 1.41
(cherry picked from commit 6637f1cac6)
2020-02-18 22:42:14 +01:00
Daniël de Kok
4dc0c1761c python3Packages.ftfy: 5.6 -> 5.7
Changelog:

https://github.com/LuminosoInsight/python-ftfy/blob/master/CHANGELOG.md#version-57-february-18-2020

The most important change in this version is the update of Unicode
character categories data to Unicode 12.1. This fixes the Python 3.8
build.

(cherry picked from commit 77aa1a7f5b)
2020-02-18 15:03:45 -05:00
Maximilian Bosch
fb06d445af Merge pull request #80438 from KoviRobi/zhf-20.03-fix-xonsh-tests
ZHF: #80379 xonsh: fix broken tests
2020-02-18 19:13:41 +01:00
Jonathan Ringer
f2076d2efb python3Packages.fastparquet: 0.3.2 -> 0.3.3
ZHF: #80379

(cherry picked from commit e24c04f278)
2020-02-18 09:38:34 -08:00
Frederik Rietdijk
07f97d3ed4 Merge pull request #79852 from Ralith/vulkan-1.2
vulkan: 1.1 -> 1.2 (backport to 20.03)
2020-02-18 18:25:59 +01:00
Benjamin Saunders
b85b1e23cd vulkan-tools: 1.1.114.0 -> 1.2.131.1
(cherry picked from commit ad1934b465)
2020-02-18 09:17:35 -08:00
Benjamin Saunders
990fdb4464 shaderc: 2019.0 -> 2019.1
(cherry picked from commit 3b9d71af2c)
2020-02-18 09:17:30 -08:00
Benjamin Saunders
d775ca1040 vulkan-validation-layers: 1.1.114.0 -> 1.2.131.2
(cherry picked from commit d73c83fca5)
2020-02-18 09:17:24 -08:00
Benjamin Saunders
b927b88eea glslang: 7.11.3214 -> 8.13.3559
(cherry picked from commit 533e7c2296)
2020-02-18 09:17:19 -08:00
Benjamin Saunders
3a746e2d4a vulkan-loader: 1.1.144.0 -> 1.2.131.2
(cherry picked from commit eb250b9a00)
2020-02-18 09:17:16 -08:00
Benjamin Saunders
ffa369a57d vulkan-headers: 1.1.144.0 -> 1.2.131.1
(cherry picked from commit 8985abb3c6)
2020-02-18 09:17:11 -08:00
worldofpeace
a1ab61634f Merge pull request #80135 from worldofpeace/backport-79844
[20.03] xfce.xfce4-pulseaudio-plugin: 0.4.1 -> 0.4.2, fix volume
2020-02-18 12:05:27 -05:00
Florian Klink
bd896275f1 Merge pull request #80128 from worldofpeace/backport-79659
[20.03] testing: fix runInMachineWithX/runInMachine
2020-02-18 17:59:33 +01:00
Florian Klink
8c964854b2 Merge pull request #80215 from primeos/brightnessctl-systemd-support-backport
[20.03] brightnessctl: Add systemd support (backport)
2020-02-18 17:49:23 +01:00
edef
370505a6e6 google-cloud-sdk: disable checking for gsutil updates
The update checking mechanism references the tests, and thus
dbaafbbf73 turned it into a crash at
startup.

It isn't much use in nixpkgs, so we're better off without it.

(cherry picked from commit 0c403efde9)
2020-02-18 15:43:23 +01:00
edef
45217d0bd4 google-cloud-sdk: remove gsutil test
The command module references the tests, and since all command modules
get imported at startup, dbaafbbf73
turned it into a startup crash.

Unless you're actively hacking on gsutil, this command isn't much use,
so we're better off without it.

(cherry picked from commit 5bda7e7fb2)
2020-02-18 15:43:22 +01:00
Andreas Rammhold
0399f675e5 Merge pull request #80434 from andir/20.03/firefox73.0.1
[20.03] firefox: 73.0 -> 73.0.1
2020-02-18 15:17:50 +01:00
Kovacsics Robert
bf822c4caa xonsh: Fix broken tests
Pulls in a patch committed a couple of days after the 0.9.13 release
(the one here), to fix the tests.
2020-02-18 13:26:04 +00:00
Andreas Rammhold
1f5135da0b firefox: 73.0 -> 73.0.1
(cherry picked from commit 52920a6b2c)
2020-02-18 13:28:43 +01:00
Georg Haas
302f23cb4f tor-browser-bundle-bin: 9.0.4 -> 9.0.5
(cherry picked from commit ec3daae1fc)
2020-02-18 10:57:35 +01:00
Vladimír Čunát
01d84d1ecf efibootmgr: fixup build on i686
Same as efivar; I believe it doesn't really needs LTO.  I checked:
nix build -f nixos/release-combined.nix nixos.iso_minimal.i686-linux

(cherry picked from commit f595677418)
/cc ZHF: #80379
2020-02-18 10:34:55 +01:00
Francesco Gazzetta
6656178800 milkytracker: set cmake sdl variable to fix build
ZHF: #80379
(cherry picked from commit eb2ab18614)
2020-02-18 09:50:16 +01:00
Mario Rodas
ed7f18b5d2 postgresql_9_5: 9.5.20 -> 9.5.21
Release notes: https://www.postgresql.org/docs/9.5/release-9-5-21.html
2020-02-18 09:22:48 +02:00
Mario Rodas
9e9d5d9f0d postgresql_12: 12.1 -> 12.2
Release notes: https://www.postgresql.org/docs/current/release-12-2.html
2020-02-18 09:20:05 +02:00
Mario Rodas
c60cc121c1 postgresql_11: 11.6 -> 11.7
Release notes: https://www.postgresql.org/docs/11/release-11-7.html
2020-02-18 09:20:05 +02:00
Mario Rodas
d89d10786d postgresql_10: 10.11 -> 10.12
Release notes: https://www.postgresql.org/docs/10/release-10-12.html
2020-02-18 09:20:05 +02:00
Mario Rodas
2197162526 postgresql_9_6: 9.6.16 -> 9.6.17
Release notes: https://www.postgresql.org/docs/9.6/release-9-6-17.html
2020-02-18 09:20:05 +02:00
worldofpeace
d242942b1f pantheon.elementary-files: 4.3.0 -> 4.4.0
https://github.com/elementary/files/releases/tag/4.4.0
(cherry picked from commit 59bf79ec4b)
2020-02-17 21:06:01 -05:00
Silvan Mosberger
fb131bd0c9 Merge pull request #80392 from Infinisil/fix/mint
mint: Pin to crystal 0.30 to fix build
2020-02-18 03:00:34 +01:00
pacien
97935971be riot-web: add config overrides for privacy
Preventing the app from phoning home by default.

GitHub: closes https://github.com/NixOS/nixpkgs/issues/80358
(cherry picked from commit c9e5cca071)
2020-02-17 20:02:27 -05:00
pacien
72fcbcfc40 riot-desktop: 1.5.6 -> 1.5.9
(cherry picked from commit 5bd923057c)
2020-02-17 20:02:27 -05:00
pacien
70e97c8052 riot-web: 1.5.8 -> 1.5.9
(cherry picked from commit 85e09daf43)
2020-02-17 20:02:27 -05:00
rnhmjoj
5c4224e754 python/aiohttp: disable test on 32bit platforms
The test `test_cookiejar` is failing because a time_t
constant can't be represented on 32bit platforms.

(cherry picked from commit 6be8389b04)
2020-02-17 19:48:29 -05:00
zowoq
e6febf8f7e flatpak: 1.6.1 -> 1.6.2
https://github.com/flatpak/flatpak/releases/tag/1.6.2
(cherry picked from commit d744b4f928)
2020-02-17 19:42:27 -05:00
worldofpeace
33ce841a55 flatpak: add dev output
(cherry picked from commit 26f1d1e81b)
2020-02-17 19:42:27 -05:00
worldofpeace
4603e7085a flatpak: propagate glib and ostree
Pantheon's sideload broke:
```
meson.build:17:0: ERROR: Could not generate cargs for flatpak:
Package ostree-1 was not found in the pkg-config search path.
Perhaps you should add the directory containing `ostree-1.pc'
to the PKG_CONFIG_PATH environment variable
Package 'ostree-1', required by 'flatpak', not found
```

https://hydra.nixos.org/build/113077888

ZHF: #80379
(cherry picked from commit 461ea02544)
2020-02-17 19:42:27 -05:00
Silvan Mosberger
798524fba4 mint: Pin to crystal 0.30 to fix build 2020-02-18 01:41:22 +01:00
Silvan Mosberger
51991d7752 Merge pull request #80389 from Infinisil/fix/crystal
crystal_0_32: Fix hydra build on 20.03
2020-02-18 01:34:14 +01:00
Dylan Simon
81e6859218 scalapack: 2.1 -> 2.1.0
2.1 seems to have disappeared

(cherry picked from commit e25f0b3e3d)
2020-02-18 01:30:46 +01:00
Silvan Mosberger
fc1bbc0f04 crystal_0_32: Fix hydra build
It seems that there might be hydra machines that run an older version of Nix
where https://github.com/NixOS/nix/pull/2878 is not yet included
(unconfirmed)

In addition crystal 0.32.1 has a bug that only occurs when there is no
tty: https://github.com/crystal-lang/crystal/issues/8609

Combining this lead to a crystal build failing: https://hydra.nixos.org/build/113074265

This fixes that probably rather uncommon occurence by applying the
upstream fix for the bug: https://github.com/crystal-lang/crystal/issues/8609
2020-02-18 01:29:48 +01:00
R. RyanTM
6c6ac9a5c8 gnome3.accerciser: 3.34.3 -> 3.34.4
(cherry picked from commit 124ff1a3fa)
2020-02-17 18:15:04 -05:00
Robert Scott
194c1ea3de pythonPackages.pysaml2: fix tests with fixed & now-expired timestamps
these only expired (and upstream only seem to have noticed) today

ZHF: #80379
https://hydra.nixos.org/build/112818101

(cherry picked from commit f77e057cda)
2020-02-17 23:44:22 +01:00
Benjamin Slade
3ffada4169 mullvad-vpn: 2020.1 -> 2020.2
(cherry picked from commit f2e5bb967f)
2020-02-17 21:14:11 +00:00
Vladimír Čunát
1a6b6e9124 efivar: fixup build on i686
I don't think it really needs LTO.

(cherry picked from commit 9b4424cbb7)
2020-02-17 21:06:19 +01:00
Eelco Dolstra
181e0d854c nixos/release-small.nix: List constituents of the 'tested' job by name
https://github.com/NixOS/hydra/issues/715
(cherry picked from commit 895042956f)
2020-02-17 19:41:55 +01:00
Eelco Dolstra
f996744fd3 nixos/release-combined.nix: List constituents of the 'tested' job by name
https://github.com/NixOS/hydra/issues/715
(cherry picked from commit 2de3caf011)
2020-02-17 19:41:08 +01:00
Vladimír Čunát
e168b5a2e1 release-combined: readd keymap tests
This reverts commit ceb90b08ef.
2020-02-17 19:39:14 +01:00
Jörg Thalheim
47dfd37e5a Merge pull request #80172 from Mic92/knot-backport
[20.03-backport] knot: keyFiles, no dynamicUser
2020-02-17 17:23:58 +00:00
jakobrs
07244aa21b electron: correct casing of MacOS (#80362)
(cherry picked from commit 35bae4f749)
cc #80362
2020-02-17 12:03:13 -05:00
OmnipotentEntity
0b4c592114 geant4: 10.6.0 -> 10.6.1 (#80365)
(cherry picked from commit eb40131310)
cc #80365
2020-02-17 12:00:40 -05:00
Thomas Tuegel
04ffd910b2 kinit: Increase environment size limit
start_kdeinit reads its environment over a pipe from start_kdeinit_wrapper. For
security, each environment entry must be smaller than 4kb by default. Qt-based
applications in Nixpkgs may have larger environments, and the recent upgrade to
Plasma 5.17 pushed start_kdeinit_wrapper over the limit. The limit is now
extended to 16kb.

This problem was not detected during testing because the failure is silent:
start_kdeinit will continue with an empty environment. In other circumstances,
this strategy might work, but it does not work on NixOS. This failure is now
treated as a fatal error.

Fixes: #79707
(cherry picked from commit c75860918f)
2020-02-17 09:13:03 -06:00
Franz Pletz
337d0b3509 dovecot: 2.3.9.2 -> 2.3.9.3
Fixes CVE-2020-7046 & CVE-2020-7957:

  https://dovecot.org/pipermail/dovecot-news/2020-February/000429.html

(cherry picked from commit f9a34082e6)
2020-02-17 15:27:55 +01:00
Frederik Rietdijk
5abddd16e4 Merge release-20.03 into staging-20.03 2020-02-17 15:14:17 +01:00
Benjamin Hipple
bee35e73e2 doomseeker: add qt wrapper, cleanup (#79794)
This avoids using NIX_CFLAGS_COMPILE by switching to hardeningDisable.
The hack is also only needed for darwin sources and is not specific to
clang.

Co-authored-by: Dmitry Kalinkin <dmitry.kalinkin@gmail.com>

(cherry picked from commit 5ef4af7afc)
cc #79794
2020-02-17 04:58:31 -05:00
Maximilian Bosch
45e870cf6c nextcloud-client: 2.6.2 -> 2.6.3
https://github.com/nextcloud/desktop/releases/tag/v2.6.3
(cherry picked from commit ed944d4cee)
2020-02-17 08:02:52 +01:00
Maximilian Bosch
47446c7140 mautrix-whatsapp: 2020-01-12 -> 2020-02-09
(cherry picked from commit 52981cedfd)
2020-02-17 08:02:51 +01:00
Dmitry Kalinkin
13b151cfe7 soundfont-fluid: fix src url
(cherry picked from commit e019371ab4)
cc #80174
2020-02-16 23:45:10 -05:00
Maximilian Bosch
a3d6e9ed9a youtube-dl: 2020.01.24 -> 2020.02.16
https://github.com/ytdl-org/youtube-dl/releases/tag/2020.02.16
(cherry picked from commit 7957f43b6a)
2020-02-17 00:18:41 +01:00
Tor Hedin Brønner
075ce56cb3 gnomeExtensions.gsconnect: fix build
dbus is now propagated from at-spi2-core, which made gsconnect try to
install dbus service files in the wrong location.

closes https://github.com/NixOS/nixpkgs/issues/79806

(cherry picked from commit 71a54f1130)
2020-02-16 15:17:55 +01:00
Eelco Dolstra
e421d740cb nixUnstable, nixFlakes: Update to latest
Note that we need to build from a tarball now to get the vendored
crates. A bit ugly to fetch tarballs from Hydra...

(cherry picked from commit dd7f6b0c6b)
2020-02-16 11:18:39 +01:00
taku0
08c4b48d3a flashplayer: 32.0.0.314 -> 32.0.0.330
(cherry picked from commit 87d9d9a374)
2020-02-16 09:20:41 +01:00
Frederik Rietdijk
64f497550e Merge release-20.03 into staging-20.03 2020-02-16 09:13:01 +01:00
Frederik Rietdijk
642541f5d0 Merge staging-20.03 insto release-20.03 2020-02-16 09:12:24 +01:00
Michael Weiss
e8042ed139 nixos/brightnessctl: Remove the module
Due to the support of the systemd-logind API the udev rules aren't
required anymore which renders this module useless [0].
Note: brightnessctl should now require a working D-Bus setup and a valid
local logind session for this to work.

[0]: https://github.com/NixOS/nixpkgs/pull/79663

(cherry picked from commit 5282bc9a74)
2020-02-16 00:01:37 +01:00
Michael Weiss
9229faee7d brightnessctl: Add systemd support
This makes it possible to use brightnessctl without udev rules / suid.

(cherry picked from commit cf5dd2623b)
2020-02-16 00:01:37 +01:00
worldofpeace
15992aae7b Merge #80120: webkitgtk: 2.26.3 -> 2.26.4 (security!)
(cherry picked from commit 03d5f9cf1f)
I re-checked it builds.  20.03 shouldn't have diverged much,
so I trust it will work the same.
2020-02-15 23:13:15 +01:00
Vladimír Čunát
306d76f357 openssl: revert a workaround that's no longer needed
Thanks to python3Minimal.  This reverts part of c2038483f #79738.

(cherry picked from commit 5a8000dc05)
2020-02-15 15:21:27 -05:00
Vladimír Čunát
ced2b5a7dd glibc: use python3Minimal instead of python3
This should improve the speed of bootstrapping process.
Cost of evaluation also decreases a bit,
but I don't expect that will be significant.

(cherry picked from commit f6519103bf)
2020-02-15 15:21:27 -05:00
worldofpeace
f43895474f Merge pull request #80200 from ilya-fedin/backport-fix-xdg-current-desktop
Backport DesktopNames parameter to 20.03
2020-02-15 15:17:58 -05:00
Eelco Dolstra
6948bfce69 nixos/modules/misc/version.nix: Don't parse .git
This leads to inconsistent results between local builds and
Hydra. Also Nix is not a general purpose language, we shouldn't be
parsing .git from inside Nix code.

(cherry picked from commit f0f040c3f7)
2020-02-15 15:04:40 -05:00
Eelco Dolstra
accf1c7e44 nixos/modules/installer/cd-dvd/channel.nix: Handle null config.system.nixos.revision
(cherry picked from commit a5f883e535)
2020-02-15 15:04:36 -05:00
Michael Weiss
25955ae7c1 fscrypt-experimental: 0.2.5 -> 0.2.6 (#79853)
Changelog: https://github.com/google/fscrypt/releases/tag/v0.2.6
(cherry picked from commit ac758caff1)
Reason: Since NixOS 20.03 will ship with Linux kernel 5.4 by default,
the new support for v2 kernel encryption policies is useful.
2020-02-15 20:21:52 +01:00
Michael Weiss
51e1cb0d93 google-chrome*: Add the newly required dependencies
See 3fadc45499. Since the beta channel is now also on 81 and the stable
channel will be on 81 soon, it makes sense to already add this
unconditionally for all channels.

(cherry picked from commit 67f349d224)
Backport of #80074.
2020-02-15 20:02:52 +01:00
Ilya Fedin
75f90af321 nixos/display-managers: Add DesktopNames parameter to generated desktop session files
Some display managers (e.g. SDDM) set the XDG_CURRENT_DESKTOP variable accroding to this parameter.
If this variable is not defined, there will be some problems (e.g. MATE doesn't have icons on the desktop).

Fixes https://github.com/NixOS/nixpkgs/issues/71427

(cherry picked from commit f7768c939a)
2020-02-15 23:02:12 +04:00
Maximilian Bosch
b6551f4ca5 nixos/nixos-build-vms: switch to python test-driver
In 0945178b3c we decided that Perl-based
VM tests should be deprecated and will be removed between 20.03 and
20.09. So let's switch `nixos-build-vms(8)` to python as well (which is
entirely interactive, so other scripts won't break).

In my experience, the test-driver isn't used most of the time, so this
patch is mainly supposed to get rid of the (probably misleading)
deprecation warning when running `nixos-build-vms`. Apart from that, the
interface for python's test-driver is way nicer.

(cherry picked from commit c391343fcd)
2020-02-15 19:37:48 +01:00
Graham Christensen
419bebfe42 nixos/release.nix: correct revCount offset
Not sure how 1350291 was reached, but it is causing evaluation errors.

Recalculating on the 20.03-beta tag gets me 212938, so updating.
2020-02-15 11:55:59 -05:00
Maximilian Bosch
1e92961486 python3Packages.mautrix: 0.4.1 -> 0.4.2
https://pypi.org/project/mautrix/0.4.2/
(cherry picked from commit ade5a50b0f)
2020-02-15 17:07:53 +01:00
David Terry
50edd0f565 linuxPackages.wireguard: 0.0.20200214 -> 0.0.20200215
(cherry picked from commit b76dab8fc8)
2020-02-15 12:49:04 +01:00
Jörg Thalheim
8325e2b36d knot: add keyFiles option
This useful to include tsig keys using nixops without adding those
world-readable to the nix store.

(cherry picked from commit e2ef8b439f)
2020-02-15 11:16:44 +00:00
Jörg Thalheim
0af3b7580a knot: drop dynamic user
This makes it hard to include secret files.
Also using tools like keymgr becomes harder.

(cherry picked from commit 88029bce39)
2020-02-15 11:16:42 +00:00
Jörg Thalheim
e989a193e6 knot: put runtime paths outside the nix store
Otherwise knot tries to write to non-writable directories.
This for example breaks dnssec signing.
While it's possible to overwrite these path in the configuration,
having a sane defaults is nicer.

(cherry picked from commit 6adc09ed30)
2020-02-15 11:16:40 +00:00
Maximilian Bosch
10c6239bf3 mono: fix build w/glibc-2.30
(cherry picked from commit c30b4a746f)
2020-02-14 14:33:24 -05:00
worldofpeace
bbf602546c xfce.xfce4-pulseaudio-plugin: 0.4.1 -> 0.4.2, fix volume
We needed to add keybinder3.

(cherry picked from commit 8e5ed7cfbb)
2020-02-14 14:23:19 -05:00
Samuel Leathers
63772f7f99 python3Packages.openapi-spec-validator: add setuptools
(cherry picked from commit a721edfabb)
2020-02-14 12:56:04 -05:00
worldofpeace
d074d34343 testing: fix runInMachineWithX
(cherry picked from commit 5507e09618)
2020-02-14 12:45:55 -05:00
worldofpeace
aea80290ef testing-python: readd auto displayManager
we import it for the runInMachineWithX

(cherry picked from commit 88f76812f2)
2020-02-14 12:45:55 -05:00
worldofpeace
fbfa6ac077 testing-python: fix runInMachine
The test script's were unported.
It's unclear whether the preBuild or
postBuild will work as expect, due to
the linting of the test scripts.

(cherry picked from commit fa9af83e96)
2020-02-14 12:45:55 -05:00
Vladimír Čunát
ad29694571 Merge #62890: libclc: 2017-11-29 -> 2019-06-09 (unbreak)
(cherry picked from commit ed77cf1c56)
2020-02-14 17:59:30 +01:00
Maximilian Bosch
2e83e4ee34 linuxPackages.wireguard: 0.0.20200205 -> 0.0.20200214
https://lists.zx2c4.com/pipermail/wireguard/2020-February/005013.html
(cherry picked from commit 7666bf47c7)
2020-02-14 17:32:47 +01:00
Michael Weiss
7f99e2c100 chromium: 80.0.3987.100 -> 80.0.3987.106
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_13.html
(cherry picked from commit 574a57a67f)
Backport of #80074.
2020-02-14 13:20:41 +01:00
Jyun-Yan You
e9d271f1f4 nixos/pppd: fix build error
(cherry picked from commit 0f8d1ac47d)
2020-02-14 11:03:08 +01:00
rnhmjoj
3c103bd93d nixos/unclutter: fix remaining typo
Fix an evaluation warning.

(cherry picked from commit f01bcccd25)
2020-02-14 10:40:13 +01:00
rnhmjoj
6a179f0555 nixos/alsa: replace list by attrset in environment.etc
Fix an evaluation warning.

(cherry picked from commit 2ad680ac73)
2020-02-14 10:38:18 +01:00
Mario Rodas
0b3697e700 docker-slim: move expression to outside of build-support (#80078)
(cherry picked from commit 7696369bec)
2020-02-14 09:43:00 +01:00
Michael Weiss
f9bcb42529 google-chrome-dev: Add the newly required dependencies
google-chrome-unstable won't launch without the following shared object
files: libdrm.so.2 and libgbm.so.1.

(cherry picked from commit 3fadc45499)
2020-02-14 01:39:16 +01:00
Michael Weiss
266abf70df chromium: 80.0.3987.87 -> 80.0.3987.100
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_11.html
(cherry picked from commit e61b8d99c2)
2020-02-14 01:39:08 +01:00
Georg Haas
38152c4e78 bino3d: use mkDerivation from qt
adopted solution from commit 7e0dd3833d

(cherry picked from commit c9ca90af51)
2020-02-14 00:20:08 +01:00
Ben Darwin
95bf506b90 c3d: unbreak via stdenv -> gcc8Stdenv
(cherry picked from commit 1112bcc75e)
2020-02-13 17:50:11 -05:00
Ben Darwin
dee6990b90 c3d: 2018-10-04 -> unstable-2019-10-22; mark unbroken
(cherry picked from commit c79d6d0430)
2020-02-13 17:50:11 -05:00
Florian Klink
4171378761 gitlab: 12.7.5 -> 12.7.6
(cherry picked from commit 0a87568b03)
2020-02-13 23:43:11 +01:00
Vladimír Čunát
ceb90b08ef Revert-like "Merge #79656: release-combined: readd keymap tests"
It's a temporary measure until we have better ways.  See #79907.
(Not a real revert, as the comment wouldn't make sense, etc.)
2020-02-13 19:49:32 +01:00
Marek Mahut
7e4eea6d74 Merge pull request #79903 from mmahut/trezord-backport
(20.03) trezord-go: 2.0.27 -> 2.0.28
2020-02-13 17:31:16 +01:00
taku0
0ce2f49473 thunderbird: 68.4.2 -> 68.5.0
(cherry picked from commit 64fe2b7260)
2020-02-13 14:06:23 +01:00
taku0
7e10d60c80 thunderbird-bin: 68.4.2 -> 68.5.0
(cherry picked from commit eaf12cc4d1)
2020-02-13 14:06:20 +01:00
rnhmjoj
313414d650 rxvt-unicode/vtwheel: use new package name for rxvt-unicode
(cherry picked from commit 91f81e84de)
2020-02-13 11:19:43 +01:00
rnhmjoj
2defe9ded6 nixos/sway: use new package name for rxvt-unicode
(cherry picked from commit ceb35dac58)
2020-02-13 11:19:35 +01:00
rnhmjoj
2d4842ec22 nixos/urxvtd: use new package name for rxvt-unicode
(cherry picked from commit 9290e6e7ba)
2020-02-13 11:19:21 +01:00
rnhmjoj
1da1f3fbf2 rxvt-unicode: fix typo in aliases.nix
This fixes an evaluation error when services.urxvtd is enabled.

(cherry picked from commit 72bdf27771)
2020-02-13 11:16:51 +01:00
Jonathan Ringer
66e115ea89 python3Packages.numba: disable for python < 3.6
(cherry picked from commit 984eb94496)
2020-02-13 08:21:08 +01:00
Nikolay Korotkiy
125e5baf0d opencc: enable on darwin
(cherry picked from commit 5c8356105c)
2020-02-12 18:43:39 -05:00
worldofpeace
ae62101af8 Merge pull request #79950 from puckipedia/signal-desktop-notifications-20.03
[20.03] signal-desktop: fix notifications
2020-02-12 17:45:22 -05:00
Puck Meerburg
a4cddd0ae5 signal-desktop: fix notifications
(cherry picked from commit 0b3e5db5d3)
2020-02-12 22:43:16 +00:00
R. RyanTM
f54d7568be quilter: 2.1.0 -> 2.1.1
(cherry picked from commit 3a9a0f299a)
2020-02-12 16:57:10 -05:00
Florian Klink
9fafbd1f6f nixos/filesystems: don't chown /run/keys recursively
3c74e48d9c was a bit too much, it updated
permissions of all files recursively, causing files to be readable by
the group.

This isn't a problem immediately after bootup, but on a new activation,
as tmpfiles.d get restarted then, updating the permission bits of
now-existing files.

This updates the `Z` to be a `z` (the non-recursive variant), and adds a
`d` to ensure a directory is created (which should be covered by the
initrd shell script anyway)

(cherry picked from commit 4c8bdd1c4f)
2020-02-12 17:52:53 +01:00
Andreas Rammhold
2053cb0593 Merge pull request #79914 from andir/20.03/firefox73
[20.03] firefox 73
2020-02-12 17:17:25 +01:00
Vladimír Čunát
78a273da0a Merge #79740: libssh2: patch CVE-2019-17498
(cherry picked from commit 4ff2a1641c)
2020-02-12 13:09:53 +01:00
Hlöðver Sigurðsson
2ebeaa9e43 clojure 1.10.1.492 -> 1.10.1.507 plus bugfix (#79868)
(cherry picked from commit 91801c0b45)
2020-02-12 11:51:40 +00:00
Andreas Rammhold
ae03096e50 nixos/tests/firefox: support running the test with the firefox ESR version
Also adds this to the release jobset.

(cherry picked from commit 7a625e7453)
2020-02-12 11:25:15 +01:00
Andreas Rammhold
7deaadc143 firefox-esr: 68.4.2esr -> 68.5.0esr
(cherry picked from commit f43fdd1151)
2020-02-12 11:25:15 +01:00
Andreas Rammhold
5cc5f7bf3f firefox-bin: 72.0.3 -> 73.0
(cherry picked from commit 11920736e8)
2020-02-12 11:25:15 +01:00
Andreas Rammhold
db66f71737 firefox: 72.0.2 -> 73.0
(cherry picked from commit 8019df98f8)
2020-02-12 11:25:15 +01:00
Andreas Rammhold
3187daaec0 firefox: prepare for 73.0
(cherry picked from commit 187d6912a8)
2020-02-12 11:25:15 +01:00
Andreas Rammhold
662591b085 rust-cbindgen: 0.10.0 -> 0.13.1
(cherry picked from commit 82d9ce45fe)
2020-02-12 11:25:15 +01:00
Andreas Rammhold
99c958f076 nss: 3.48 -> 3.49.2
(cherry picked from commit 48603cd9d7)
2020-02-12 11:25:15 +01:00
Marek Mahut
9690c7e2c6 trezord-go: 2.0.27 -> 2.0.28
(cherry picked from commit ab1a14d581)
2020-02-12 08:43:34 +01:00
Martin Milata
d903c899f9 gunicorn: add 19.x branch for python2.7 support
The nixos/moinmoin module uses gunicorn, however the 20.0 version
dropped python2 support which broke the module as there's no python3
port planned for moinmoin: http://moinmo.in/Python3

(cherry picked from commit d202e9eac2b3e17c8598b941a11025cef31c762f)
2020-02-11 22:25:21 +01:00
Izorkin
94c380cbb7 zsh: fix bracketed-paste-magic
(cherry picked from commit 8f5af404d2)
2020-02-11 18:50:38 +00:00
Samuel Dionne-Riel
b2e203bd6f Merge pull request #79826 from worldofpeace/remove-sd_image_raspberrypi4
[20.03] Remove sd image raspberrypi4
2020-02-11 13:39:01 -05:00
Milan Pässler
6e73318160 tipp10: init at 3.1.0
(cherry picked from commit 7fbc860d72)
2020-02-11 17:41:53 +00:00
Michele Guerini Rocco
d3d8d5ce6c Merge pull request #79833 from tokudan/20.03/encrypted-swap-entropy-fix
rngd: Start early during boot and encrypted swap entropy fix [20.03]
2020-02-11 16:37:37 +01:00
Maximilian Bosch
23dfaf07c6 pinentry_qt5: alias to pinentry-qt
Attribute was removed in a4916fdea5 which
will land in 20.03, but breaks evaluation for everyone using
pinentry_qt5 on NixOS 19.09 when updating.

(cherry picked from commit 3d1007716c)
2020-02-11 16:10:38 +01:00
Daniel Frank
4579f11c20 security.rngd: start rngd during early boot to reduce entropy starvation due to encrypted swap and remove PrivateTmp to avoid a circular dependency
(cherry picked from commit d14ba1e1ad)
2020-02-11 15:23:28 +01:00
Daniel Frank
93bd12da91 swap: depend on rngd if enabled and randomEncryption is configured to
avoid entropy starvation during boot

(cherry picked from commit 1ac86e14c7)
2020-02-11 15:23:28 +01:00
worldofpeace
40a420e38b release: remove sd_image_raspberrypi4 2020-02-11 08:28:35 -05:00
Justin Bedo
1781000f03 delly: 0.8.1 -> 0.8.2
Backported patch required for htslib 1.10.2

(cherry picked from commit a8fe9e7aff)
2020-02-11 03:54:51 -05:00
Dmitry Kalinkin
b0aa920b4d libtasn1: fix on darwin
Test binaries are linked to the libraries at their install path, but
those are not installed when checkPhase executes.

(cherry picked from commit 7cc5d84cd7)
2020-02-11 07:43:40 +01:00
zimbatm
f8f607b824 ruby_2_4: remove
According to https://endoflife.software/programming-languages/server-side-scripting/ruby
ruby 2.4 will go end-of-life in march, where the new release of nixpkgs
will be cut. We won't be able to support it for security updates.

Remove all references to ruby_2_4 and add ruby_2_7 instead where
missing.

Mark packages that depend on ruby 2.4 as broken:
* chefdk
* sonic-pi

(cherry picked from commit bcdc90a3a7)
2020-02-10 16:29:07 -05:00
worldofpeace
793fc88dbe 20.03 beta release 2020-02-10 15:10:02 -05:00
1974 changed files with 59803 additions and 34385 deletions

View File

@@ -53,9 +53,9 @@ For package version upgrades and such a one-line commit message is usually suffi
To [backport a change into a release branch](https://nixos.org/nixpkgs/manual/#submitting-changes-stable-release-branches):
1. Take note of the commit in which the change was introduced into `master`.
2. Check out the target _release branch_, e.g. `release-19.09`. Do not use a _channel branch_ like `nixos-19.09` or `nixpkgs-19.09`.
2. Check out the target _release branch_, e.g. `release-20.03`. Do not use a _channel branch_ like `nixos-20.03` or `nixpkgs-20.03`.
3. Use `git cherry-pick -x <original commit>`.
4. Open your backport PR. Make sure to select the release branch (e.g. `release-19.09`) as the target branch of the PR, and link to the PR in which the original change was made to `master`.
4. Open your backport PR. Make sure to select the release branch (e.g. `release-20.03`) as the target branch of the PR, and link to the PR in which the original change was made to `master`.
## Reviewing contributions

View File

@@ -6,7 +6,7 @@
<!-- Please check what applies. Note that these are not hard requirements but merely serve as information for reviewers. -->
- [ ] Tested using sandboxing ([nix.useSandbox](http://nixos.org/nixos/manual/options.html#opt-nix.useSandbox) on NixOS, or option `sandbox` in [`nix.conf`](http://nixos.org/nix/manual/#sec-conf-file) on non-NixOS linux)
- [ ] Tested using sandboxing ([nix.useSandbox](https://nixos.org/nixos/manual/options.html#opt-nix.useSandbox) on NixOS, or option `sandbox` in [`nix.conf`](https://nixos.org/nix/manual/#sec-conf-file) on non-NixOS linux)
- Built on platform(s)
- [ ] NixOS
- [ ] macOS

View File

@@ -44,9 +44,9 @@ Nixpkgs and NixOS are built and tested by our continuous integration
system, [Hydra](https://hydra.nixos.org/).
* [Continuous package builds for unstable/master](https://hydra.nixos.org/jobset/nixos/trunk-combined)
* [Continuous package builds for the NixOS 19.09 release](https://hydra.nixos.org/jobset/nixos/release-19.09)
* [Continuous package builds for the NixOS 20.03 release](https://hydra.nixos.org/jobset/nixos/release-20.03)
* [Tests for unstable/master](https://hydra.nixos.org/job/nixos/trunk-combined/tested#tabs-constituents)
* [Tests for the NixOS 19.09 release](https://hydra.nixos.org/job/nixos/release-19.09/tested#tabs-constituents)
* [Tests for the NixOS 20.03 release](https://hydra.nixos.org/job/nixos/release-20.03/tested#tabs-constituents)
Artifacts successfully built with Hydra are published to cache at
https://cache.nixos.org/. When successful build and test criteria are

View File

@@ -112,7 +112,7 @@
</para>
<para>
The exact syntax and semantics of the Nix expression language, including the built-in function, are described in the Nix manual in the <link
xlink:href="http://hydra.nixos.org/job/nix/trunk/tarball/latest/download-by-type/doc/manual/#chap-writing-nix-expressions">chapter on writing Nix expressions</link>.
xlink:href="https://hydra.nixos.org/job/nix/trunk/tarball/latest/download-by-type/doc/manual/#chap-writing-nix-expressions">chapter on writing Nix expressions</link>.
</para>
</listitem>
<listitem>

View File

@@ -407,23 +407,47 @@ Additional information.
<section xml:id="submitting-changes-stable-release-branches">
<title>Stable release branches</title>
<itemizedlist>
<para>
For cherry-picking a commit to a stable release branch (<quote>backporting</quote>), use <literal>git cherry-pick -x &lt;original commit&gt;</literal> so that the original commit id is included in the commit.
</para>
<para>
Add a reason for the backport by using <literal>git cherry-pick -xe &lt;original commit&gt;</literal> instead when it is not obvious from the original commit message. It is not needed when its a minor version update that includes security and bug fixes but dont add new features or when the commit fixes an otherwise broken package.
</para>
<para>
Here is an example of a cherry-picked commit message with good reason description:
</para>
<screen>
zfs: Keep trying root import until it works
Works around #11003.
(cherry picked from commit 98b213a11041af39b39473906b595290e2a4e2f9)
Reason: several people cannot boot with ZFS on NVMe
</screen>
<para>
Other examples of reasons are:
</para>
<itemizedlist spacing="compact">
<listitem>
<para>
If you're cherry-picking a commit to a stable release branch (“backporting”), always use <command>git cherry-pick -xe</command> and ensure the message contains a clear description about why this needs to be included in the stable branch.
Previously the build would fail due to, e.g., <literal>getaddrinfo</literal> not being defined
</para>
</listitem>
<listitem>
<para>
An example of a cherry-picked commit would look like this:
The previous download links were all broken
</para>
</listitem>
<listitem>
<para>
Crash when starting on some X11 systems
</para>
<screen>
nixos: Refactor the world.
The original commit message describing the reason why the world was torn apart.
(cherry picked from commit abcdef)
Reason: I just had a gut feeling that this would also be wanted by people from
the stone age.
</screen>
</listitem>
</itemizedlist>
</section>

View File

@@ -167,7 +167,7 @@ parameters that the SDK composition function (the function shown in the
previous section) supports.
This build function is particularly useful when it is desired to use
[Hydra](http://nixos.org/hydra): the Nix-based continuous integration solution
[Hydra](https://nixos.org/hydra): the Nix-based continuous integration solution
to build Android apps. An Android APK gets exposed as a build product and can be
installed on any Android device with a web browser by navigating to the build
result page.

View File

@@ -66,6 +66,6 @@ crystal.buildCrystalPackage rec {
shardsFile = ./shards.nix;
crystalBinaries.mint.src = "src/mint.cr";
buildInputs = [ openssl_1_0_2 ];
buildInputs = [ openssl ];
}
```

View File

@@ -233,7 +233,7 @@ mkDerivation {
</term>
<listitem>
<para>
You can rely on applications depending on the library set the necessary environment variables but that it often easy to miss. Instead we recommend to patch the paths in the source code whenever possible. Here are some examples:
You can rely on applications depending on the library setting the necessary environment variables but that is often easy to miss. Instead we recommend to patch the paths in the source code whenever possible. Here are some examples:
<itemizedlist>
<listitem xml:id="ssec-gnome-common-issues-unwrappable-package-gnome-shell-ext">
<para>

View File

@@ -112,8 +112,10 @@ haskell.compiler.ghc865 ghc-8.6.5
haskell.compiler.integer-simple.ghc865 ghc-8.6.5
haskell.compiler.ghc881 ghc-8.8.1
haskell.compiler.integer-simple.ghc881 ghc-8.8.1
haskell.compiler.ghc882 ghc-8.8.1.20191211
haskell.compiler.integer-simple.ghc882 ghc-8.8.1.20191211
haskell.compiler.ghc882 ghc-8.8.2
haskell.compiler.integer-simple.ghc882 ghc-8.8.2
haskell.compiler.ghc883 ghc-8.8.3
haskell.compiler.integer-simple.ghc883 ghc-8.8.3
haskell.compiler.ghcjs ghcjs-8.6.0.1
```
@@ -367,7 +369,7 @@ automatically select the right version of GHC and other build tools to build,
test and execute apps in an existing project downloaded from somewhere on the
Internet. Pass the `--nix` flag to any `stack` command to do so, e.g.
```shell
git clone --recursive https://github.com/yesodweb/wai
git clone --recurse-submodules https://github.com/yesodweb/wai.git
cd wai
stack --nix build
```

View File

@@ -18,7 +18,7 @@ The primary objective of this project is to use the Nix expression language to
specify how iOS apps can be built from source code, and to automatically spawn
iOS simulator instances for testing.
This component also makes it possible to use [Hydra](http://nixos.org/hydra),
This component also makes it possible to use [Hydra](https://nixos.org/hydra),
the Nix-based continuous integration server to regularly build iOS apps and to
do wireless ad-hoc installations of enterprise IPAs on iOS devices through
Hydra.

View File

@@ -1,7 +1,7 @@
<book xmlns="http://docbook.org/ns/docbook"
xmlns:xi="http://www.w3.org/2001/XInclude">
<info>
<title>Nixpkgs Users and Contributors Guide</title>
<title>Nixpkgs Manual</title>
<subtitle>Version <xi:include href=".version" parse="text" />
</subtitle>
</info>

View File

@@ -42,7 +42,7 @@ distributed as soon as all tests for that channel pass, e.g.
[this table](https://hydra.nixos.org/job/nixpkgs/trunk/unstable#tabs-constituents)
shows the status of tests for the `nixpkgs` channel.
The tests are conducted by a cluster called [Hydra](http://nixos.org/hydra/),
The tests are conducted by a cluster called [Hydra](https://nixos.org/hydra/),
which also builds binary packages from the Nix expressions in Nixpkgs for
`x86_64-linux`, `i686-linux` and `x86_64-darwin`.
The binaries are made available via a [binary cache](https://cache.nixos.org).

View File

@@ -286,7 +286,7 @@ export NIX_MIRRORS_sourceforge=http://osdn.dl.sourceforge.net/sourceforge/</prog
<note>
<para>
This release of Nixpkgs requires <link
xlink:href='http://nixos.org/releases/nix/nix-0.10/'>Nix 0.10</link> or higher.
xlink:href='https://nixos.org/releases/nix/nix-0.10/'>Nix 0.10</link> or higher.
</para>
</note>
@@ -436,7 +436,7 @@ stdenv.mkDerivation {
<listitem>
<para>
Distribution files have been moved to <link
xlink:href="http://nixos.org/" />.
xlink:href="https://nixos.org/" />.
</para>
</listitem>
<listitem>

View File

@@ -1,8 +1,6 @@
# Experimental flake interface to Nixpkgs.
# See https://github.com/NixOS/rfcs/pull/49 for details.
{
edition = 201909;
description = "A collection of packages for the Nix package manager";
outputs = { self }:
@@ -25,7 +23,7 @@
import ./nixos/lib/eval-config.nix (args // {
modules = modules ++
[ { system.nixos.versionSuffix =
".${lib.substring 0 8 self.lastModified}.${self.shortRev or "dirty"}";
".${lib.substring 0 8 (self.lastModifiedDate or self.lastModified)}.${self.shortRev or "dirty"}";
system.nixos.revision = lib.mkIf (self ? rev) self.rev;
}
];

View File

@@ -649,6 +649,13 @@ lib.mapAttrs (n: v: v // { shortName = n; }) {
url = http://metadata.ftp-master.debian.org/changelogs/main/d/debianutils/debianutils_4.8.1_copyright;
};
sspl = {
shortName = "SSPL";
fullName = "Server Side Public License";
url = https://www.mongodb.com/licensing/server-side-public-license;
free = false;
};
tcltk = spdx {
spdxId = "TCL";
fullName = "TCL/TK License";

View File

@@ -159,7 +159,7 @@ rec {
let ss = opt.type.getSubOptions opt.loc;
in if ss != {} then optionAttrSetToDocList' opt.loc ss else [];
in
[ docOption ] ++ subOptions) (collect isOption options);
[ docOption ] ++ optionals docOption.visible subOptions) (collect isOption options);
/* This function recursively removes all derivation attributes from

View File

@@ -148,10 +148,14 @@ rec {
# packed-refs file, so we have to grep through it:
then
let fileContent = readFile packedRefsName;
matchRef = match (".*\n([^\n ]*) " + file + "\n.*") fileContent;
in if matchRef == null
matchRef = builtins.match "([a-z0-9]+) ${file}";
isRef = s: builtins.isString s && (matchRef s) != null;
# there is a bug in libstdc++ leading to stackoverflow for long strings:
# https://github.com/NixOS/nix/issues/2147#issuecomment-659868795
refs = builtins.filter isRef (builtins.split "\n" fileContent);
in if refs == []
then throw ("Could not find " + file + " in " + packedRefsName)
else lib.head matchRef
else lib.head (matchRef (lib.head refs))
else throw ("Not a .git directory: " + path);
in readCommitFromFile "HEAD";

View File

@@ -178,7 +178,7 @@ rec {
let suffixFile = ../.version-suffix;
in if pathExists suffixFile
then lib.strings.fileContents suffixFile
else "pre-git";
else "post-git";
/* Attempts to return the the current revision of nixpkgs and
returns the supplied default value otherwise.

View File

@@ -1427,6 +1427,16 @@
githubId = 5684605;
name = "Cole Scott";
};
cole-h = {
name = "Cole Helbling";
email = "cole.e.helbling@outlook.com";
github = "cole-h";
githubId = 28582702;
keys = [{
longkeyid = "rsa4096/0xB37E0F2371016A4C";
fingerprint = "68B8 0D57 B2E5 4AC3 EC1F 49B0 B37E 0F23 7101 6A4C";
}];
};
copumpkin = {
email = "pumpkingod@gmail.com";
github = "copumpkin";
@@ -3275,6 +3285,12 @@
githubId = 1198065;
name = "Jeffrey David Johnson";
};
jefflabonte = {
email = "grimsleepless@protonmail.com";
github = "jefflabonte";
githubId = 9425955;
name = "Jean-François Labonté";
};
jensbin = {
email = "jensbin+git@pm.me";
github = "jensbin";
@@ -3902,6 +3918,12 @@
githubId = 10544;
name = "Giuluo Eulisse";
};
kthielen = {
email = "kthielen@gmail.com";
github = "kthielen";
githubId = 1409287;
name = "Kalani Thielen";
};
ktor = {
email = "kruszewsky@gmail.com";
github = "ktor";
@@ -3991,6 +4013,12 @@
githubId = 32152;
name = "Luka Blaskovic";
};
lbpdt = {
email = "nix@pdtpartners.com";
github = "lbpdt";
githubId = 45168934;
name = "Louis Blin";
};
ldelelis = {
email = "ldelelis@est.frba.utn.edu.ar";
github = "ldelelis";
@@ -4055,6 +4083,12 @@
github = "leonardoce";
name = "Leonardo Cecchi";
};
leshainc = {
email = "leshainc@fomalhaut.me";
github = "LeshaInc";
githubId = 42153076;
name = "Alexey Nikashkin";
};
lethalman = {
email = "lucabru@src.gnome.org";
github = "lethalman";
@@ -4494,6 +4528,12 @@
githubId = 1269099;
name = "Marius Bakke";
};
mbaillie = {
email = "martin@baillie.email";
github = "martinbaillie";
githubId = 613740;
name = "Martin Baillie";
};
mbbx6spp = {
email = "me@susanpotter.net";
github = "mbbx6spp";
@@ -7119,6 +7159,12 @@
githubId = 844343;
name = "Thiago K. Okada";
};
thmzlt = {
email = "git@thomazleite.com";
github = "thmzlt";
githubId = 7709;
name = "Thomaz Leite";
};
ThomasMader = {
email = "thomas.mader@gmail.com";
github = "ThomasMader";
@@ -7428,6 +7474,12 @@
github = "valeriangalliat";
name = "Valérian Galliat";
};
valodim = {
email = "look@my.amazin.horse";
github = "valodim";
githubId = 27813;
name = "Vincent Breitmoser";
};
vandenoever = {
email = "jos@vandenoever.info";
github = "vandenoever";
@@ -7610,6 +7662,12 @@
githubId = 3889405;
name = "vyp";
};
wamserma = {
name = "Markus S. Wamser";
email = "github-dev@mail2013.wamser.eu";
github = "wamserma";
githubId = 60148;
};
waynr = {
name = "Wayne Warren";
email = "wayne.warren.s@gmail.com";
@@ -7686,7 +7744,7 @@
email = "worldofpeace@protonmail.ch";
github = "worldofpeace";
githubId = 28888242;
name = "Worldofpeace";
name = "worldofpeace";
};
wscott = {
email = "wsc9tt@gmail.com";

View File

@@ -79,7 +79,7 @@ def cli(jobset):
and print a summary of failed builds
"""
url = "http://hydra.nixos.org/jobset/{}".format(jobset)
url = "https://hydra.nixos.org/jobset/{}".format(jobset)
# get the last evaluation
click.echo(click.style(

View File

@@ -2,6 +2,7 @@
, maintainer ? null
, path ? null
, max-workers ? null
, include-overlays ? false
, keep-going ? null
}:
@@ -20,9 +21,7 @@ let
in
[x] ++ nubOn f xs;
pkgs = import ./../../default.nix {
overlays = [];
};
pkgs = import ./../../default.nix (if include-overlays then { } else { overlays = []; });
packagesWith = cond: return: set:
nubOn (pkg: pkg.updateScript)

View File

@@ -2,4 +2,4 @@
NixOS is a Linux distribution based on the purely functional package
management system Nix. More information can be found at
http://nixos.org/nixos and in the manual in doc/manual.
https://nixos.org/nixos and in the manual in doc/manual.

View File

@@ -11,7 +11,7 @@
the package to your clone, and (optionally) submit a patch or pull request to
have it accepted into the main Nixpkgs repository. This is described in
detail in the <link
xlink:href="http://nixos.org/nixpkgs/manual">Nixpkgs
xlink:href="https://nixos.org/nixpkgs/manual">Nixpkgs
manual</link>. In short, you clone Nixpkgs:
<screen>
<prompt>$ </prompt>git clone https://github.com/NixOS/nixpkgs

View File

@@ -14,7 +14,7 @@
when managing complex systems. The syntax and semantics of the Nix language
are fully described in the
<link
xlink:href="http://nixos.org/nix/manual/#chap-writing-nix-expressions">Nix
xlink:href="https://nixos.org/nix/manual/#chap-writing-nix-expressions">Nix
manual</link>, but here we give a short overview of the most important
constructs useful in NixOS configuration files.
</para>

View File

@@ -21,7 +21,6 @@
<xi:include href="xfce.xml" />
<xi:include href="networking.xml" />
<xi:include href="linux-kernel.xml" />
<xi:include href="matrix.xml" />
<xi:include href="../generated/modules.xml" xpointer="xpointer(//section[@id='modules']/*)" />
<xi:include href="profiles.xml" />
<xi:include href="kubernetes.xml" />

View File

@@ -10,7 +10,7 @@
expression language. Its not complete. In particular, there are many other
built-in functions. See the
<link
xlink:href="http://nixos.org/nix/manual/#chap-writing-nix-expressions">Nix
xlink:href="https://nixos.org/nix/manual/#chap-writing-nix-expressions">Nix
manual</link> for the rest.
</para>

View File

@@ -9,7 +9,6 @@
<programlisting>
<xref linkend="opt-services.xserver.desktopManager.xfce.enable" /> = true;
<xref linkend="opt-services.xserver.displayManager.defaultSession" /> = "xfce";
};
</programlisting>
</para>
<para>

View File

@@ -57,7 +57,7 @@
<listitem>
<para>
<link xlink:href="https://github.com/NixOS/nixos-org-configurations/pull/18">
Make sure a channel is created at http://nixos.org/channels/. </link>
Make sure a channel is created at https://nixos.org/channels/. </link>
</para>
</listitem>
<listitem>

View File

@@ -37,7 +37,7 @@
imports =
[ # Use postgresql service from nixos-unstable channel.
# sudo nix-channel --add http://nixos.org/channels/nixos-unstable nixos-unstable
# sudo nix-channel --add https://nixos.org/channels/nixos-unstable nixos-unstable
&lt;nixos-unstable/nixos/modules/services/databases/postgresql.nix&gt;
];

View File

@@ -7,7 +7,7 @@
<para>
NixOS ISO images can be downloaded from the
<link
xlink:href="http://nixos.org/nixos/download.html">NixOS download
xlink:href="https://nixos.org/nixos/download.html">NixOS download
page</link>. There are a number of installation options. If you happen to
have an optical drive and a spare CD, burning the image to CD and booting
from that is probably the easiest option. Most people will need to prepare a
@@ -26,7 +26,7 @@ xlink:href="https://nixos.wiki/wiki/NixOS_Installation_Guide#Making_the_installa
<para>
Using virtual appliances in Open Virtualization Format (OVF) that can be
imported into VirtualBox. These are available from the
<link xlink:href="http://nixos.org/nixos/download.html">NixOS download
<link xlink:href="https://nixos.org/nixos/download.html">NixOS download
page</link>.
</para>
</listitem>

View File

@@ -14,7 +14,7 @@
<para>
<emphasis>Stable channels</emphasis>, such as
<literal
xlink:href="https://nixos.org/channels/nixos-19.09">nixos-19.09</literal>.
xlink:href="https://nixos.org/channels/nixos-20.03">nixos-20.03</literal>.
These only get conservative bug fixes and package upgrades. For instance,
a channel update may cause the Linux kernel on your system to be upgraded
from 4.19.34 to 4.19.38 (a minor bug fix), but not from
@@ -38,7 +38,7 @@
<para>
<emphasis>Small channels</emphasis>, such as
<literal
xlink:href="https://nixos.org/channels/nixos-19.09-small">nixos-19.09-small</literal>
xlink:href="https://nixos.org/channels/nixos-20.03-small">nixos-20.03-small</literal>
or
<literal
xlink:href="https://nixos.org/channels/nixos-unstable-small">nixos-unstable-small</literal>.
@@ -63,8 +63,8 @@
<para>
When you first install NixOS, youre automatically subscribed to the NixOS
channel that corresponds to your installation source. For instance, if you
installed from a 19.09 ISO, you will be subscribed to the
<literal>nixos-19.09</literal> channel. To see which NixOS channel youre
installed from a 20.03 ISO, you will be subscribed to the
<literal>nixos-20.03</literal> channel. To see which NixOS channel youre
subscribed to, run the following as root:
<screen>
# nix-channel --list | grep nixos
@@ -75,13 +75,13 @@ nixos https://nixos.org/channels/nixos-unstable
# nix-channel --add https://nixos.org/channels/<replaceable>channel-name</replaceable> nixos
</screen>
(Be sure to include the <literal>nixos</literal> parameter at the end.) For
instance, to use the NixOS 19.09 stable channel:
instance, to use the NixOS 20.03 stable channel:
<screen>
# nix-channel --add https://nixos.org/channels/nixos-19.09 nixos
# nix-channel --add https://nixos.org/channels/nixos-20.03 nixos
</screen>
If you have a server, you may want to use the “small” channel instead:
<screen>
# nix-channel --add https://nixos.org/channels/nixos-19.09-small nixos
# nix-channel --add https://nixos.org/channels/nixos-20.03-small nixos
</screen>
And if you want to live on the bleeding edge:
<screen>
@@ -132,7 +132,7 @@ nixos https://nixos.org/channels/nixos-unstable
kernel, initrd or kernel modules.
You can also specify a channel explicitly, e.g.
<programlisting>
<xref linkend="opt-system.autoUpgrade.channel"/> = https://nixos.org/channels/nixos-19.09;
<xref linkend="opt-system.autoUpgrade.channel"/> = https://nixos.org/channels/nixos-20.03;
</programlisting>
</para>
</section>

View File

@@ -49,7 +49,7 @@
<para>
Nix has been updated to 1.7
(<link
xlink:href="http://nixos.org/nix/manual/#ssec-relnotes-1.7">details</link>).
xlink:href="https://nixos.org/nix/manual/#ssec-relnotes-1.7">details</link>).
</para>
</listitem>
<listitem>

View File

@@ -22,7 +22,7 @@
in excess of 8,000 Haskell packages. Detailed instructions on how to use
that infrastructure can be found in the
<link
xlink:href="http://nixos.org/nixpkgs/manual/#users-guide-to-the-haskell-infrastructure">User's
xlink:href="https://nixos.org/nixpkgs/manual/#users-guide-to-the-haskell-infrastructure">User's
Guide to the Haskell Infrastructure</link>. Users migrating from an earlier
release may find helpful information below, in the list of
backwards-incompatible changes. Furthermore, we distribute 51(!) additional
@@ -555,7 +555,7 @@ nix-env -f &quot;&lt;nixpkgs&gt;&quot; -iA haskellPackages.pandoc
the compiler now is the <literal>haskellPackages.ghcWithPackages</literal>
function. The
<link
xlink:href="http://nixos.org/nixpkgs/manual/#users-guide-to-the-haskell-infrastructure">User's
xlink:href="https://nixos.org/nixpkgs/manual/#users-guide-to-the-haskell-infrastructure">User's
Guide to the Haskell Infrastructure</link> provides more information about
this subject.
</para>

View File

@@ -54,7 +54,7 @@
xlink:href="https://reproducible-builds.org/specs/source-date-epoch/">SOURCE_DATE_EPOCH</envar>
to a deterministic value, and Nix has
<link
xlink:href="http://nixos.org/nix/manual/#ssec-relnotes-1.11">gained
xlink:href="https://nixos.org/nix/manual/#ssec-relnotes-1.11">gained
an option</link> to repeat a build a number of times to test determinism.
An ongoing project, the goal of exact reproducibility is to allow binaries
to be verified independently (e.g., a user might only trust binaries that

View File

@@ -3,7 +3,7 @@
xmlns:xi="http://www.w3.org/2001/XInclude"
version="5.0"
xml:id="sec-release-20.03">
<title>Release 20.03 (“Markhor”, 2020.03/??)</title>
<title>Release 20.03 (“Markhor”, 2020.04/20)</title>
<section xmlns="http://docbook.org/ns/docbook"
xmlns:xlink="http://www.w3.org/1999/xlink"
@@ -23,11 +23,24 @@
Support is planned until the end of October 2020, handing over to 20.09.
</para>
</listitem>
<listitem>
<para>Core version changes:</para>
<para>gcc: 8.3.0 -&gt; 9.2.0</para>
<para>glibc: 2.27 -&gt; 2.30</para>
<para>linux: 4.19 -&gt; 5.4</para>
<para>mesa: 19.1.5 -&gt; 19.3.3</para>
<para>openssl: 1.0.2u -&gt; 1.1.1d</para>
</listitem>
<listitem>
<para>Desktop version changes:</para>
<para>plasma5: 5.16.5 -&gt; 5.17.5</para>
<para>kdeApplications: 19.08.2 -&gt; 19.12.3</para>
<para>gnome3: 3.32 -&gt; 3.34</para>
<para>pantheon: 5.0 -&gt; 5.1.3</para>
</listitem>
<listitem>
<para>
Linux kernel is updated to branch 5.4 by default (from 4.19).
Users of Intel GPUs may prefer to explicitly set branch to 4.19 to avoid some regressions.
<programlisting>boot.kernelPackages = pkgs.linuxPackages_4_19;</programlisting>
</para>
</listitem>
<listitem>
@@ -43,6 +56,24 @@
quirk in the boot menu.
</para>
</listitem>
<listitem>
<para>
GNOME 3 has been upgraded to 3.34. Please take a look at their
<link xlink:href="https://help.gnome.org/misc/release-notes/3.34">Release Notes</link>
for details.
</para>
</listitem>
<listitem>
<para>
If you enable the Pantheon Desktop Manager via
<xref linkend="opt-services.xserver.desktopManager.pantheon.enable" />, we now default to also use
<link xlink:href="https://blog.elementary.io/say-hello-to-the-new-greeter/">
Pantheon's newly designed greeter
</link>.
Contrary to NixOS's usual update policy, Pantheon will receive updates during the cycle of
NixOS 20.03 when backwards compatible.
</para>
</listitem>
<listitem>
<para>
By default zfs pools will now be trimmed on a weekly basis.
@@ -75,6 +106,24 @@ services.xserver.displayManager.defaultSession = "xfce+icewm";
</programlisting>
</para>
</listitem>
<listitem>
<para>
The testing driver implementation in NixOS is now in Python <filename>make-test-python.nix</filename>.
This was done by Jacek Galowicz (<link xlink:href="https://github.com/tfc">@tfc</link>), and with the
collaboration of Julian Stecklina (<link xlink:href="https://github.com/blitz">@blitz</link>) and
Jana Traue (<link xlink:href="https://github.com/jtraue">@jtraue</link>). All documentation has been updated to use this
testing driver, and a vast majority of the 286 tests in NixOS were ported to python driver. In 20.09 the Perl driver implementation,
<filename>make-test.nix</filename>, is slated for removal. This should give users of the NixOS integration framework
a transitory period to rewrite their tests to use the Python implementation. Users of the Perl driver will see
this warning everytime they use it:
<screen>
<prompt>$ </prompt>warning: Perl VM tests are deprecated and will be removed for 20.09.
Please update your tests to use the python test driver.
See https://github.com/NixOS/nixpkgs/pull/71684 for details.
</screen>
API compatibility is planned to be kept for at least the next release with the perl driver.
</para>
</listitem>
</itemizedlist>
</section>
@@ -110,6 +159,241 @@ services.xserver.displayManager.defaultSession = "xfce+icewm";
It was created so Geary could function properly outside of GNOME.
</para>
</listitem>
<listitem>
<para>
<filename>./config/console.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./hardware/brillo.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./hardware/tuxedo-keyboard.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./programs/bandwhich.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./programs/bash-my-aws.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./programs/liboping.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./programs/traceroute.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/backup/sanoid.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/backup/syncoid.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/backup/zfs-replication.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/continuous-integration/buildkite-agents.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/databases/victoriametrics.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/desktops/gnome3/gnome-initial-setup.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/desktops/neard.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/games/openarena.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/hardware/fancontrol.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/mail/sympa.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/misc/freeswitch.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/misc/mame.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/monitoring/do-agent.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/monitoring/prometheus/xmpp-alerts.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/network-filesystems/orangefs/server.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/network-filesystems/orangefs/client.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/3proxy.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/corerad.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/go-shadowsocks2.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/ntp/openntpd.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/shorewall.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/shorewall6.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/spacecookie.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/trickster.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/v2ray.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/xandikos.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/networking/yggdrasil.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/dokuwiki.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/gotify-server.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/grocy.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/ihatemoney</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/moinmoin.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/trac.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/trilium.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-apps/shiori.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/web-servers/ttyd.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/x11/picom.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/x11/hardware/digimend.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./services/x11/imwheel.nix</filename>
</para>
</listitem>
<listitem>
<para>
<filename>./virtualisation/cri-o.nix</filename>
</para>
</listitem>
</itemizedlist>
</section>
@@ -127,6 +411,17 @@ services.xserver.displayManager.defaultSession = "xfce+icewm";
</para>
<itemizedlist>
<listitem>
<para>
The <package>dhcpcd</package> package <link xlink:href="https://roy.marples.name/archives/dhcpcd-discuss/0002621.html">
does not request IPv4 addresses for tap and bridge interfaces anymore by default</link>.
In order to still get an address on a bridge interface, one has to disable
<literal>networking.useDHCP</literal> and explicitly enable
<literal>networking.interfaces.&lt;name&gt;.useDHCP</literal> on
every interface, that should get an address via DHCP. This way, dhcpcd
is configured in an explicit way about which interface to run on.
</para>
</listitem>
<listitem>
<para>
GnuPG is now built without support for a graphical passphrase entry
@@ -154,7 +449,7 @@ services.xserver.displayManager.defaultSession = "xfce+icewm";
</listitem>
<listitem>
<para>
The <literal>99-main.network</literal> file was removed. Maching all
The <literal>99-main.network</literal> file was removed. Matching all
network interfaces caused many breakages, see
<link xlink:href="https://github.com/NixOS/nixpkgs/pull/18962">#18962</link>
and <link xlink:href="https://github.com/NixOS/nixpkgs/pull/71106">#71106</link>.
@@ -196,10 +491,10 @@ services.xserver.displayManager.defaultSession = "xfce+icewm";
</listitem>
<listitem>
<para>
There is now only one Xfce package-set and module. This means attributes, <literal>xfce4-14</literal>
<literal>xfce4-12</literal>, and <literal>xfceUnstable</literal> all now point to the latest Xfce 4.14
packages. And in future NixOS releases will be the latest released version of Xfce available at the
time during the releases development (if viable).
There is now only one Xfce package-set and module. This means that attributes <literal>xfce4-14</literal>
and <literal>xfceUnstable</literal> all now point to the latest Xfce 4.14
packages. And in the future NixOS releases will be the latest released version of Xfce available at the
time of the release's development (if viable).
</para>
</listitem>
<listitem>
@@ -235,7 +530,7 @@ services.xserver.displayManager.defaultSession = "xfce+icewm";
<listitem>
<para>
The <literal>buildRustCrate</literal> infrastructure now produces <literal>lib</literal> outputs in addition to the <literal>out</literal> output.
This has led to drastically reduced closed sizes for some rust crates since development dependencies are now in the <literal>lib</literal> output.
This has led to drastically reduced closure sizes for some rust crates since development dependencies are now in the <literal>lib</literal> output.
</para>
</listitem>
<listitem>
@@ -603,6 +898,25 @@ auth required pam_succeed_if.so uid >= 1000 quiet
The <option>services.dnscrypt-proxy</option> module has been removed
as it used the deprecated version of dnscrypt-proxy. We've added
<xref linkend="opt-services.dnscrypt-proxy2.enable"/> to use the supported version.
This module supports configuration via the Nix attribute set
<xref linkend="opt-services.dnscrypt-proxy2.settings" />, or by passing a TOML configuration file via
<xref linkend="opt-services.dnscrypt-proxy2.configFile" />.
<programlisting>
# Example configuration:
services.dnscrypt-proxy2.enable = true;
services.dnscrypt-proxy2.settings = {
listen_addresses = [ "127.0.0.1:43" ];
sources.public-resolvers = {
urls = [ "https://download.dnscrypt.info/resolvers-list/v2/public-resolvers.md" ];
cache_file = "public-resolvers.md";
minisign_key = "RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3";
refresh_delay = 72;
};
};
services.dnsmasq.enable = true;
services.dnsmasq.servers = [ "127.0.0.1#43" ];
</programlisting>
</para>
</listitem>
<listitem>
@@ -634,6 +948,150 @@ auth required pam_succeed_if.so uid >= 1000 quiet
to a fairly old snapshot from the <package>gcc7</package>-branch.
</para>
</listitem>
<listitem>
<para>
The <citerefentry><refentrytitle>nixos-build-vms</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>-script now uses the python test-driver.
</para>
</listitem>
<listitem>
<para>
The <package>riot-web</package> package now accepts configuration overrides as an attribute set instead of a string.
A formerly used JSON configuration can be converted to an attribute set with <literal>builtins.fromJSON</literal>.
</para>
<para>
The new default configuration also disables automatic guest account registration and analytics to improve privacy.
The previous behavior can be restored by setting <literal>config.riot-web.conf = { disable_guests = false; piwik = true; }</literal>.
</para>
</listitem>
<listitem>
<para>
Stand-alone usage of <literal>Upower</literal> now requires
<option>services.upower.enable</option> instead of just installing into
<xref linkend="opt-environment.systemPackages"/>.
</para>
</listitem>
<listitem>
<para>
<package>nextcloud</package> has been updated to <literal>v18.0.2</literal>. This means
that users from NixOS 19.09 can't upgrade directly since you can only move one version
forward and 19.09 uses <literal>v16.0.8</literal>.
</para>
<para>
To provide a safe upgrade-path and to circumvent similar issues in the future, the following
measures were taken:
<itemizedlist>
<listitem>
<para>
The <package>pkgs.nextcloud</package>-attribute has been removed and replaced with
versioned attributes (currently <package>pkgs.nextcloud17</package> and
<package>pkgs.nextcloud18</package>). With this change major-releases can be backported
without breaking stuff and to make upgrade-paths easier.
</para>
</listitem>
<listitem>
<para>
Existing setups will be detected using
<link linkend="opt-system.stateVersion">system.stateVersion</link>: by default,
<package>nextcloud17</package> will be used, but will raise a warning which notes
that after that deploy it's recommended to update to the latest stable version
(<package>nextcloud18</package>) by declaring the newly introduced setting
<link linkend="opt-services.nextcloud.package">services.nextcloud.package</link>.
</para>
</listitem>
<listitem>
<para>
Users with an overlay (e.g. to use <package>nextcloud</package> at version
<literal>v18</literal> on <literal>19.09</literal>) will get an evaluation error
by default. This is done to ensure that our
<link linkend="opt-services.nextcloud.package">package</link>-option doesn't select an
older version by accident. It's recommended to use <package>pkgs.nextcloud18</package>
or to set <link linkend="opt-services.nextcloud.package">package</link> to
<package>pkgs.nextcloud</package> explicitly.
</para>
</listitem>
</itemizedlist>
</para>
<warning>
<para>
Please note that if you're coming from <literal>19.03</literal> or older, you have
to manually upgrade to <literal>19.09</literal> first to upgrade your server
to Nextcloud v16.
</para>
</warning>
</listitem>
<listitem>
<para>
<package>Hydra</package> has gained a massive performance improvement due to
<link xlink:href="https://github.com/NixOS/hydra/pull/710">some database schema
changes</link> by adding several IDs and better indexing. However, it's necessary
to upgrade Hydra in multiple steps:
<itemizedlist>
<listitem>
<para>
At first, an older version of Hydra needs to be deployed which adds those
(nullable) columns. When having set <link linkend="opt-system.stateVersion">stateVersion
</link> to a value older than <literal>20.03</literal>, this package will be selected
by default from the module when upgrading. Otherwise, the package can be deployed using
the following config:
<programlisting>{ pkgs, ... }: {
<link linkend="opt-services.hydra.package">services.hydra.package</link> = pkgs.hydra-migration;
}</programlisting>
</para>
</listitem>
<listitem>
<para>
Automatically fill the newly added ID columns on the server by running the following
command:
<screen>
<prompt>$ </prompt>hydra-backfill-ids
</screen>
<warning>
<para>Please note that this process can take a while depending on your database-size!</para>
</warning>
</para>
</listitem>
<listitem>
<para>
Deploy a newer version of Hydra to activate the DB optimizations. This can be done by
using <package>hydra-unstable</package>. This package already includes
<link xlink:href="https://github.com/nixos/rfcs/pull/49">flake-support</link> and is
therefore compiled against <package>pkgs.nixFlakes</package>.
<warning>
<para>
If your <link linkend="opt-system.stateVersion">stateVersion</link> is set to
<literal>20.03</literal> or greater, <package>hydra-unstable</package> will be used
automatically! This will break your setup if you didn't run the migration.
</para>
</warning>
Please note that Hydra is currently not available with <package>nixStable</package>
as this doesn't compile anymore.
</para>
</listitem>
</itemizedlist>
<warning>
<para>
<package>pkgs.hydra</package> has been removed to ensure a graceful database-migration
using the dedicated package-attributes. If you still have <package>pkgs.hydra</package>
defined in e.g. an overlay, an assertion error will be thrown. To circumvent this,
you need to set <xref linkend="opt-services.hydra.package" /> to <package>pkgs.hydra</package>
explicitly and make sure you know what you're doing!
</para>
</warning>
</para>
</listitem>
<listitem>
<para>
The TokuDB storage engine will be disabled in <package>mariadb</package> 10.5. It is recommended to switch
to RocksDB. See also <link xlink:href="https://mariadb.com/kb/en/tokudb/">TokuDB</link>.
</para>
</listitem>
<listitem>
<para>
Graylog introduced a change in the LDAP server certificate validation behaviour for version 3.3.3 which might break existing setups.
When updating Graylog from a version before 3.3.3 make sure to check the Graylog <link xlink:href="https://www.graylog.org/post/announcing-graylog-v3-3-3">release info</link> for information on how to avoid the issue.
</para>
</listitem>
</itemizedlist>
</section>
@@ -651,7 +1109,8 @@ auth required pam_succeed_if.so uid >= 1000 quiet
<listitem>
<para>
The nginx web server previously started its master process as root
privileged, then ran worker processes as a less privileged identity user.
privileged, then ran worker processes as a less privileged identity user
(the <literal>nginx</literal> user).
This was changed to start all of nginx as a less privileged user (defined by
<literal>services.nginx.user</literal> and
<literal>services.nginx.group</literal>). As a consequence, all files that
@@ -659,6 +1118,13 @@ auth required pam_succeed_if.so uid >= 1000 quiet
certificates and keys, etc.) must now be readable by this less privileged
user/group.
</para>
<para>
To continue to use the old approach, you can configure:
<programlisting>
services.nginx.appendConfig = let cfg = config.services.nginx; in ''user ${cfg.user} ${cfg.group};'';
systemd.services.nginx.serviceConfig.User = lib.mkForce "root";
</programlisting>
</para>
</listitem>
<listitem>
<para>
@@ -685,9 +1151,11 @@ auth required pam_succeed_if.so uid >= 1000 quiet
As well as this, the options <literal>security.acme.acceptTerms</literal> and either
<literal>security.acme.email</literal> or <literal>security.acme.certs.&lt;name&gt;.email</literal>
must be set in order to use the ACME module.
Certificates will be regenerated anew on the next renewal date. The credentials for simp-le are
preserved and thus it is possible to roll back to previous versions without breaking certificate
generation.
Certificates will be regenerated on activation, no account or certificate will be migrated from simp-le.
In particular private keys will not be preserved. However, the credentials for simp-le are preserved and
thus it is possible to roll back to previous versions without breaking certificate generation.
Note also that in contrary to simp-le a new private key is recreated at each renewal by default, which can
have consequences if you embed your public key in apps.
</para>
</listitem>
<listitem>
@@ -696,6 +1164,86 @@ auth required pam_succeed_if.so uid >= 1000 quiet
via <option>boot.initrd.luks.fido2Support</option>.
</para>
</listitem>
<listitem>
<para>
Predictably named network interfaces get renamed in stage-1. This means that it is possible
to use the proper interface name for e.g. Dropbear setups.
</para>
<para>
For further reference, please read <link xlink:href="https://github.com/NixOS/nixpkgs/pull/68953">#68953</link> or the corresponding <link xlink:href="https://discourse.nixos.org/t/predictable-network-interface-names-in-initrd/4055">discourse thread</link>.
</para>
</listitem>
<listitem>
<para>
The <package>matrix-synapse</package>-package has been updated to
<link xlink:href="https://github.com/matrix-org/synapse/releases/tag/v1.11.1">v1.11.1</link>.
Due to <link xlink:href="https://github.com/matrix-org/synapse/releases/tag/v1.10.0rc1">stricter requirements</link>
for database configuration when using <package>postgresql</package>, the automated database setup
of the module has been removed to avoid any further edge-cases.
</para>
<para>
<package>matrix-synapse</package> expects <literal>postgresql</literal>-databases to have the options
<literal>LC_COLLATE</literal> and <literal>LC_CTYPE</literal> set to
<link xlink:href="https://www.postgresql.org/docs/12/locale.html"><literal>'C'</literal></link> which basically
instructs <literal>postgresql</literal> to ignore any locale-based preferences.
</para>
<para>
Depending on your setup, you need to incorporate one of the following changes in your setup to
upgrade to 20.03:
<itemizedlist>
<listitem><para>If you use <literal>sqlite3</literal> you don't need to do anything.</para></listitem>
<listitem><para>If you use <literal>postgresql</literal> on a different server, you don't need
to change anything as well since this module was never designed to configure remote databases.
</para></listitem>
<listitem><para>If you use <literal>postgresql</literal> and configured your synapse initially on
<literal>19.09</literal> or older, you simply need to enable <package>postgresql</package>-support
explicitly:
<programlisting>{ ... }: {
services.matrix-synapse = {
<link linkend="opt-services.matrix-synapse.enable">enable</link> = true;
/* and all the other config you've defined here */
};
<link linkend="opt-services.postgresql.enable">services.postgresql.enable</link> = true;
}</programlisting>
</para></listitem>
<listitem><para>If you deploy a fresh <package>matrix-synapse</package>, you need to configure
the database yourself (e.g. by using the
<link linkend="opt-services.postgresql.initialScript">services.postgresql.initialScript</link>
option). An example for this can be found in the
<link linkend="module-services-matrix">documentation of the Matrix module</link>.
</para></listitem>
<listitem><para>If you initially deployed your <package>matrix-synapse</package> on
<literal>nixos-unstable</literal> <emphasis>after</emphasis> the <literal>19.09</literal>-release,
your database is misconfigured due to a regression in NixOS. For now, <package>matrix-synapse</package> will
startup with a warning, but it's recommended to reconfigure the database to set the values
<literal>LC_COLLATE</literal> and <literal>LC_CTYPE</literal> to
<link xlink:href="https://www.postgresql.org/docs/12/locale.html"><literal>'C'</literal></link>.
</para></listitem>
</itemizedlist>
</para>
</listitem>
<listitem>
<para>
The <link linkend="opt-systemd.network.links">systemd.network.links</link> option is now respected
even when <link linkend="opt-systemd.network.enable">systemd-networkd</link> is disabled.
This mirrors the behaviour of systemd - It's udev that parses <literal>.link</literal> files,
not <command>systemd-networkd</command>.
</para>
</listitem>
<listitem>
<para>
<package>mongodb</package> has been updated to version <literal>3.4.24</literal>.
<warning>
<para>
Please note that <package>mongodb</package> has been relicensed under their own
<link xlink:href="https://www.mongodb.com/licensing/server-side-public-license/faq"><literal>
sspl</literal></link>-license. Since it's not entirely free and not OSI-approved,
it's listed as non-free. This means that Hydra doesn't provide prebuilt
<package>mongodb</package>-packages and needs to be built locally.
</para>
</warning>
</para>
</listitem>
</itemizedlist>
</section>
</section>

View File

@@ -41,6 +41,12 @@ let
# default to the argument. That way this new default could propagate all
# they way through, but has the last priority behind everything else.
nixpkgs.system = lib.mkDefault system;
# Stash the value of the `system` argument. When using `nesting.children`
# we want to have the same default value behavior (immediately above)
# without any interference from the user's configuration.
nixpkgs.initialSystem = system;
_module.args.pkgs = lib.mkIf (pkgs_ != null) (lib.mkForce pkgs_);
};
};

View File

@@ -107,6 +107,7 @@ xorriso="xorriso
-publisher nixos
-graft-points
-full-iso9660-filenames
-joliet
${isoBootFlags}
${usbBootFlags}
${efiBootFlags}

View File

@@ -86,7 +86,7 @@ let
optionsList = lib.sort optionLess optionsListDesc;
# Convert the list of options into an XML file.
optionsXML = pkgs.writeText "options.xml" (builtins.toXML optionsList);
optionsXML = builtins.toFile "options.xml" (builtins.toXML optionsList);
optionsNix = builtins.listToAttrs (map (o: { name = o.name; value = removeAttrs o ["name" "visible" "internal"]; }) optionsList);
@@ -133,6 +133,7 @@ in {
optionsJSON = pkgs.runCommand "options.json"
{ meta.description = "List of NixOS options in JSON format";
buildInputs = [ pkgs.brotli ];
}
''
# Export list of options in different format.
@@ -141,8 +142,11 @@ in {
cp ${builtins.toFile "options.json" (builtins.unsafeDiscardStringContext (builtins.toJSON optionsNix))} $dst/options.json
brotli -9 < $dst/options.json > $dst/options.json.br
mkdir -p $out/nix-support
echo "file json $dst/options.json" >> $out/nix-support/hydra-build-products
echo "file json-br $dst/options.json.br" >> $out/nix-support/hydra-build-products
''; # */
optionsDocBook = pkgs.runCommand "options-docbook.xml" {} ''

View File

@@ -141,7 +141,7 @@ class Logger:
self.logfile = os.environ.get("LOGFILE", "/dev/null")
self.logfile_handle = open(self.logfile, "wb")
self.xml = XMLGenerator(self.logfile_handle, encoding="utf-8")
self.queue: "Queue[Dict[str, str]]" = Queue(1000)
self.queue: "Queue[Dict[str, str]]" = Queue()
self.xml.startDocument()
self.xml.startElement("logfile", attrs={})
@@ -367,7 +367,7 @@ class Machine:
q = q.replace("'", "\\'")
return self.execute(
(
"su -l {} -c "
"su -l {} --shell /bin/sh -c "
"$'XDG_RUNTIME_DIR=/run/user/`id -u` "
"systemctl --user {}'"
).format(user, q)
@@ -383,17 +383,17 @@ class Machine:
if state != require_state:
raise Exception(
"Expected unit {} to to be in state ".format(unit)
+ "'active' but it is in state {}".format(state)
+ "'{}' but it is in state {}".format(require_state, state)
)
def execute(self, command: str) -> Tuple[int, str]:
self.connect()
out_command = "( {} ); echo '|!EOF' $?\n".format(command)
out_command = "( {} ); echo '|!=EOF' $?\n".format(command)
self.shell.send(out_command.encode())
output = ""
status_code_pattern = re.compile(r"(.*)\|\!EOF\s+(\d+)")
status_code_pattern = re.compile(r"(.*)\|\!=EOF\s+(\d+)")
while True:
chunk = self.shell.recv(4096).decode(errors="ignore")

View File

@@ -175,13 +175,13 @@ in rec {
nodeNames = builtins.attrNames nodes;
invalidNodeNames = lib.filter
(node: builtins.match "^[A-z_][A-z0-9_]+$" node == null) nodeNames;
(node: builtins.match "^[A-z_]([A-z0-9_]+)?$" node == null) nodeNames;
in
if lib.length invalidNodeNames > 0 then
throw ''
Cannot create machines out of (${lib.concatStringsSep ", " invalidNodeNames})!
All machines are referenced as perl variables in the testing framework which will break the
All machines are referenced as python variables in the testing framework which will break the
script when special characters are used.
Please stick to alphanumeric chars and underscores as separation.
@@ -218,12 +218,12 @@ in rec {
'';
testScript = ''
startAll;
$client->waitForUnit("multi-user.target");
start_all()
client.wait_for_unit("multi-user.target")
${preBuild}
$client->succeed("env -i ${bash}/bin/bash ${buildrunner} /tmp/xchg/saved-env >&2");
client.succeed("env -i ${bash}/bin/bash ${buildrunner} /tmp/xchg/saved-env >&2")
${postBuild}
$client->succeed("sync"); # flush all data before pulling the plug
client.succeed("sync") # flush all data before pulling the plug
'';
vmRunCommand = writeText "vm-run" ''
@@ -263,9 +263,12 @@ in rec {
{ ... }:
{
inherit require;
imports = [
../tests/common/auto.nix
];
virtualisation.memorySize = 1024;
services.xserver.enable = true;
services.xserver.displayManager.auto.enable = true;
test-support.displayManager.auto.enable = true;
services.xserver.displayManager.defaultSession = "none+icewm";
services.xserver.windowManager.icewm.enable = true;
};
@@ -274,7 +277,7 @@ in rec {
machine = client;
preBuild =
''
$client->waitForX;
client.wait_for_x()
'';
} // args);

View File

@@ -250,9 +250,12 @@ in rec {
{ ... }:
{
inherit require;
imports = [
../tests/common/auto.nix
];
virtualisation.memorySize = 1024;
services.xserver.enable = true;
services.xserver.displayManager.auto.enable = true;
test-support.displayManager.auto.enable = true;
services.xserver.displayManager.defaultSession = "none+icewm";
services.xserver.windowManager.icewm.enable = true;
};

View File

@@ -8,10 +8,15 @@ in {
imports = [ ../../../modules/virtualisation/amazon-image.nix ];
# Required to provide good EBS experience,
# Amazon recomments setting this to the highest possible value for a good EBS
# experience, which prior to 4.15 was 255.
# https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/nvme-ebs-volumes.html#timeout-nvme-ebs-volumes
# TODO change value to 4294967295 when kernel is updated to 4.15 or later
config.boot.kernelParams = [ "nvme_core.io_timeout=255" ];
config.boot.kernelParams =
let timeout =
if pkgs.lib.versionAtLeast config.boot.kernelPackages.kernel.version "4.15"
then "4294967295"
else "255";
in [ "nvme_core.io_timeout=${timeout}" ];
options.amazonImage = {
name = mkOption {

View File

@@ -195,7 +195,7 @@ let
confPkg = pkgs.runCommand "fontconfig-conf" {
preferLocalBuild = true;
} ''
support_folder=$out/etc/fonts/conf.d
support_folder=$out/etc/fonts/${lib.optionalString cfg.disableVersionedFontConfiguration "2.10/"}conf.d
latest_folder=$out/etc/fonts/${latestVersion}/conf.d
mkdir -p $support_folder
@@ -206,6 +206,11 @@ let
ln -s ${latestPkg.out}/etc/fonts/fonts.conf \
$latest_folder/../fonts.conf
${lib.optionalString cfg.disableVersionedFontConfiguration ''
ln -s $latest_folder/../fonts.conf \
$latest_folder/../../fonts.conf
''}
# fontconfig default config files
ln -s ${supportPkg.out}/etc/fonts/conf.d/*.conf \
$support_folder/
@@ -292,6 +297,23 @@ in
'';
};
disableVersionedFontConfiguration = mkOption {
type = types.bool;
default = true;
description = ''
If enabled, /etc/fonts/fonts.conf will contain configuration file
for the latest fontconfig, instead of the ancient 2.10 version.
This is necessary for using packages from Nixpkgs unstable.
Without it, running programs from unstable will populate
~/.cache/fontconfig with values incompatible with
programs from NixOS 20.03.
Enabling this should not cause any issues as there are no programs
using the legacy fontconfig version since NixOS 15.03.
'';
};
confPackages = mkOption {
internal = true;
type = with types; listOf path;

View File

@@ -25,6 +25,7 @@ in
fonts = {
enableFontDir = mkOption {
type = types.bool;
default = false;
description = ''
Whether to create a directory with links to all fonts in

View File

@@ -9,6 +9,7 @@ with lib;
fonts = {
enableGhostscriptFonts = mkOption {
type = types.bool;
default = false;
description = ''
Whether to add the fonts provided by Ghostscript (such as

View File

@@ -88,6 +88,7 @@ in
};
useTLS = mkOption {
type = types.bool;
default = false;
description = ''
If enabled, use TLS (encryption) over an LDAP (port 389)
@@ -109,6 +110,7 @@ in
daemon = {
enable = mkOption {
type = types.bool;
default = false;
description = ''
Whether to let the nslcd daemon (nss-pam-ldapd) handle the

View File

@@ -185,6 +185,8 @@ in
{ description = "Initialisation of swap device ${sw.device}";
wantedBy = [ "${realDevice'}.swap" ];
before = [ "${realDevice'}.swap" ];
# If swap is encrypted, depending on rngd resolves a possible entropy starvation during boot
after = mkIf (config.security.rngd.enable && sw.randomEncryption.enable) [ "rngd.service" ];
path = [ pkgs.utillinux ] ++ optional sw.randomEncryption.enable pkgs.cryptsetup;
script =

View File

@@ -8,8 +8,7 @@ with lib;
let
requiredPackages = map (pkg: setPrio ((pkg.meta.priority or 5) + 3) pkg)
[ config.nix.package
pkgs.acl
[ pkgs.acl
pkgs.attr
pkgs.bashInteractive # bash with ncurses support
pkgs.bzip2
@@ -33,7 +32,6 @@ let
pkgs.nano
pkgs.ncurses
pkgs.netcat
pkgs.nix-info
config.programs.ssh.package
pkgs.perl
pkgs.procps

View File

@@ -51,6 +51,7 @@ in {
rtlwifi_new-firmware
zd1211fw
alsa-firmware
sof-firmware
openelec-dvb-firmware
] ++ optional (pkgs.stdenv.hostPlatform.isAarch32 || pkgs.stdenv.hostPlatform.isAarch64) raspberrypiWirelessFirmware
++ optionals (versionOlder config.boot.kernelPackages.kernel.version "4.13") [

View File

@@ -1,31 +0,0 @@
{ config, lib, pkgs, ... }:
with lib;
let
cfg = config.hardware.brightnessctl;
in
{
options = {
hardware.brightnessctl = {
enable = mkOption {
default = false;
type = types.bool;
description = ''
Enable brightnessctl in userspace.
This will allow brightness control from users in the video group.
'';
};
};
};
config = mkIf cfg.enable {
services.udev.packages = with pkgs; [ brightnessctl ];
environment.systemPackages = with pkgs; [ brightnessctl ];
};
}

View File

@@ -64,7 +64,7 @@ in
# Without dconf enabled it is impossible to use IBus
programs.dconf.enable = true;
programs.dconf.profiles.ibus = "${ibusPackage}/etc/dconf/profile/ibus";
programs.dconf.packages = [ ibusPackage ];
services.dbus.packages = [
ibusAutostart
@@ -75,5 +75,9 @@ in
QT_IM_MODULE = "ibus";
XMODIFIERS = "@im=ibus";
};
xdg.portal.extraPortals = mkIf config.xdg.portal.enable [
ibusPackage
];
};
}

View File

@@ -21,7 +21,9 @@ let
if [ ! -e $out/nixos/nixpkgs ]; then
ln -s . $out/nixos/nixpkgs
fi
echo -n ${config.system.nixos.revision} > $out/nixos/.git-revision
${optionalString (config.system.nixos.revision != null) ''
echo -n ${config.system.nixos.revision} > $out/nixos/.git-revision
''}
echo -n ${config.system.nixos.versionSuffix} > $out/nixos/.version-suffix
echo ${config.system.nixos.versionSuffix} | sed -e s/pre// > $out/nixos/svn-revision
'';

View File

@@ -18,8 +18,6 @@ with lib;
# ISO naming.
isoImage.isoName = "${config.isoImage.isoBaseName}-${config.system.nixos.label}-${pkgs.stdenv.hostPlatform.system}.iso";
isoImage.volumeID = substring 0 11 "NIXOS_ISO";
# EFI booting
isoImage.makeEfiBootable = true;

View File

@@ -8,6 +8,8 @@ with lib;
{
imports = [ ./installation-cd-graphical-base.nix ];
isoImage.edition = "gnome";
services.xserver.desktopManager.gnome3.enable = true;
# Auto-login as root.

View File

@@ -8,6 +8,8 @@ with lib;
{
imports = [ ./installation-cd-graphical-base.nix ];
isoImage.edition = "plasma5";
services.xserver = {
desktopManager.plasma5 = {
enable = true;

View File

@@ -8,5 +8,7 @@
[ ./installation-cd-base.nix
];
isoImage.edition = "minimal";
fonts.fontconfig.enable = false;
}

View File

@@ -417,8 +417,17 @@ in
'';
};
isoImage.edition = mkOption {
default = "";
description = ''
Specifies which edition string to use in the volume ID of the generated
ISO image.
'';
};
isoImage.volumeID = mkOption {
default = "NIXOS_BOOT_CD";
# nixos-$EDITION-$RELEASE-$ARCH
default = "nixos${optionalString (config.isoImage.edition != "") "-${config.isoImage.edition}"}-${config.system.nixos.release}-${pkgs.stdenv.hostPlatform.uname.processor}";
description = ''
Specifies the label or volume ID of the generated ISO image.
Note that the label is used by stage 1 of the boot process to
@@ -515,6 +524,19 @@ in
};
config = {
assertions = [
{
assertion = !(stringLength config.isoImage.volumeID > 32);
# https://wiki.osdev.org/ISO_9660#The_Primary_Volume_Descriptor
# Volume Identifier can only be 32 bytes
message = let
length = stringLength config.isoImage.volumeID;
howmany = toString length;
toomany = toString (length - 32);
in
"isoImage.volumeID ${config.isoImage.volumeID} is ${howmany} characters. That is ${toomany} characters longer than the limit of 32.";
}
];
boot.loader.grub.version = 2;

View File

@@ -1,31 +0,0 @@
# To build, use:
# nix-build nixos -I nixos-config=nixos/modules/installer/cd-dvd/sd-image-raspberrypi4.nix -A config.system.build.sdImage
{ config, lib, pkgs, ... }:
{
imports = [
../../profiles/base.nix
../../profiles/installation-device.nix
./sd-image.nix
];
boot.loader.grub.enable = false;
boot.loader.raspberryPi.enable = true;
boot.loader.raspberryPi.version = 4;
boot.kernelPackages = pkgs.linuxPackages_rpi4;
boot.consoleLogLevel = lib.mkDefault 7;
sdImage = {
firmwareSize = 128;
# This is a hack to avoid replicating config.txt from boot.loader.raspberryPi
populateFirmwareCommands =
"${config.system.build.installBootLoader} ${config.system.build.toplevel} -d ./firmware";
# As the boot process is done entirely in the firmware partition.
populateRootCommands = "";
};
# the installation media is also the installation target,
# so we don't want to provide the installation configuration.nix.
installer.cloneConfig = false;
}

View File

@@ -1,6 +1,6 @@
{
x86_64-linux = "/nix/store/0q5qnh10m2sfrriszc1ysmggw659q6qm-nix-2.3.2";
i686-linux = "/nix/store/i7ad7r5d8a5b3l22hg4a1im2qq05y6vd-nix-2.3.2";
aarch64-linux = "/nix/store/bv06pavfw0dbqzr8w3l7s71nx27gnxa0-nix-2.3.2";
x86_64-darwin = "/nix/store/x6mnl1nij7y4v5ihlplr4k937ayr403r-nix-2.3.2";
x86_64-linux = "/nix/store/j8dbv5w6jl34caywh2ygdy88knx1mdf7-nix-2.3.6";
i686-linux = "/nix/store/9fqvbdisahqp0238vrs7wn5anpri0a65-nix-2.3.6";
aarch64-linux = "/nix/store/72pwn0nm9bjqx9vpi8sgh4bl6g5wh814-nix-2.3.6";
x86_64-darwin = "/nix/store/g37vk77m90p5zcl5nixjlzp3vqpisfn5-nix-2.3.6";
}

View File

@@ -5,7 +5,7 @@
let nodes = import networkExpr; in
with import ../../../../lib/testing.nix {
with import ../../../../lib/testing-python.nix {
inherit system;
pkgs = import ../../../../.. { inherit system config; };
};

View File

@@ -42,7 +42,10 @@ let
inherit (config.system.nixos-generate-config) configuration;
};
nixos-option = pkgs.callPackage ./nixos-option { };
nixos-option =
if lib.versionAtLeast (lib.getVersion pkgs.nix) "2.4pre"
then null
else pkgs.callPackage ./nixos-option { };
nixos-version = makeProg {
name = "nixos-version";
@@ -108,10 +111,10 @@ in
# networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
# Select internationalisation properties.
# i18n = {
# consoleFont = "Lat2-Terminus16";
# consoleKeyMap = "us";
# defaultLocale = "en_US.UTF-8";
# i18n.defaultLocale = "en_US.UTF-8";
# console = {
# font = "Lat2-Terminus16";
# keyMap = "us";
# };
# Set your time zone.
@@ -184,10 +187,9 @@ in
nixos-install
nixos-rebuild
nixos-generate-config
nixos-option
nixos-version
nixos-enter
];
] ++ lib.optional (nixos-option != null) nixos-option;
system.build = {
inherit nixos-install nixos-generate-config nixos-option nixos-rebuild nixos-enter;

View File

@@ -17,6 +17,7 @@ let
inherit pkgs config;
version = config.system.nixos.release;
revision = "release-${version}";
extraSources = cfg.nixos.extraModuleSources;
options =
let
scrubbedEval = evalModules {
@@ -163,6 +164,19 @@ in
'';
};
nixos.extraModuleSources = mkOption {
type = types.listOf (types.either types.path types.str);
default = [ ];
description = ''
Which extra NixOS module paths the generated NixOS's documentation should strip
from options.
'';
example = literalExample ''
# e.g. with options from modules in ''${pkgs.customModules}/nix:
[ pkgs.customModules ]
'';
};
};
};

View File

@@ -133,7 +133,7 @@ in
tcpcryptd = 93; # tcpcryptd uses a hard-coded uid. We patch it in Nixpkgs to match this choice.
firebird = 95;
#keys = 96; # unused
#haproxy = 97; # DynamicUser as of 2019-11-08
#haproxy = 97; # dynamically allocated as of 2020-03-11
mongodb = 98;
openldap = 99;
#users = 100; # unused
@@ -448,7 +448,7 @@ in
#tcpcryptd = 93; # unused
firebird = 95;
keys = 96;
#haproxy = 97; # DynamicUser as of 2019-11-08
#haproxy = 97; # dynamically allocated as of 2020-03-11
#mongodb = 98; # unused
openldap = 99;
munin = 102;

View File

@@ -216,6 +216,14 @@ in
Ignored when <code>nixpkgs.pkgs</code> is set.
'';
};
initialSystem = mkOption {
type = types.str;
internal = true;
description = ''
Preserved value of <literal>system</literal> passed to <literal>eval-config.nix</literal>.
'';
};
};
config = {

View File

@@ -4,10 +4,6 @@ with lib;
let
cfg = config.system.nixos;
gitRepo = "${toString pkgs.path}/.git";
gitRepoValid = lib.pathIsGitRepo gitRepo;
gitCommitId = lib.substring 0 7 (commitIdFromGitRepo gitRepo);
in
{
@@ -80,7 +76,7 @@ in
defaultChannel = mkOption {
internal = true;
type = types.str;
default = https://nixos.org/channels/nixos-unstable;
default = https://nixos.org/channels/nixos-20.03;
description = "Default NixOS channel to which the root user is subscribed.";
};
@@ -98,8 +94,6 @@ in
# These defaults are set here rather than up there so that
# changing them would not rebuild the manual
version = mkDefault (cfg.release + cfg.versionSuffix);
revision = mkIf gitRepoValid (mkDefault gitCommitId);
versionSuffix = mkIf gitRepoValid (mkDefault (".git." + gitCommitId));
};
# Generate /etc/os-release. See
@@ -115,8 +109,8 @@ in
PRETTY_NAME="NixOS ${cfg.release} (${cfg.codeName})"
LOGO="nix-snowflake"
HOME_URL="https://nixos.org/"
DOCUMENTATION_URL="https://nixos.org/nixos/manual/index.html"
SUPPORT_URL="https://nixos.org/nixos/support.html"
DOCUMENTATION_URL="https://nixos.org/learn.html"
SUPPORT_URL="https://nixos.org/community.html"
BUG_REPORT_URL="https://github.com/NixOS/nixpkgs/issues"
'';

View File

@@ -41,7 +41,6 @@
./hardware/acpilight.nix
./hardware/all-firmware.nix
./hardware/bladeRF.nix
./hardware/brightnessctl.nix
./hardware/brillo.nix
./hardware/ckb-next.nix
./hardware/cpu/amd-microcode.nix
@@ -724,6 +723,7 @@
./services/networking/syncthing.nix
./services/networking/syncthing-relay.nix
./services/networking/syncplay.nix
./services/networking/tailscale.nix
./services/networking/tcpcrypt.nix
./services/networking/teamspeak3.nix
./services/networking/tedicross.nix

View File

@@ -238,9 +238,6 @@ in
"/share/bash-completion"
];
environment.systemPackages = optional cfg.enableCompletion
pkgs.nix-bash-completions;
environment.shells =
[ "/run/current-system/sw/bin/bash"
"/run/current-system/sw/bin/sh"

View File

@@ -8,6 +8,7 @@ in {
options = {
programs.cdemu = {
enable = mkOption {
type = types.bool;
default = false;
description = ''
<command>cdemu</command> for members of

View File

@@ -8,6 +8,7 @@ in {
options = {
programs.criu = {
enable = mkOption {
type = types.bool;
default = false;
description = ''
Install <command>criu</command> along with necessary kernel options.

View File

@@ -4,13 +4,24 @@ with lib;
let
cfg = config.programs.dconf;
mkDconfProfile = name: path:
{
name = "dconf/profile/${name}";
value.source = path;
};
cfgDir = pkgs.symlinkJoin {
name = "dconf-system-config";
paths = map (x: "${x}/etc/dconf") cfg.packages;
postBuild = ''
mkdir -p $out/profile
mkdir -p $out/db
'' + (
concatStringsSep "\n" (
mapAttrsToList (
name: path: ''
ln -s ${path} $out/profile/${name}
''
) cfg.profiles
)
) + ''
${pkgs.dconf}/bin/dconf update $out/db
'';
};
in
{
###### interface
@@ -22,18 +33,24 @@ in
profiles = mkOption {
type = types.attrsOf types.path;
default = {};
description = "Set of dconf profile files.";
description = "Set of dconf profile files, installed at <filename>/etc/dconf/profiles/<replaceable>name</replaceable></filename>.";
internal = true;
};
packages = mkOption {
type = types.listOf types.package;
default = [];
description = "A list of packages which provide dconf profiles and databases in <filename>/etc/dconf</filename>.";
};
};
};
###### implementation
config = mkIf (cfg.profiles != {} || cfg.enable) {
environment.etc = optionalAttrs (cfg.profiles != {})
(mapAttrs' mkDconfProfile cfg.profiles);
environment.etc.dconf = mkIf (cfg.profiles != {} || cfg.packages != []) {
source = cfgDir;
};
services.dbus.packages = [ pkgs.dconf ];

View File

@@ -14,8 +14,16 @@ in
{
imports = [
(mkRenamedOptionModule [ "networking" "defaultMailServer" ] [ "services" "ssmtp" ])
(mkRenamedOptionModule [ "services" "ssmtp" "directDelivery" ] [ "services" "ssmtp" "enable" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "directDelivery" ] [ "services" "ssmtp" "enable" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "hostName" ] [ "services" "ssmtp" "hostName" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "domain" ] [ "services" "ssmtp" "domain" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "root" ] [ "services" "ssmtp" "root" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "useTLS" ] [ "services" "ssmtp" "useTLS" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "useSTARTTLS" ] [ "services" "ssmtp" "useSTARTTLS" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "authUser" ] [ "services" "ssmtp" "authUser" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "authPass" ] [ "services" "ssmtp" "authPass" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "authPassFile" ] [ "services" "ssmtp" "authPassFile" ])
(mkRenamedOptionModule [ "networking" "defaultMailServer" "setSendmail" ] [ "services" "ssmtp" "setSendmail" ])
];
options = {

View File

@@ -88,10 +88,10 @@ in {
default = with pkgs; [
swaylock swayidle
xwayland alacritty dmenu
rxvt_unicode # For backward compatibility (old default terminal)
rxvt-unicode # For backward compatibility (old default terminal)
];
defaultText = literalExample ''
with pkgs; [ swaylock swayidle xwayland rxvt_unicode dmenu ];
with pkgs; [ swaylock swayidle xwayland rxvt-unicode dmenu ];
'';
example = literalExample ''
with pkgs; [

View File

@@ -8,6 +8,7 @@ in {
options = {
programs.systemtap = {
enable = mkOption {
type = types.bool;
default = false;
description = ''
Install <command>systemtap</command> along with necessary kernel options.

View File

@@ -75,7 +75,7 @@ in
};
link = mkOption {
default = "http://planet.nixos.org";
default = "https://planet.nixos.org";
type = types.str;
description = ''
Link to the main page.

View File

@@ -39,6 +39,7 @@ in
options = {
programs.zsh.ohMyZsh = {
enable = mkOption {
type = types.bool;
default = false;
description = ''
Enable oh-my-zsh.

View File

@@ -162,9 +162,8 @@ in
# This file is read for all shells.
# Only execute this file once per shell.
# But don't clobber the environment of interactive non-login children!
if [ -n "$__ETC_ZSHENV_SOURCED" ]; then return; fi
export __ETC_ZSHENV_SOURCED=1
__ETC_ZSHENV_SOURCED=1
if [ -z "$__NIXOS_SET_ENVIRONMENT_DONE" ]; then
. ${config.system.build.setEnvironment}

View File

@@ -21,12 +21,12 @@ with lib;
(mkRemovedOptionModule [ "services" "firefox" "syncserver" "group" ] "")
(mkRemovedOptionModule [ "services" "winstone" ] "The corresponding package was removed from nixpkgs.")
(mkRemovedOptionModule [ "networking" "vpnc" ] "Use environment.etc.\"vpnc/service.conf\" instead.")
(mkRemovedOptionModule [ "environment.blcr.enable" ] "The BLCR module has been removed")
(mkRemovedOptionModule [ "services.beegfsEnable" ] "The BeeGFS module has been removed")
(mkRemovedOptionModule [ "services.beegfs" ] "The BeeGFS module has been removed")
(mkRemovedOptionModule [ "services.osquery" ] "The osquery module has been removed")
(mkRemovedOptionModule [ "services.fourStore" ] "The fourStore module has been removed")
(mkRemovedOptionModule [ "services.fourStoreEndpoint" ] "The fourStoreEndpoint module has been removed")
(mkRemovedOptionModule [ "environment" "blcr" "enable" ] "The BLCR module has been removed")
(mkRemovedOptionModule [ "services" "beegfsEnable" ] "The BeeGFS module has been removed")
(mkRemovedOptionModule [ "services" "beegfs" ] "The BeeGFS module has been removed")
(mkRemovedOptionModule [ "services" "osquery" ] "The osquery module has been removed")
(mkRemovedOptionModule [ "services" "fourStore" ] "The fourStore module has been removed")
(mkRemovedOptionModule [ "services" "fourStoreEndpoint" ] "The fourStoreEndpoint module has been removed")
(mkRemovedOptionModule [ "programs" "way-cooler" ] ("way-cooler is abandoned by its author: " +
"https://way-cooler.org/blog/2020/01/09/way-cooler-post-mortem.html"))
(mkRemovedOptionModule [ "services" "xserver" "multitouch" ] ''
@@ -42,6 +42,12 @@ with lib;
instead, or any other display manager in NixOS as they all support auto-login.
'')
(mkRemovedOptionModule [ "services" "dnscrypt-proxy" ] "Use services.dnscrypt-proxy2 instead")
(mkRemovedOptionModule ["hardware" "brightnessctl" ] ''
The brightnessctl module was removed because newer versions of
brightnessctl don't require the udev rules anymore (they can use the
systemd-logind API). Instead of using the module you can now
simply add the brightnessctl package to environment.systemPackages.
'')
# Do NOT add any option renames here, see top of the file
];

View File

@@ -87,19 +87,19 @@ let
default = {};
example = literalExample ''
{
"example.org" = "/srv/http/nginx";
"example.org" = null;
"mydomain.org" = null;
}
'';
description = ''
A list of extra domain names, which are included in the one certificate to be issued, with their
own server roots if needed.
A list of extra domain names, which are included in the one certificate to be issued.
Setting a distinct server root is deprecated and not functional in 20.03+
'';
};
keyType = mkOption {
type = types.str;
default = "ec384";
default = "ec256";
description = ''
Key type to use for private keys.
For an up to date list of supported values check the --key-type option
@@ -174,7 +174,7 @@ in
renewInterval = mkOption {
type = types.str;
default = "weekly";
default = "daily";
description = ''
Systemd calendar expression when to check for renewal. See
<citerefentry><refentrytitle>systemd.time</refentrytitle>
@@ -229,7 +229,7 @@ in
"example.com" = {
webroot = "/var/www/challenges/";
email = "foo@example.com";
extraDomains = { "www.example.com" = null; "foo.example.com" = "/var/www/foo/"; };
extraDomains = { "www.example.com" = null; "foo.example.com" = null; };
};
"bar.example.com" = {
webroot = "/var/www/challenges/";
@@ -280,8 +280,8 @@ in
# StateDirectory must be relative, and will be created under /var/lib by systemd
lpath = "acme/${cert}";
apath = "/var/lib/${lpath}";
spath = "/var/lib/acme/.lego";
rights = if data.allowKeysForGroup then "750" else "700";
spath = "/var/lib/acme/.lego/${cert}";
fileMode = if data.allowKeysForGroup then "640" else "600";
globalOpts = [ "-d" data.domain "--email" data.email "--path" "." "--key-type" data.keyType ]
++ optionals (cfg.acceptTerms) [ "--accept-tos" ]
++ optionals (data.dnsProvider != null && !data.dnsPropagationCheck) [ "--dns.disable-cp" ]
@@ -294,24 +294,20 @@ in
description = "Renew ACME Certificate for ${cert}";
after = [ "network.target" "network-online.target" ];
wants = [ "network-online.target" ];
wantedBy = mkIf (!config.boot.isContainer) [ "multi-user.target" ];
serviceConfig = {
Type = "oneshot";
# With RemainAfterExit the service is considered active even
# after the main process having exited, which means when it
# gets changed, the activation phase restarts it, meaning
# the permissions of the StateDirectory get adjusted
# according to the specified group
RemainAfterExit = true;
User = data.user;
Group = data.group;
PrivateTmp = true;
StateDirectory = "acme/.lego ${lpath}";
StateDirectoryMode = rights;
StateDirectory = "acme/.lego/${cert} acme/.lego/accounts ${lpath}";
StateDirectoryMode = if data.allowKeysForGroup then "750" else "700";
WorkingDirectory = spath;
# Only try loading the credentialsFile if the dns challenge is enabled
EnvironmentFile = if data.dnsProvider != null then data.credentialsFile else null;
ExecStart = pkgs.writeScript "acme-start" ''
#!${pkgs.runtimeShell} -e
test -L ${spath}/accounts -o -d ${spath}/accounts || ln -s ../accounts ${spath}/accounts
${pkgs.lego}/bin/lego ${renewOpts} || ${pkgs.lego}/bin/lego ${runOpts}
'';
ExecStartPost =
@@ -323,17 +319,23 @@ in
# Test that existing cert is older than new cert
KEY=${spath}/certificates/${keyName}.key
KEY_CHANGED=no
if [ -e $KEY -a $KEY -nt key.pem ]; then
KEY_CHANGED=yes
cp -p ${spath}/certificates/${keyName}.key key.pem
cp -p ${spath}/certificates/${keyName}.crt cert.pem
cp -p ${spath}/certificates/${keyName}.crt fullchain.pem
cp -p ${spath}/certificates/${keyName}.issuer.crt chain.pem
cat cert.pem chain.pem > fullchain.pem
cat key.pem cert.pem chain.pem > full.pem
chmod ${rights} *.pem
chown '${data.user}:${data.group}' *.pem
ln -sf fullchain.pem cert.pem
cat key.pem fullchain.pem > full.pem
fi
${data.postRun}
chmod ${fileMode} *.pem
chown '${data.user}:${data.group}' *.pem
if [ "$KEY_CHANGED" = "yes" ]; then
: # noop in case postRun is empty
${data.postRun}
fi
'';
in
"+${script}";
@@ -374,7 +376,7 @@ in
# Give key acme permissions
chown '${data.user}:${data.group}' "${apath}/"{key,fullchain,full}.pem
chmod ${rights} "${apath}/"{key,fullchain,full}.pem
chmod ${fileMode} "${apath}/"{key,fullchain,full}.pem
'';
serviceConfig = {
Type = "oneshot";
@@ -399,7 +401,17 @@ in
systemd.tmpfiles.rules =
map (data: "d ${data.webroot}/.well-known/acme-challenge - ${data.user} ${data.group}") (filter (data: data.webroot != null) (attrValues cfg.certs));
systemd.timers = flip mapAttrs' cfg.certs (cert: data: nameValuePair
systemd.timers = let
# Allow systemd to pick a convenient time within the day
# to run the check.
# This allows the coalescing of multiple timer jobs.
# We divide by the number of certificates so that if you
# have many certificates, the renewals are distributed over
# the course of the day to avoid rate limits.
numCerts = length (attrNames cfg.certs);
_24hSecs = 60 * 60 * 24;
AccuracySec = "${toString (_24hSecs / numCerts)}s";
in flip mapAttrs' cfg.certs (cert: data: nameValuePair
("acme-${cert}")
({
description = "Renew ACME Certificate for ${cert}";
@@ -408,8 +420,9 @@ in
OnCalendar = cfg.renewInterval;
Unit = "acme-${cert}.service";
Persistent = "yes";
AccuracySec = "5m";
RandomizedDelaySec = "1h";
inherit AccuracySec;
# Skew randomly within the day, per https://letsencrypt.org/docs/integration-guide/.
RandomizedDelaySec = "24h";
};
})
);

View File

@@ -6,65 +6,49 @@
<title>SSL/TLS Certificates with ACME</title>
<para>
NixOS supports automatic domain validation &amp; certificate retrieval and
renewal using the ACME protocol. This is currently only implemented by and
for Let's Encrypt. The alternative ACME client <literal>lego</literal> is
used under the hood.
renewal using the ACME protocol. Any provider can be used, but by default
NixOS uses Let's Encrypt. The alternative ACME client <literal>lego</literal>
is used under the hood.
</para>
<para>
Automatic cert validation and configuration for Apache and Nginx virtual
hosts is included in NixOS, however if you would like to generate a wildcard
cert or you are not using a web server you will have to configure DNS
based validation.
</para>
<section xml:id="module-security-acme-prerequisites">
<title>Prerequisites</title>
<para>
You need to have a running HTTP server for verification. The server must
have a webroot defined that can serve
To use the ACME module, you must accept the provider's terms of service
by setting <literal><xref linkend="opt-security.acme.acceptTerms" /></literal>
to <literal>true</literal>. The Let's Encrypt ToS can be found
<link xlink:href="https://letsencrypt.org/repository/">here</link>.
</para>
<para>
You must also set an email address to be used when creating accounts with
Let's Encrypt. You can set this for all certs with
<literal><xref linkend="opt-security.acme.email" /></literal>
and/or on a per-cert basis with
<literal><xref linkend="opt-security.acme.certs._name_.email" /></literal>.
This address is only used for registration and renewal reminders,
and cannot be used to administer the certificates in any way.
</para>
<para>
Alternatively, you can use a different ACME server by changing the
<literal><xref linkend="opt-security.acme.server" /></literal> option
to a provider of your choosing, or just change the server for one cert with
<literal><xref linkend="opt-security.acme.certs._name_.server" /></literal>.
</para>
<para>
You will need an HTTP server or DNS server for verification. For HTTP,
the server must have a webroot defined that can serve
<filename>.well-known/acme-challenge</filename>. This directory must be
writeable by the user that will run the ACME client.
</para>
<para>
For instance, this generic snippet could be used for Nginx:
<programlisting>
http {
server {
server_name _;
listen 80;
listen [::]:80;
location /.well-known/acme-challenge {
root /var/www/challenges;
}
location / {
return 301 https://$host$request_uri;
}
}
}
</programlisting>
</para>
</section>
<section xml:id="module-security-acme-configuring">
<title>Configuring</title>
<para>
To enable ACME certificate retrieval &amp; renewal for a certificate for
<literal>foo.example.com</literal>, add the following in your
<filename>configuration.nix</filename>:
<programlisting>
<xref linkend="opt-security.acme.certs"/>."foo.example.com" = {
<link linkend="opt-security.acme.certs._name_.webroot">webroot</link> = "/var/www/challenges";
<link linkend="opt-security.acme.certs._name_.email">email</link> = "foo@example.com";
};
</programlisting>
</para>
<para>
The private key <filename>key.pem</filename> and certificate
<filename>fullchain.pem</filename> will be put into
<filename>/var/lib/acme/foo.example.com</filename>.
</para>
<para>
Refer to <xref linkend="ch-options" /> for all available configuration
options for the <link linkend="opt-security.acme.certs">security.acme</link>
module.
writeable by the user that will run the ACME client. For DNS, you must
set up credentials with your provider/server for use with lego.
</para>
</section>
<section xml:id="module-security-acme-nginx">
@@ -80,12 +64,27 @@ http {
</para>
<programlisting>
<xref linkend="opt-security.acme.acceptTerms" /> = true;
<xref linkend="opt-security.acme.email" /> = "admin+acme@example.com";
services.nginx = {
<link linkend="opt-services.nginx.enable">enable = true;</link>
<link linkend="opt-services.nginx.enable">enable</link> = true;
<link linkend="opt-services.nginx.virtualHosts">virtualHosts</link> = {
"foo.example.com" = {
<link linkend="opt-services.nginx.virtualHosts._name_.forceSSL">forceSSL</link> = true;
<link linkend="opt-services.nginx.virtualHosts._name_.enableACME">enableACME</link> = true;
# All serverAliases will be added as <link linkend="opt-security.acme.certs._name_.extraDomains">extra domains</link> on the certificate.
<link linkend="opt-services.nginx.virtualHosts._name_.serverAliases">serverAliases</link> = [ "bar.example.com" ];
locations."/" = {
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.root">root</link> = "/var/www";
};
};
# We can also add a different vhost and reuse the same certificate
# but we have to append extraDomains manually.
<link linkend="opt-security.acme.certs._name_.extraDomains">security.acme.certs."foo.example.com".extraDomains."baz.example.com"</link> = null;
"baz.example.com" = {
<link linkend="opt-services.nginx.virtualHosts._name_.forceSSL">forceSSL</link> = true;
<link linkend="opt-services.nginx.virtualHosts._name_.useACMEHost">useACMEHost</link> = "foo.example.com";
locations."/" = {
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.root">root</link> = "/var/www";
};
@@ -94,4 +93,162 @@ services.nginx = {
}
</programlisting>
</section>
<section xml:id="module-security-acme-httpd">
<title>Using ACME certificates in Apache/httpd</title>
<para>
Using ACME certificates with Apache virtual hosts is identical
to using them with Nginx. The attribute names are all the same, just replace
"nginx" with "httpd" where appropriate.
</para>
</section>
<section xml:id="module-security-acme-configuring">
<title>Manual configuration of HTTP-01 validation</title>
<para>
First off you will need to set up a virtual host to serve the challenges.
This example uses a vhost called <literal>certs.example.com</literal>, with
the intent that you will generate certs for all your vhosts and redirect
everyone to HTTPS.
</para>
<programlisting>
<xref linkend="opt-security.acme.acceptTerms" /> = true;
<xref linkend="opt-security.acme.email" /> = "admin+acme@example.com";
services.nginx = {
<link linkend="opt-services.nginx.enable">enable</link> = true;
<link linkend="opt-services.nginx.virtualHosts">virtualHosts</link> = {
"acmechallenge.example.com" = {
# Catchall vhost, will redirect users to HTTPS for all vhosts
<link linkend="opt-services.nginx.virtualHosts._name_.serverAliases">serverAliases</link> = [ "*.example.com" ];
# /var/lib/acme/.challenges must be writable by the ACME user
# and readable by the Nginx user.
# By default, this is the case.
locations."/.well-known/acme-challenge" = {
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.root">root</link> = "/var/lib/acme/.challenges";
};
locations."/" = {
<link linkend="opt-services.nginx.virtualHosts._name_.locations._name_.return">return</link> = "301 https://$host$request_uri";
};
};
};
}
# Alternative config for Apache
services.httpd = {
<link linkend="opt-services.httpd.enable">enable = true;</link>
<link linkend="opt-services.httpd.virtualHosts">virtualHosts</link> = {
"acmechallenge.example.com" = {
# Catchall vhost, will redirect users to HTTPS for all vhosts
<link linkend="opt-services.httpd.virtualHosts._name_.serverAliases">serverAliases</link> = [ "*.example.com" ];
# /var/lib/acme/.challenges must be writable by the ACME user and readable by the Apache user.
# By default, this is the case.
<link linkend="opt-services.httpd.virtualHosts._name_.documentRoot">documentRoot</link> = "/var/lib/acme/.challenges";
<link linkend="opt-services.httpd.virtualHosts._name_.extraConfig">extraConfig</link> = ''
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteCond %{REQUEST_URI} !^/\.well-known/acme-challenge [NC]
RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI} [R=301]
'';
};
};
}
</programlisting>
<para>
Now you need to configure ACME to generate a certificate.
</para>
<programlisting>
<xref linkend="opt-security.acme.certs"/>."foo.example.com" = {
<link linkend="opt-security.acme.certs._name_.webroot">webroot</link> = "/var/lib/acme/.challenges";
<link linkend="opt-security.acme.certs._name_.email">email</link> = "foo@example.com";
# Since we have a wildcard vhost to handle port 80,
# we can generate certs for anything!
# Just make sure your DNS resolves them.
<link linkend="opt-security.acme.certs._name_.extraDomains">extraDomains</link> = [ "mail.example.com" ];
};
</programlisting>
<para>
The private key <filename>key.pem</filename> and certificate
<filename>fullchain.pem</filename> will be put into
<filename>/var/lib/acme/foo.example.com</filename>.
</para>
<para>
Refer to <xref linkend="ch-options" /> for all available configuration
options for the <link linkend="opt-security.acme.certs">security.acme</link>
module.
</para>
</section>
<section xml:id="module-security-acme-config-dns">
<title>Configuring ACME for DNS validation</title>
<para>
This is useful if you want to generate a wildcard certificate, since
ACME servers will only hand out wildcard certs over DNS validation.
There a number of supported DNS providers and servers you can utilise,
see the <link xlink:href="https://go-acme.github.io/lego/dns/">lego docs</link>
for provider/server specific configuration values. For the sake of these
docs, we will provide a fully self-hosted example using bind.
</para>
<programlisting>
services.bind = {
<link linkend="opt-services.bind.enable">enable</link> = true;
<link linkend="opt-services.bind.extraConfig">extraConfig</link> = ''
include "/var/lib/secrets/dnskeys.conf";
'';
<link linkend="opt-services.bind.zones">zones</link> = [
rec {
name = "example.com";
file = "/var/db/bind/${name}";
master = true;
extraConfig = "allow-update { key rfc2136key.example.com.; };";
}
];
}
# Now we can configure ACME
<xref linkend="opt-security.acme.acceptTerms" /> = true;
<xref linkend="opt-security.acme.email" /> = "admin+acme@example.com";
<xref linkend="opt-security.acme.certs" />."example.com" = {
<link linkend="opt-security.acme.certs._name_.domain">domain</link> = "*.example.com";
<link linkend="opt-security.acme.certs._name_.dnsProvider">dnsProvider</link> = "rfc2136";
<link linkend="opt-security.acme.certs._name_.credentialsFile">credentialsFile</link> = "/var/lib/secrets/certs.secret";
# We don't need to wait for propagation since this is a local DNS server
<link linkend="opt-security.acme.certs._name_.dnsPropagationCheck">dnsPropagationCheck</link> = false;
};
</programlisting>
<para>
The <filename>dnskeys.conf</filename> and <filename>certs.secret</filename>
must be kept secure and thus you should not keep their contents in your
Nix config. Instead, generate them one time with these commands:
</para>
<programlisting>
mkdir -p /var/lib/secrets
tsig-keygen rfc2136key.example.com &gt; /var/lib/secrets/dnskeys.conf
chown named:root /var/lib/secrets/dnskeys.conf
chmod 400 /var/lib/secrets/dnskeys.conf
# Copy the secret value from the dnskeys.conf, and put it in
# RFC2136_TSIG_SECRET below
cat &gt; /var/lib/secrets/certs.secret &lt;&lt; EOF
RFC2136_NAMESERVER='127.0.0.1:53'
RFC2136_TSIG_ALGORITHM='hmac-sha256.'
RFC2136_TSIG_KEY='rfc2136key.example.com'
RFC2136_TSIG_SECRET='your secret key'
EOF
chmod 400 /var/lib/secrets/certs.secret
</programlisting>
<para>
Now you're all set to generate certs! You should monitor the first invokation
by running <literal>systemctl start acme-example.com.service &amp;
journalctl -fu acme-example.com.service</literal> and watching its log output.
</para>
</section>
</chapter>

View File

@@ -9,6 +9,7 @@ with lib;
];
options.security.apparmor.confineSUIDApplications = mkOption {
type = types.bool;
default = true;
description = ''
Install AppArmor profiles for commonly-used SUID application

View File

@@ -24,22 +24,6 @@ let
motd=${boolToStr cfg.motd}
accept_env_factor=${boolToStr cfg.acceptEnvFactor}
'';
loginCfgFile = optionalAttrs cfg.ssh.enable {
"duo/login_duo.conf" =
{ source = pkgs.writeText "login_duo.conf" configFileLogin;
mode = "0600";
user = "sshd";
};
};
pamCfgFile = optional cfg.pam.enable {
"duo/pam_duo.conf" =
{ source = pkgs.writeText "pam_duo.conf" configFilePam;
mode = "0600";
user = "sshd";
};
};
in
{
imports = [
@@ -198,7 +182,18 @@ in
environment.systemPackages = [ pkgs.duo-unix ];
security.wrappers.login_duo.source = "${pkgs.duo-unix.out}/bin/login_duo";
environment.etc = loginCfgFile // pamCfgFile;
environment.etc."duo/login_duo.conf" = mkIf cfg.ssh.enable
{ source = pkgs.writeText "login_duo.conf" configFileLogin;
mode = "0600";
user = "sshd";
};
environment.etc."duo/pam_duo.conf" = mkIf cfg.pam.enable
{ source = pkgs.writeText "pam_duo.conf" configFilePam;
mode = "0600";
user = "sshd";
};
/* If PAM *and* SSH are enabled, then don't do anything special.
If PAM isn't used, set the default SSH-only options. */

View File

@@ -545,6 +545,7 @@ in
};
security.pam.enableSSHAgentAuth = mkOption {
type = types.bool;
default = false;
description =
''
@@ -555,12 +556,7 @@ in
'';
};
security.pam.enableOTPW = mkOption {
default = false;
description = ''
Enable the OTPW (one-time password) PAM module.
'';
};
security.pam.enableOTPW = mkEnableOption "the OTPW (one-time password) PAM module";
security.pam.u2f = {
enable = mkOption {
@@ -719,12 +715,7 @@ in
};
};
security.pam.enableEcryptfs = mkOption {
default = false;
description = ''
Enable eCryptfs PAM module (mounting ecryptfs home directory on login).
'';
};
security.pam.enableEcryptfs = mkEnableOption "eCryptfs PAM module (mounting ecryptfs home directory on login)";
users.motd = mkOption {
default = null;

View File

@@ -37,14 +37,24 @@ in
after = [ "dev-random.device" ];
# Clean shutdown without DefaultDependencies
conflicts = [ "shutdown.target" ];
before = [
"sysinit.target"
"shutdown.target"
];
description = "Hardware RNG Entropy Gatherer Daemon";
# rngd may have to start early to avoid entropy starvation during boot with encrypted swap
unitConfig.DefaultDependencies = false;
serviceConfig = {
ExecStart = "${pkgs.rng-tools}/sbin/rngd -f"
+ optionalString cfg.debug " -d";
# PrivateTmp would introduce a circular dependency if /tmp is on tmpfs and swap is encrypted,
# thus depending on rngd before swap, while swap depends on rngd to avoid entropy starvation.
NoNewPrivileges = true;
PrivateNetwork = true;
PrivateTmp = true;
ProtectSystem = "full";
ProtectHome = true;
};

View File

@@ -173,7 +173,9 @@ in
config = mkIf cfg.enable {
security.sudo.extraRules = [
# We `mkOrder 600` so that the default rule shows up first, but there is
# still enough room for a user to `mkBefore` it.
security.sudo.extraRules = mkOrder 600 [
{ groups = [ "wheel" ];
commands = [ { command = "ALL"; options = (if cfg.wheelNeedsPassword then [ "SETENV" ] else [ "NOPASSWD" "SETENV" ]); } ];
}

View File

@@ -135,7 +135,7 @@ in {
];
execPkgs = lib.concatMap (opt: let
isSet = config.serviceConfig ? ${opt};
in lib.optional isSet config.serviceConfig.${opt}) execOpts;
in lib.flatten (lib.optional isSet config.serviceConfig.${opt})) execOpts;
unitAttrs = toplevelConfig.systemd.units."${name}.service";
allPkgs = lib.singleton (builtins.toJSON unitAttrs);
unitPkgs = if fullUnit then allPkgs else execPkgs;

View File

@@ -166,7 +166,7 @@ in
boot.specialFileSystems.${parentWrapperDir} = {
fsType = "tmpfs";
options = [ "nodev" ];
options = [ "nodev" "mode=755" ];
};
# Make sure our wrapperDir exports to the PATH env variable when
@@ -184,6 +184,8 @@ in
# programs to be wrapped.
WRAPPER_PATH=${config.system.path}/bin:${config.system.path}/sbin
chmod 755 "${parentWrapperDir}"
# We want to place the tmpdirs for the wrappers to the parent dir.
wrapperDir=$(mktemp --directory --tmpdir="${parentWrapperDir}" wrappers.XXXXXXXXXX)
chmod a+rx $wrapperDir
@@ -194,6 +196,9 @@ in
# Atomically replace the symlink
# See https://axialcorps.com/2013/07/03/atomically-replacing-files-and-directories/
old=$(readlink -f ${wrapperDir})
if [ -e ${wrapperDir}-tmp ]; then
rm --force --recursive ${wrapperDir}-tmp
fi
ln --symbolic --force --no-dereference $wrapperDir ${wrapperDir}-tmp
mv --no-target-directory ${wrapperDir}-tmp ${wrapperDir}
rm --force --recursive $old

View File

@@ -17,6 +17,7 @@ in {
options = {
services.rabbitmq = {
enable = mkOption {
type = types.bool;
default = false;
description = ''
Whether to enable the RabbitMQ server, an Advanced Message

View File

@@ -91,11 +91,7 @@ in
environment.systemPackages = [ alsaUtils ];
environment.etc = mkIf (!pulseaudioEnabled && config.sound.extraConfig != "")
[
{ source = pkgs.writeText "asound.conf" config.sound.extraConfig;
target = "asound.conf";
}
];
{ "asound.conf".text = config.sound.extraConfig; };
# ALSA provides a udev rule for restoring volume settings.
services.udev.packages = [ alsaUtils ];

View File

@@ -37,12 +37,7 @@ in
services.mysqlBackup = {
enable = mkOption {
default = false;
description = ''
Whether to enable MySQL backups.
'';
};
enable = mkEnableOption "MySQL backups";
calendar = mkOption {
type = types.str;

View File

@@ -44,12 +44,7 @@ in {
options = {
services.postgresqlBackup = {
enable = mkOption {
default = false;
description = ''
Whether to enable PostgreSQL dumps.
'';
};
enable = mkEnableOption "PostgreSQL dumps";
startAt = mkOption {
default = "*-*-* 01:15:00";

View File

@@ -258,7 +258,7 @@ in
});
config.assertions = mapAgents (name: cfg: [
{ assertion = cfg.hooksPath == hooksDir || all (v: v == null) (attrValues cfg.hooks);
{ assertion = cfg.hooksPath == (hooksDir cfg) || all (v: v == null) (attrValues cfg.hooks);
message = ''
Options `services.buildkite-agents.${name}.hooksPath' and
`services.buildkite-agents.${name}.hooks.<name>' are mutually exclusive.

View File

@@ -37,6 +37,8 @@ let
haveLocalDB = cfg.dbi == localDB;
inherit (config.system) stateVersion;
in
{
@@ -63,8 +65,7 @@ in
};
package = mkOption {
type = types.path;
default = pkgs.hydra;
type = types.package;
defaultText = "pkgs.hydra";
description = "The Hydra package.";
};
@@ -194,6 +195,34 @@ in
config = mkIf cfg.enable {
warnings = optional (cfg.package.migration or false) ''
You're currently deploying an older version of Hydra which is needed to
make some required database changes[1]. As soon as this is done, it's recommended
to run `hydra-backfill-ids` and set `services.hydra.package` to `pkgs.hydra-unstable`
after that.
[1] https://github.com/NixOS/hydra/pull/711
'';
services.hydra.package = with pkgs;
mkDefault (
if pkgs ? hydra
then throw ''
The Hydra package doesn't exist anymore in `nixpkgs`! It probably exists
due to an overlay. To upgrade Hydra, you need to take two steps as some
bigger changes in the database schema were implemented recently[1]. You first
need to deploy `pkgs.hydra-migration`, run `hydra-backfill-ids` on the server
and then deploy `pkgs.hydra-unstable`.
If you want to use `pkgs.hydra` from your overlay, please set `services.hydra.package`
explicitly to `pkgs.hydra` and make sure you know what you're doing.
[1] https://github.com/NixOS/hydra/pull/711
''
else if versionOlder stateVersion "20.03" then hydra-migration
else hydra-unstable
);
users.groups.hydra = {
gid = config.ids.gids.hydra;
};

View File

@@ -11,10 +11,7 @@ with lib;
services.clickhouse = {
enable = mkOption {
default = false;
description = "Whether to enable ClickHouse database server.";
};
enable = mkEnableOption "ClickHouse database server";
};

View File

@@ -40,12 +40,7 @@ in
services.firebird = {
enable = mkOption {
default = false;
description = ''
Whether to enable the Firebird super server.
'';
};
enable = mkEnableOption "the Firebird super server";
package = mkOption {
default = pkgs.firebirdSuper;

View File

@@ -18,12 +18,7 @@ in
services.memcached = {
enable = mkOption {
default = false;
description = "
Whether to enable Memcached.
";
};
enable = mkEnableOption "Memcached";
user = mkOption {
default = "memcached";

View File

@@ -29,12 +29,7 @@ in
services.mongodb = {
enable = mkOption {
default = false;
description = "
Whether to enable the MongoDB server.
";
};
enable = mkEnableOption "the MongoDB server";
package = mkOption {
default = pkgs.mongodb;

View File

@@ -10,16 +10,8 @@ let
isMariaDB = lib.getName mysql == lib.getName pkgs.mariadb;
isMysqlAtLeast57 =
(lib.getName mysql == lib.getName pkgs.mysql57)
&& (builtins.compareVersions mysql.version "5.7" >= 0);
mysqldOptions =
"--user=${cfg.user} --datadir=${cfg.dataDir} --basedir=${mysql}";
# For MySQL 5.7+, --insecure creates the root user without password
# (earlier versions and MariaDB do this by default).
installOptions =
"${mysqldOptions} ${lib.optionalString isMysqlAtLeast57 "--insecure"}";
in
@@ -307,9 +299,14 @@ in
pkgs.nettools
];
preStart = ''
preStart = if isMariaDB then ''
if ! test -e ${cfg.dataDir}/mysql; then
${mysql}/bin/mysql_install_db --defaults-file=/etc/my.cnf ${installOptions}
${mysql}/bin/mysql_install_db --defaults-file=/etc/my.cnf ${mysqldOptions}
touch /tmp/mysql_init
fi
'' else ''
if ! test -e ${cfg.dataDir}/mysql; then
${mysql}/bin/mysqld --defaults-file=/etc/my.cnf ${mysqldOptions} --initialize-insecure
touch /tmp/mysql_init
fi
'';

View File

@@ -7,12 +7,10 @@
<!-- FIXME: render nicely -->
<!-- FIXME: source can be added automatically -->
<para>
<emphasis>Source:</emphasis>
<filename>modules/services/databases/postgresql.nix</filename>
<emphasis>Source:</emphasis> <filename>modules/services/databases/postgresql.nix</filename>
</para>
<para>
<emphasis>Upstream documentation:</emphasis>
<link xlink:href="http://www.postgresql.org/docs/"/>
<emphasis>Upstream documentation:</emphasis> <link xlink:href="http://www.postgresql.org/docs/"/>
</para>
<!-- FIXME: more stuff, like maintainer? -->
<para>
@@ -23,18 +21,12 @@
<title>Configuring</title>
<para>
To enable PostgreSQL, add the following to your
<filename>configuration.nix</filename>:
To enable PostgreSQL, add the following to your <filename>configuration.nix</filename>:
<programlisting>
<xref linkend="opt-services.postgresql.enable"/> = true;
<xref linkend="opt-services.postgresql.package"/> = pkgs.postgresql_11;
</programlisting>
Note that you are required to specify the desired version of PostgreSQL
(e.g. <literal>pkgs.postgresql_11</literal>). Since upgrading your
PostgreSQL version requires a database dump and reload (see below), NixOS
cannot provide a default value for
<xref linkend="opt-services.postgresql.package"/> such as the most recent
release of PostgreSQL.
Note that you are required to specify the desired version of PostgreSQL (e.g. <literal>pkgs.postgresql_11</literal>). Since upgrading your PostgreSQL version requires a database dump and reload (see below), NixOS cannot provide a default value for <xref linkend="opt-services.postgresql.package"/> such as the most recent release of PostgreSQL.
</para>
<!--
@@ -51,9 +43,7 @@ Type "help" for help.
-->
<para>
By default, PostgreSQL stores its databases in
<filename>/var/lib/postgresql/$psqlSchema</filename>. You can override this using
<xref linkend="opt-services.postgresql.dataDir"/>, e.g.
By default, PostgreSQL stores its databases in <filename>/var/lib/postgresql/$psqlSchema</filename>. You can override this using <xref linkend="opt-services.postgresql.dataDir"/>, e.g.
<programlisting>
<xref linkend="opt-services.postgresql.dataDir"/> = "/data/postgresql";
</programlisting>
@@ -63,25 +53,83 @@ Type "help" for help.
<title>Upgrading</title>
<para>
FIXME: document dump/upgrade/load cycle.
Major PostgreSQL upgrade requires PostgreSQL downtime and a few imperative steps to be called. To simplify this process, use the following NixOS module:
<programlisting>
containers.temp-pg.config.services.postgresql = {
enable = true;
package = pkgs.postgresql_12;
## set a custom new dataDir
# dataDir = "/some/data/dir";
};
environment.systemPackages =
let newpg = config.containers.temp-pg.config.services.postgresql;
in [
(pkgs.writeScriptBin "upgrade-pg-cluster" ''
set -x
export OLDDATA="${config.services.postgresql.dataDir}"
export NEWDATA="${newpg.dataDir}"
export OLDBIN="${config.services.postgresql.package}/bin"
export NEWBIN="${newpg.package}/bin"
install -d -m 0700 -o postgres -g postgres "$NEWDATA"
cd "$NEWDATA"
sudo -u postgres $NEWBIN/initdb -D "$NEWDATA"
systemctl stop postgresql # old one
sudo -u postgres $NEWBIN/pg_upgrade \
--old-datadir "$OLDDATA" --new-datadir "$NEWDATA" \
--old-bindir $OLDBIN --new-bindir $NEWBIN \
"$@"
'')
];
</programlisting>
</para>
<para>
The upgrade process is:
</para>
<orderedlist>
<listitem>
<para>
Rebuild nixos configuration with the configuration above added to your <filename>configuration.nix</filename>. Alternatively, add that into separate file and reference it in <literal>imports</literal> list.
</para>
</listitem>
<listitem>
<para>
Login as root (<literal>sudo su -</literal>)
</para>
</listitem>
<listitem>
<para>
Run <literal>upgrade-pg-cluster</literal>. It will stop old postgresql, initialize new one and migrate old one to new one. You may supply arguments like <literal>--jobs 4</literal> and <literal>--link</literal> to speedup migration process. See <link xlink:href="https://www.postgresql.org/docs/current/pgupgrade.html" /> for details.
</para>
</listitem>
<listitem>
<para>
Change postgresql package in NixOS configuration to the one you were upgrading to, and change <literal>dataDir</literal> to the one you have migrated to. Rebuild NixOS. This should start new postgres using upgraded data directory.
</para>
</listitem>
<listitem>
<para>
After upgrade you may want to <literal>ANALYZE</literal> new db.
</para>
</listitem>
</orderedlist>
</section>
<section xml:id="module-services-postgres-options">
<title>Options</title>
<para>
A complete list of options for the PostgreSQL module may be found
<link linkend="opt-services.postgresql.enable">here</link>.
A complete list of options for the PostgreSQL module may be found <link linkend="opt-services.postgresql.enable">here</link>.
</para>
</section>
<section xml:id="module-services-postgres-plugins">
<title>Plugins</title>
<para>
Plugins collection for each PostgreSQL version can be accessed with
<literal>.pkgs</literal>. For example, for
<literal>pkgs.postgresql_11</literal> package, its plugin collection is
accessed by <literal>pkgs.postgresql_11.pkgs</literal>:
Plugins collection for each PostgreSQL version can be accessed with <literal>.pkgs</literal>. For example, for <literal>pkgs.postgresql_11</literal> package, its plugin collection is accessed by <literal>pkgs.postgresql_11.pkgs</literal>:
<screen>
<prompt>$ </prompt>nix repl '&lt;nixpkgs&gt;'
@@ -98,8 +146,9 @@ postgresql_11.pkgs.pg_partman postgresql_11.pkgs.pgroonga
...
</screen>
</para>
<para>
To add plugins via NixOS configuration, set <literal>services.postgresql.extraPlugins</literal>:
To add plugins via NixOS configuration, set <literal>services.postgresql.extraPlugins</literal>:
<programlisting>
<xref linkend="opt-services.postgresql.package"/> = pkgs.postgresql_11;
<xref linkend="opt-services.postgresql.extraPlugins"/> = with pkgs.postgresql_11.pkgs; [
@@ -108,10 +157,9 @@ postgresql_11.pkgs.pg_partman postgresql_11.pkgs.pgroonga
];
</programlisting>
</para>
<para>
You can build custom PostgreSQL-with-plugins (to be used outside of NixOS) using
function <literal>.withPackages</literal>. For example, creating a custom
PostgreSQL package in an overlay can look like:
You can build custom PostgreSQL-with-plugins (to be used outside of NixOS) using function <literal>.withPackages</literal>. For example, creating a custom PostgreSQL package in an overlay can look like:
<programlisting>
self: super: {
postgresql_custom = self.postgresql_11.withPackages (ps: [
@@ -121,8 +169,9 @@ self: super: {
}
</programlisting>
</para>
<para>
Here's a recipe on how to override a particular plugin through an overlay:
Here's a recipe on how to override a particular plugin through an overlay:
<programlisting>
self: super: {
postgresql_11 = super.postgresql_11.override { this = self.postgresql_11; } // {

View File

@@ -13,10 +13,7 @@ with lib;
services.virtuoso = {
enable = mkOption {
default = false;
description = "Whether to enable Virtuoso Opensource database server.";
};
enable = mkEnableOption "Virtuoso Opensource database server";
config = mkOption {
default = "";

View File

@@ -13,6 +13,8 @@ with lib;
###### implementation
config = mkIf config.services.gnome3.gnome-remote-desktop.enable {
services.pipewire.enable = true;
systemd.packages = [ pkgs.gnome3.gnome-remote-desktop ];
};
}

Some files were not shown because too many files have changed in this diff Show More