summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>2024-02-25 00:14:41 +0000
committerGitHub <noreply@github.com>2024-02-25 00:14:41 +0000
commit5f2f12a661c2d3388bce8180140ff0cf0963535c (patch)
tree965ad019736ed635d083806dc2f0835843dc1d19
parentMerge #291034: c-ares: apply patch for CVE-2024-25629 (diff)
parentMerge release-23.11 into staging-next-23.11 (diff)
downloadnixpkgs-5f2f12a661c2d3388bce8180140ff0cf0963535c.tar.gz
Merge staging-next-23.11 into staging-23.11
-rw-r--r--pkgs/applications/misc/clipit/default.nix3
-rw-r--r--pkgs/applications/misc/logseq/default.nix14
-rw-r--r--pkgs/applications/networking/browsers/chromium/upstream-info.nix30
-rw-r--r--pkgs/applications/networking/mailreaders/thunderbird/packages.nix4
-rw-r--r--pkgs/applications/science/math/geogebra/default.nix2
-rw-r--r--pkgs/applications/version-management/git-absorb/default.nix8
-rw-r--r--pkgs/applications/version-management/gitea/XSS-vulnerabilities-1.21.6.patch223
-rw-r--r--pkgs/applications/version-management/gitea/default.nix1
-rw-r--r--pkgs/by-name/sa/samdump2/package.nix70
-rw-r--r--pkgs/by-name/un/unix-privesc-check/package.nix87
-rw-r--r--pkgs/by-name/un/unix-privesc-check/unix-privesc-check.patch20
-rw-r--r--pkgs/development/compilers/llvm/17/default.nix4
-rw-r--r--pkgs/development/compilers/llvm/common/mlir/default.nix71
-rw-r--r--pkgs/development/compilers/llvm/common/mlir/gnu-install-dirs.patch15
-rw-r--r--pkgs/development/compilers/llvm/git/default.nix4
-rw-r--r--pkgs/development/compilers/unison/default.nix6
-rw-r--r--pkgs/development/java-modules/postgresql_jdbc/default.nix4
-rw-r--r--pkgs/development/libraries/java/commons/compress/default.nix4
-rw-r--r--pkgs/development/tools/rust/cargo-semver-checks/default.nix6
-rw-r--r--pkgs/servers/mastodon/gemset.nix80
-rw-r--r--pkgs/servers/mastodon/source.nix4
-rw-r--r--pkgs/servers/monitoring/plugins/default.nix5
-rw-r--r--pkgs/top-level/all-packages.nix2
23 files changed, 582 insertions, 85 deletions
diff --git a/pkgs/applications/misc/clipit/default.nix b/pkgs/applications/misc/clipit/default.nix
index fafcf3d54404..b40bc4fec930 100644
--- a/pkgs/applications/misc/clipit/default.nix
+++ b/pkgs/applications/misc/clipit/default.nix
@@ -28,8 +28,9 @@ stdenv.mkDerivation rec {
meta = with lib; {
description = "Lightweight GTK Clipboard Manager";
inherit (src.meta) homepage;
- license = licenses.gpl3;
+ license = licenses.gpl3Plus;
platforms = platforms.linux;
+ mainProgram = "clipit";
maintainers = with maintainers; [ kamilchm ];
};
}
diff --git a/pkgs/applications/misc/logseq/default.nix b/pkgs/applications/misc/logseq/default.nix
index a40064bb5ff8..57248b6b7744 100644
--- a/pkgs/applications/misc/logseq/default.nix
+++ b/pkgs/applications/misc/logseq/default.nix
@@ -4,7 +4,7 @@
, appimageTools
, makeWrapper
# graphs will not sync without matching upstream's major electron version
-, electron_25
+, electron_27
, git
, nix-update-script
}:
@@ -14,11 +14,11 @@ stdenv.mkDerivation (finalAttrs: let
in {
pname = "logseq";
- version = "0.9.20";
+ version = "0.10.6";
src = fetchurl {
url = "https://github.com/logseq/logseq/releases/download/${version}/logseq-linux-x64-${version}.AppImage";
- hash = "sha256-iT0Gc/ePx1tUNTPoE2Ol+dHUmbS4CkneZbyraRBx5Ak=";
+ hash = "sha256-OUQh+6HRnzxw8Nn/OkU+DkjPKWKpMN0xchD1vPU3KV8=";
name = "${pname}-${version}.AppImage";
};
@@ -57,7 +57,7 @@ in {
postFixup = ''
# set the env "LOCAL_GIT_DIRECTORY" for dugite so that we can use the git in nixpkgs
- makeWrapper ${electron_25}/bin/electron $out/bin/${pname} \
+ makeWrapper ${electron_27}/bin/electron $out/bin/${pname} \
--set "LOCAL_GIT_DIRECTORY" ${git} \
--add-flags $out/share/${pname}/resources/app \
--add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--ozone-platform-hint=auto --enable-features=WaylandWindowDecorations}}" \
@@ -66,12 +66,12 @@ in {
passthru.updateScript = nix-update-script { };
- meta = with lib; {
+ meta = {
description = "A local-first, non-linear, outliner notebook for organizing and sharing your personal knowledge base";
homepage = "https://github.com/logseq/logseq";
changelog = "https://github.com/logseq/logseq/releases/tag/${version}";
- license = licenses.agpl3Plus;
- maintainers = with maintainers; [ ];
+ license = lib.licenses.agpl3Plus;
+ maintainers = with lib.maintainers; [ ];
platforms = [ "x86_64-linux" ];
};
})
diff --git a/pkgs/applications/networking/browsers/chromium/upstream-info.nix b/pkgs/applications/networking/browsers/chromium/upstream-info.nix
index daaad6ae08f4..c4888aac71f6 100644
--- a/pkgs/applications/networking/browsers/chromium/upstream-info.nix
+++ b/pkgs/applications/networking/browsers/chromium/upstream-info.nix
@@ -1,11 +1,11 @@
{
stable = {
chromedriver = {
- hash_darwin = "sha256-Mdm+aOd8czNX7oJcNCSdu5TFwIlh5Y37OLdiPpOD+mk=";
+ hash_darwin = "sha256-qo7eiMC4MR4pskSim6twkC2QDeqe3qfZsIEe5mjS7jg=";
hash_darwin_aarch64 =
- "sha256-ZF8nfAXX99I4x6RUEvQkiXZ/SMugXYYyzgC1SzcE1OE=";
- hash_linux = "sha256-DIC7Ew7aCvtYMVXVXsnMItdeLPDdkNZXZH35I0ZdWEs=";
- version = "122.0.6261.57";
+ "sha256-RHqu0wNeAx34LTkVgNjBfXrSWvZ1G7OkNAIGA4WUhmw=";
+ hash_linux = "sha256-K4QeHFp520Z3KjefvVsJf8V7gz7gTf2BCSW4Jxz/H9M=";
+ version = "122.0.6261.69";
};
deps = {
gn = {
@@ -15,25 +15,25 @@
version = "2024-01-22";
};
};
- hash = "sha256-VvurD1r89dI0ahaVDQ3yinGlHOfzzm7TkL09tF4nebE=";
- hash_deb_amd64 = "sha256-Q3AUKzUsRzW00+WLhuri86QzBGk/rlq5Hk+NdoRbbM4=";
- version = "122.0.6261.57";
+ hash = "sha256-uEN1hN6DOLgw4QDrMBZdiLLPx+yKQc5MimIf/vbCC84=";
+ hash_deb_amd64 = "sha256-k3/Phs72eIMB6LAU4aU0+ze/cRu6KlRhpBshKhmq9N4=";
+ version = "122.0.6261.69";
};
ungoogled-chromium = {
deps = {
gn = {
- hash = "sha256-eD3KORYYuIH+94+BgL+yFD5lTQFvj/MqPU9DPiHc98s=";
- rev = "7367b0df0a0aa25440303998d54045bda73935a5";
+ hash = "sha256-UhdDsq9JyP0efGpAaJ/nLp723BbjM6pkFPcAnQbgMKY=";
+ rev = "f99e015ac35f689cfdbf46e4eb174e5d2da78d8e";
url = "https://gn.googlesource.com/gn";
- version = "2023-11-28";
+ version = "2024-01-22";
};
ungoogled-patches = {
- hash = "sha256-nJDLCVynuGFRIjLBV0NmC0zHeEDHjzFM16FKAv2QyNY=";
- rev = "121.0.6167.184-1";
+ hash = "sha256-G+agHdsssYhsyi4TgJUJBqMEnEgQ7bYeqpTqmonXI6I=";
+ rev = "122.0.6261.69-1";
};
};
- hash = "sha256-mLXBaW4KBieOiz2gRXfgA/KPdmUnNlpUIOqdj7CywcY=";
- hash_deb_amd64 = "sha256-UDgO1sJ7bggFTe7C36CnHYXjG9rM+ZqFCOzNyIDpQ0Y=";
- version = "121.0.6167.184";
+ hash = "sha256-uEN1hN6DOLgw4QDrMBZdiLLPx+yKQc5MimIf/vbCC84=";
+ hash_deb_amd64 = "sha256-k3/Phs72eIMB6LAU4aU0+ze/cRu6KlRhpBshKhmq9N4=";
+ version = "122.0.6261.69";
};
}
diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix
index 4f74168837fd..46d23c54b932 100644
--- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix
+++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix
@@ -44,13 +44,13 @@ rec {
thunderbird-115 = (buildMozillaMach rec {
pname = "thunderbird";
- version = "115.7.0";
+ version = "115.8.0";
application = "comm/mail";
applicationName = "Mozilla Thunderbird";
binaryName = pname;
src = fetchurl {
url = "mirror://mozilla/thunderbird/releases/${version}/source/thunderbird-${version}.source.tar.xz";
- sha512 = "de9edb81cf5da494101bf927a5b963ccdec0cc9bff87ebd72d896c6e25102c1113b326f67302a81abd237048aa1e6150c4a97fe4b1892bc80030cbab9099e2d8";
+ sha512 = "a0bdd34bebda4973f714422293f10a5a96c2b12f097c68d76fa37c48943fdbfb32dd2e504faa0b88fd699118b1903e18c3bb54cb32cd5e2ff60c09966b23e79c";
};
extraPatches = [
# The file to be patched is different from firefox's `no-buildconfig-ffx90.patch`.
diff --git a/pkgs/applications/science/math/geogebra/default.nix b/pkgs/applications/science/math/geogebra/default.nix
index f4c6e724270d..62fb57115075 100644
--- a/pkgs/applications/science/math/geogebra/default.nix
+++ b/pkgs/applications/science/math/geogebra/default.nix
@@ -4,7 +4,7 @@ let
version = "5-0-785-0";
srcIcon = fetchurl {
- url = "http://static.geogebra.org/images/geogebra-logo.svg";
+ url = "https://web.archive.org/web/20200227000442if_/https://static.geogebra.org/images/geogebra-logo.svg";
hash = "sha256-Vd7Wteya04JJT4WNirXe8O1sfVKUgc0hKGOy7d47Xgc=";
};
diff --git a/pkgs/applications/version-management/git-absorb/default.nix b/pkgs/applications/version-management/git-absorb/default.nix
index b0d00c912a78..13dcac9fde6d 100644
--- a/pkgs/applications/version-management/git-absorb/default.nix
+++ b/pkgs/applications/version-management/git-absorb/default.nix
@@ -2,20 +2,20 @@
rustPlatform.buildRustPackage rec {
pname = "git-absorb";
- version = "0.6.10";
+ version = "0.6.12";
src = fetchFromGitHub {
owner = "tummychow";
- repo = pname;
+ repo = "git-absorb";
rev = "refs/tags/${version}";
- hash = "sha256-lFaiv9bgzu6XVcQuLXWoWsKl0cylfrF5rC0i3qj+zU0=";
+ hash = "sha256-yHCO1v1d0MUakae16fFVvtKG3rVxU/Cii/G6IKzyebA=";
};
nativeBuildInputs = [ installShellFiles ];
buildInputs = lib.optionals stdenv.isDarwin [ Security ];
- cargoHash = "sha256-hksSyVdsGe/Ha3F5orL4W/k2nzFCuMqQjBgsT1jiWLw=";
+ cargoHash = "sha256-Bx7gH7jSLizG95JyBtziPBby9mF1Nj3CQexIg6gaiM0=";
postInstall = ''
installManPage Documentation/git-absorb.1
diff --git a/pkgs/applications/version-management/gitea/XSS-vulnerabilities-1.21.6.patch b/pkgs/applications/version-management/gitea/XSS-vulnerabilities-1.21.6.patch
new file mode 100644
index 000000000000..40488aefd700
--- /dev/null
+++ b/pkgs/applications/version-management/gitea/XSS-vulnerabilities-1.21.6.patch
@@ -0,0 +1,223 @@
+From f1ecf76550fe6ae9ddd8e77fa76f0afff248ac72 Mon Sep 17 00:00:00 2001
+From: 6543 <6543@obermui.de>
+Date: Thu, 22 Feb 2024 23:37:21 +0100
+Subject: [PATCH] Fix XSS vulnerabilities (#29336)
+
+- The Wiki page did not sanitize author name
+- the reviewer name on a "dismiss review" comment is also affected
+- the migration page has some spots
+
+---------
+
+Signed-off-by: jolheiser <john.olheiser@gmail.com>
+Co-authored-by: Gusted <postmaster@gusted.xyz>
+Co-authored-by: jolheiser <john.olheiser@gmail.com>
+(cherry picked from commit 4435d8a4b6a2c4a2aa667a9a326e7aaf6a988932)
+---
+ .../repo/issue/view_content/comments.tmpl | 2 +-
+ templates/repo/migrate/migrating.tmpl | 6 +-
+ templates/repo/settings/options.tmpl | 4 +-
+ templates/repo/wiki/revision.tmpl | 2 +-
+ templates/repo/wiki/view.tmpl | 2 +-
+ tests/integration/xss_test.go | 85 +++++++++++++++++++
+ 6 files changed, 93 insertions(+), 8 deletions(-)
+
+diff --git a/templates/repo/issue/view_content/comments.tmpl b/templates/repo/issue/view_content/comments.tmpl
+index 0e3fccd1c..ecf77083d 100644
+--- a/templates/repo/issue/view_content/comments.tmpl
++++ b/templates/repo/issue/view_content/comments.tmpl
+@@ -775,7 +775,7 @@
+ {{else}}
+ {{$reviewerName = .Review.OriginalAuthor}}
+ {{end}}
+- {{$.locale.Tr "repo.issues.review.dismissed" $reviewerName $createdStr | Safe}}
++ {{$.locale.Tr "repo.issues.review.dismissed" ($reviewerName | Escape) $createdStr | Safe}}
+ </span>
+ </div>
+ {{if .Content}}
+diff --git a/templates/repo/migrate/migrating.tmpl b/templates/repo/migrate/migrating.tmpl
+index 58c453fe5..8c8bb9291 100644
+--- a/templates/repo/migrate/migrating.tmpl
++++ b/templates/repo/migrate/migrating.tmpl
+@@ -21,12 +21,12 @@
+ <div class="ui stackable middle very relaxed page grid">
+ <div class="sixteen wide center aligned centered column">
+ <div id="repo_migrating_progress">
+- <p>{{.locale.Tr "repo.migrate.migrating" .CloneAddr | Safe}}</p>
++ <p>{{.locale.Tr "repo.migrate.migrating" (.CloneAddr | Escape) | Safe}}</p>
+ <p id="repo_migrating_progress_message"></p>
+ </div>
+ <div id="repo_migrating_failed" class="gt-hidden">
+ {{if .CloneAddr}}
+- <p>{{.locale.Tr "repo.migrate.migrating_failed" .CloneAddr | Safe}}</p>
++ <p>{{.locale.Tr "repo.migrate.migrating_failed" (.CloneAddr | Escape) | Safe}}</p>
+ {{else}}
+ <p>{{.locale.Tr "repo.migrate.migrating_failed_no_addr" | Safe}}</p>
+ {{end}}
+@@ -57,7 +57,7 @@
+ <div class="content">
+ <div class="ui warning message">
+ {{.locale.Tr "repo.settings.delete_notices_1" | Safe}}<br>
+- {{.locale.Tr "repo.settings.delete_notices_2" .Repository.FullName | Safe}}
++ {{.locale.Tr "repo.settings.delete_notices_2" (.Repository.FullName | Escape) | Safe}}
+ {{if .Repository.NumForks}}<br>
+ {{.locale.Tr "repo.settings.delete_notices_fork_1"}}
+ {{end}}
+diff --git a/templates/repo/settings/options.tmpl b/templates/repo/settings/options.tmpl
+index d02254414..c02db1c3e 100644
+--- a/templates/repo/settings/options.tmpl
++++ b/templates/repo/settings/options.tmpl
+@@ -943,7 +943,7 @@
+ <div class="content">
+ <div class="ui warning message">
+ {{.locale.Tr "repo.settings.delete_notices_1" | Safe}}<br>
+- {{.locale.Tr "repo.settings.delete_notices_2" .Repository.FullName | Safe}}
++ {{.locale.Tr "repo.settings.delete_notices_2" (.Repository.FullName | Escape) | Safe}}
+ {{if .Repository.NumForks}}<br>
+ {{.locale.Tr "repo.settings.delete_notices_fork_1"}}
+ {{end}}
+@@ -978,7 +978,7 @@
+ <div class="content">
+ <div class="ui warning message">
+ {{.locale.Tr "repo.settings.delete_notices_1" | Safe}}<br>
+- {{.locale.Tr "repo.settings.wiki_delete_notices_1" .Repository.Name | Safe}}
++ {{.locale.Tr "repo.settings.wiki_delete_notices_1" (.Repository.Name | Escape) | Safe}}
+ </div>
+ <form class="ui form" action="{{.Link}}" method="post">
+ {{.CsrfTokenHtml}}
+diff --git a/templates/repo/wiki/revision.tmpl b/templates/repo/wiki/revision.tmpl
+index b2d6e6392..4d8fa25d3 100644
+--- a/templates/repo/wiki/revision.tmpl
++++ b/templates/repo/wiki/revision.tmpl
+@@ -10,7 +10,7 @@
+ {{$title}}
+ <div class="ui sub header gt-word-break">
+ {{$timeSince := TimeSince .Author.When $.locale}}
+- {{.locale.Tr "repo.wiki.last_commit_info" .Author.Name $timeSince | Safe}}
++ {{.locale.Tr "repo.wiki.last_commit_info" (.Author.Name | Escape) $timeSince | Safe}}
+ </div>
+ </div>
+ </div>
+diff --git a/templates/repo/wiki/view.tmpl b/templates/repo/wiki/view.tmpl
+index c294af316..e64a106bc 100644
+--- a/templates/repo/wiki/view.tmpl
++++ b/templates/repo/wiki/view.tmpl
+@@ -40,7 +40,7 @@
+ {{$title}}
+ <div class="ui sub header">
+ {{$timeSince := TimeSince .Author.When $.locale}}
+- {{.locale.Tr "repo.wiki.last_commit_info" .Author.Name $timeSince | Safe}}
++ {{.locale.Tr "repo.wiki.last_commit_info" (.Author.Name | Escape) $timeSince | Safe}}
+ </div>
+ </div>
+ <div class="eight wide right aligned column">
+diff --git a/tests/integration/xss_test.go b/tests/integration/xss_test.go
+index e575ed399..9ed4d3560 100644
+--- a/tests/integration/xss_test.go
++++ b/tests/integration/xss_test.go
+@@ -4,13 +4,23 @@
+ package integration
+
+ import (
++ "context"
++ "fmt"
+ "net/http"
++ "net/url"
++ "os"
++ "path/filepath"
++ "strings"
+ "testing"
++ "time"
+
+ "code.gitea.io/gitea/models/unittest"
+ user_model "code.gitea.io/gitea/models/user"
++ "code.gitea.io/gitea/modules/git"
+ "code.gitea.io/gitea/tests"
+
++ gogit "github.com/go-git/go-git/v5"
++ "github.com/go-git/go-git/v5/plumbing/object"
+ "github.com/stretchr/testify/assert"
+ )
+
+@@ -37,3 +47,78 @@ func TestXSSUserFullName(t *testing.T) {
+ htmlDoc.doc.Find("div.content").Find(".header.text.center").Text(),
+ )
+ }
++
++func TestXSSWikiLastCommitInfo(t *testing.T) {
++ onGiteaRun(t, func(t *testing.T, u *url.URL) {
++ // Prepare the environment.
++ dstPath := t.TempDir()
++ r := fmt.Sprintf("%suser2/repo1.wiki.git", u.String())
++ u, err := url.Parse(r)
++ assert.NoError(t, err)
++ u.User = url.UserPassword("user2", userPassword)
++ assert.NoError(t, git.CloneWithArgs(context.Background(), git.AllowLFSFiltersArgs(), u.String(), dstPath, git.CloneRepoOptions{}))
++
++ // Use go-git here, because using git wouldn't work, it has code to remove
++ // `<`, `>` and `\n` in user names. Even though this is permitted and
++ // wouldn't result in a error by a Git server.
++ gitRepo, err := gogit.PlainOpen(dstPath)
++ if err != nil {
++ panic(err)
++ }
++
++ w, err := gitRepo.Worktree()
++ if err != nil {
++ panic(err)
++ }
++
++ filename := filepath.Join(dstPath, "Home.md")
++ err = os.WriteFile(filename, []byte("Oh, a XSS attack?"), 0o644)
++ if !assert.NoError(t, err) {
++ t.FailNow()
++ }
++
++ _, err = w.Add("Home.md")
++ if !assert.NoError(t, err) {
++ t.FailNow()
++ }
++
++ _, err = w.Commit("Yay XSS", &gogit.CommitOptions{
++ Author: &object.Signature{
++ Name: `Gusted <script class="evil">alert('Oh no!');</script>`,
++ Email: "valid@example.org",
++ When: time.Date(2024, time.January, 31, 0, 0, 0, 0, time.UTC),
++ },
++ })
++ if !assert.NoError(t, err) {
++ t.FailNow()
++ }
++
++ // Push.
++ _, _, err = git.NewCommand(git.DefaultContext, "push").AddArguments(git.ToTrustedCmdArgs([]string{"origin", "master"})...).RunStdString(&git.RunOpts{Dir: dstPath})
++ assert.NoError(t, err)
++
++ // Check on page view.
++ t.Run("Page view", func(t *testing.T) {
++ defer tests.PrintCurrentTest(t)()
++
++ req := NewRequest(t, http.MethodGet, "/user2/repo1/wiki/Home")
++ resp := MakeRequest(t, req, http.StatusOK)
++ htmlDoc := NewHTMLParser(t, resp.Body)
++
++ htmlDoc.AssertElement(t, "script.evil", false)
++ assert.EqualValues(t, `Gusted edited this page 0001-01-01 00:00:00 +00:00`, strings.TrimSpace(htmlDoc.Find(".ui.sub.header").Text()))
++ })
++
++ // Check on revisions page.
++ t.Run("Revision page", func(t *testing.T) {
++ defer tests.PrintCurrentTest(t)()
++
++ req := NewRequest(t, http.MethodGet, "/user2/repo1/wiki/Home?action=_revision")
++ resp := MakeRequest(t, req, http.StatusOK)
++ htmlDoc := NewHTMLParser(t, resp.Body)
++
++ htmlDoc.AssertElement(t, "script.evil", false)
++ assert.EqualValues(t, `Gusted edited this page 0001-01-01 00:00:00 +00:00`, strings.TrimSpace(htmlDoc.Find(".ui.sub.header").Text()))
++ })
++ })
++}
+--
+2.43.2
+
diff --git a/pkgs/applications/version-management/gitea/default.nix b/pkgs/applications/version-management/gitea/default.nix
index f3c05bdbeb73..9f452d73f46e 100644
--- a/pkgs/applications/version-management/gitea/default.nix
+++ b/pkgs/applications/version-management/gitea/default.nix
@@ -38,6 +38,7 @@ buildGoModule rec {
url = "https://patch-diff.githubusercontent.com/raw/go-gitea/gitea/pull/28877.patch";
hash = "sha256-cThW3EnHR695thajbnmfNziVB/iBP9OPeDgWbszYIeg=";
})
+ ./XSS-vulnerabilities-1.21.6.patch
];
postPatch = ''
diff --git a/pkgs/by-name/sa/samdump2/package.nix b/pkgs/by-name/sa/samdump2/package.nix
new file mode 100644
index 000000000000..a1a045af7664
--- /dev/null
+++ b/pkgs/by-name/sa/samdump2/package.nix
@@ -0,0 +1,70 @@
+{ lib
+, stdenv
+, fetchurl
+, fetchpatch
+, openssl
+, pkg-config
+, which
+}:
+
+stdenv.mkDerivation (finalAttrs: {
+ pname = "samdump2";
+ version = "3.0.0";
+
+ src = fetchurl {
+ url = "mirror://sourceforge/project/ophcrack/samdump2/${finalAttrs.version}/samdump2-${finalAttrs.version}.tar.bz2";
+ hash = "sha256-YCZZrzDFZXUPoBZQ4KIj0mNVtd+Y8vvDDjpsWT7U5SY=";
+ };
+
+ nativeBuildInputs = [ pkg-config which ];
+ buildInputs = [
+ openssl
+ ];
+
+ patches = [
+ (fetchpatch {
+ # fixes a FTBFS linker bug
+ url = "https://salsa.debian.org/pkg-security-team/samdump2/-/raw/b4c9f14f5a1925106e7c62c9967d430c1104df0c/debian/patches/10_ftbfs_link.patch";
+ hash = "sha256-TGzxi44dDAispG+rK/kYYMzKjt10p+ZyfVDWKG+Gw/s=";
+ })
+ (fetchpatch {
+ # the makefile overrides flags so you can't set them via d/rules or the environment
+ url = "https://salsa.debian.org/pkg-security-team/samdump2/-/raw/b4c9f14f5a1925106e7c62c9967d430c1104df0c/debian/patches/20_compiler_flags.patch";
+ hash = "sha256-VdDiNAQhlauAB4Ws/pvWMJY2rMKr3qhyVGX2GoxaagI=";
+ })
+ (fetchpatch {
+ # the makefile has a infos dep, but no target
+ url = "https://salsa.debian.org/pkg-security-team/samdump2/-/raw/b4c9f14f5a1925106e7c62c9967d430c1104df0c/debian/patches/30_install_infos.patch";
+ hash = "sha256-Y7kdU+ywUYFm2VySGFa0QE1OvzoTa0eFSWp0VFmY5iM=";
+ })
+ (fetchpatch {
+ # change the formatting in the manpage to make it more readable
+ url = "https://salsa.debian.org/pkg-security-team/samdump2/-/raw/b4c9f14f5a1925106e7c62c9967d430c1104df0c/debian/patches/40_manpage_formatting.patch";
+ hash = "sha256-L4BjtiGk91nTKZdr0SXbaxkD2mzmkU3UJlc4TZfXS4Y=";
+ })
+ (fetchpatch {
+ # fix a FTBFS with OpenSSL 1.1.0. (Closes: #828537)
+ url = "https://salsa.debian.org/pkg-security-team/samdump2/-/raw/b4c9f14f5a1925106e7c62c9967d430c1104df0c/debian/patches/50_openssl.patch";
+ hash = "sha256-pdLOSt7kX9uPg4wDVstxh3NC/DboQCP+5/wCjuJmruY=";
+ })
+ ];
+
+ postPatch = ''
+ substituteInPlace Makefile \
+ --replace " -o root -g root" ""
+ '';
+
+ makeFlags = [
+ "PREFIX=$(out)"
+ "CC=cc"
+ ];
+
+ meta = with lib; {
+ description = "Dump password hashes from a Windows NT/2k/XP installation";
+ mainProgram = "samdump2";
+ homepage = "https://sourceforge.net/projects/ophcrack/files/samdump2";
+ license = licenses.gpl2Plus;
+ maintainers = with maintainers; [ d3vil0p3r ];
+ platforms = platforms.unix;
+ };
+})
diff --git a/pkgs/by-name/un/unix-privesc-check/package.nix b/pkgs/by-name/un/unix-privesc-check/package.nix
new file mode 100644
index 000000000000..5ac7a6d29de1
--- /dev/null
+++ b/pkgs/by-name/un/unix-privesc-check/package.nix
@@ -0,0 +1,87 @@
+{ lib
+, resholve
+, fetchurl
+, gawk
+, bash
+, binutils
+, coreutils
+, file
+, findutils
+, glibc
+, gnugrep
+, gnused
+, nettools
+, openssh
+, postgresql
+, ps
+, util-linux
+, which
+}:
+
+# resholve does not yet support `finalAttrs` call pattern hence `rec`
+# https://github.com/abathur/resholve/issues/107
+resholve.mkDerivation rec {
+ pname = "unix-privesc-check";
+ version = "1.4";
+
+ src = fetchurl {
+ url = "https://pentestmonkey.net/tools/unix-privesc-check/unix-privesc-check-${version}.tar.gz";
+ hash = "sha256-4fhef2n6ut0jdWo9dqDj2GSyHih2O2DOLmGBKQ0cGWk=";
+ };
+
+ patches = [
+ ./unix-privesc-check.patch # https://github.com/NixOS/nixpkgs/pull/287629#issuecomment-1944428796
+ ];
+
+ solutions = {
+ unix-privesc-check = {
+ scripts = [ "bin/unix-privesc-check" ];
+ interpreter = "${bash}/bin/bash";
+ inputs = [
+ gawk
+ bash
+ binutils # for strings command
+ coreutils
+ file
+ findutils # for xargs command
+ glibc # for ldd command
+ gnugrep
+ gnused
+ nettools
+ openssh
+ postgresql # for psql command
+ ps
+ util-linux # for swapon command
+ which
+ ];
+ fake = {
+ external = [
+ "lanscan" # lanscan exists only for HP-UX OS
+ "mount" # Getting same error described in https://github.com/abathur/resholve/issues/29
+ "passwd" # Getting same error described in https://github.com/abathur/resholve/issues/29
+ ];
+ };
+ execer = [
+ "cannot:${glibc.bin}/bin/ldd"
+ "cannot:${postgresql}/bin/psql"
+ "cannot:${openssh}/bin/ssh-add"
+ "cannot:${util-linux.bin}/bin/swapon"
+ ];
+ };
+ };
+
+ installPhase = ''
+ runHook preInstall
+ install -Dm 755 unix-privesc-check $out/bin/unix-privesc-check
+ runHook postInstall
+ '';
+
+ meta = with lib; {
+ description = "Find misconfigurations that could allow local unprivilged users to escalate privileges to other users or to access local apps";
+ mainProgram = "unix-privesc-check";
+ homepage = "https://pentestmonkey.net/tools/audit/unix-privesc-check";
+ maintainers = with maintainers; [ d3vil0p3r ];
+ platforms = platforms.unix;
+ license = licenses.gpl2Plus;
+ };
+}
diff --git a/pkgs/by-name/un/unix-privesc-check/unix-privesc-check.patch b/pkgs/by-name/un/unix-privesc-check/unix-privesc-check.patch
new file mode 100644
index 000000000000..e0d3ab0bff56
--- /dev/null
+++ b/pkgs/by-name/un/unix-privesc-check/unix-privesc-check.patch
@@ -0,0 +1,20 @@
+--- a/unix-privesc-check 2024-02-14 20:21:24.725453661 +0100
++++ b/unix-privesc-check 2024-02-14 20:21:46.577446690 +0100
+@@ -484,17 +484,6 @@
+ # Set path so we can access usual directories. HPUX and some linuxes don't have sbin in the path.
+ PATH=$PATH:/usr/bin:/bin:/sbin:/usr/sbin; export PATH
+
+-# Check dependent programs are installed
+-# Assume "which" is installed!
+-PROGS="ls awk grep cat mount xargs file ldd strings"
+-for PROG in $PROGS; do
+- which $PROG 2>&1 > /dev/null
+- if [ ! $? = "0" ]; then
+- echo "ERROR: Dependend program '$PROG' is mising. Can't run. Sorry!"
+- exit 1
+- fi
+-done
+-
+ banner
+
+ section "Recording hostname"
diff --git a/pkgs/development/compilers/llvm/17/default.nix b/pkgs/development/compilers/llvm/17/default.nix
index 95281df892e5..60cae920945b 100644
--- a/pkgs/development/compilers/llvm/17/default.nix
+++ b/pkgs/development/compilers/llvm/17/default.nix
@@ -144,6 +144,10 @@ in let
inherit llvm_meta;
};
+ mlir = callPackage ../common/mlir {
+ inherit llvm_meta;
+ };
+
lldb = callPackage ../common/lldb.nix {
src = callPackage ({ runCommand }: runCommand "lldb-src-${version}" {} ''
mkdir -p "$out"
diff --git a/pkgs/development/compilers/llvm/common/mlir/default.nix b/pkgs/development/compilers/llvm/common/mlir/default.nix
new file mode 100644
index 000000000000..8e99fa0fe337
--- /dev/null
+++ b/pkgs/development/compilers/llvm/common/mlir/default.nix
@@ -0,0 +1,71 @@
+{ lib, stdenv, llvm_meta
+, buildLlvmTools
+, monorepoSrc, runCommand
+, cmake
+, ninja
+, libxml2
+, libllvm
+, version
+, doCheck ? (!stdenv.isx86_32 /* TODO: why */) && (!stdenv.hostPlatform.isMusl)
+}:
+
+stdenv.mkDerivation rec {
+ pname = "mlir";
+ inherit version doCheck;
+
+ # Blank llvm dir just so relative path works
+ src = runCommand "${pname}-src-${version}" {} ''
+ mkdir -p "$out"
+ cp -r ${monorepoSrc}/cmake "$out"
+ cp -r ${monorepoSrc}/${pname} "$out"
+ cp -r ${monorepoSrc}/third-party "$out/third-party"
+
+ mkdir -p "$out/llvm"
+ '';
+
+ sourceRoot = "${src.name}/${pname}";
+
+ patches = [
+ ./gnu-install-dirs.patch
+ ];
+
+ nativeBuildInputs = [ cmake ninja ];
+ buildInputs = [ libllvm libxml2 ];
+
+ ninjaFlags = [ "-v " ];
+ cmakeFlags = [
+ "-DLLVM_BUILD_TOOLS=ON"
+ # Install headers as well
+ "-DLLVM_INSTALL_TOOLCHAIN_ONLY=OFF"
+ "-DMLIR_TOOLS_INSTALL_DIR=${placeholder "out"}/bin/"
+ "-DLLVM_ENABLE_IDE=OFF"
+ "-DLLD_INSTALL_PACKAGE_DIR=${placeholder "out"}/lib/cmake/mlir"
+ "-DLLVM_BUILD_TESTS=${if doCheck then "ON" else "OFF"}"
+ "-DLLVM_ENABLE_FFI=ON"
+ "-DLLVM_HOST_TRIPLE=${stdenv.hostPlatform.config}"
+ "-DLLVM_DEFAULT_TARGET_TRIPLE=${stdenv.hostPlatform.config}"
+ "-DLLVM_ENABLE_DUMP=ON"
+ ] ++ lib.optionals stdenv.hostPlatform.isStatic [
+ # Disables building of shared libs, -fPIC is still injected by cc-wrapper
+ "-DLLVM_ENABLE_PIC=OFF"
+ "-DLLVM_BUILD_STATIC=ON"
+ "-DLLVM_LINK_LLVM_DYLIB=off"
+ ] ++ lib.optionals ((stdenv.hostPlatform != stdenv.buildPlatform) && !(stdenv.buildPlatform.canExecute stdenv.hostPlatform)) [
+ "-DLLVM_TABLEGEN_EXE=${buildLlvmTools.llvm}/bin/llvm-tblgen"
+ "-DMLIR_TABLEGEN_EXE=${buildLlvmTools.mlir}/bin/mlir-tblgen"
+ ];
+
+ outputs = [ "out" "dev" ];
+
+ meta = llvm_meta // {
+ homepage = "https://mlir.llvm.org/";
+ description = "Multi-Level IR Compiler Framework";
+ longDescription = ''
+ The MLIR project is a novel approach to building reusable and extensible
+ compiler infrastructure. MLIR aims to address software fragmentation,
+ improve compilation for heterogeneous hardware, significantly reduce
+ the cost of building domain specific compilers, and aid in connecting
+ existing compilers together.
+ '';
+ };
+}
diff --git a/pkgs/development/compilers/llvm/common/mlir/gnu-install-dirs.patch b/pkgs/development/compilers/llvm/common/mlir/gnu-install-dirs.patch
new file mode 100644
index 000000000000..95191022d1a3
--- /dev/null
+++ b/pkgs/development/compilers/llvm/common/mlir/gnu-install-dirs.patch
@@ -0,0 +1,15 @@
+diff --git a/CMakeLists.txt b/CMakeLists.txt
+index c91e9cd93dc8..23b6032a46b7 100644
+--- a/CMakeLists.txt
++++ b/CMakeLists.txt
+@@ -32,8 +32,8 @@ if(MLIR_STANDALONE_BUILD)
+ endif()
+
+ set(CMAKE_LIBRARY_OUTPUT_DIRECTORY
+- "${CMAKE_CURRENT_BINARY_DIR}/lib${LLVM_LIBDIR_SUFFIX}")
+- set(CMAKE_RUNTIME_OUTPUT_DIRECTORY "${CMAKE_CURRENT_BINARY_DIR}/bin")
++ "${CMAKE_INSTALL_LIBDIR}/${LLVM_LIBDIR_SUFFIX}")
++ set(CMAKE_RUNTIME_OUTPUT_DIRECTORY "${CMAKE_INSTALL_BINDIR}")
+
+ set(LLVM_LIT_ARGS "-sv" CACHE STRING "Default options for lit")
+ endif()
diff --git a/pkgs/development/compilers/llvm/git/default.nix b/pkgs/development/compilers/llvm/git/default.nix
index 41ce6076da5f..5cc84d26b728 100644
--- a/pkgs/development/compilers/llvm/git/default.nix
+++ b/pkgs/development/compilers/llvm/git/default.nix
@@ -149,6 +149,10 @@ in let
inherit llvm_meta;
};
+ mlir = callPackage ../common/mlir {
+ inherit llvm_meta;
+ };
+
lldb = callPackage ../common/lldb.nix {
src = callPackage ({ runCommand }: runCommand "lldb-src-${version}" {} ''
mkdir -p "$out"
diff --git a/pkgs/development/compilers/unison/default.nix b/pkgs/development/compilers/unison/default.nix
index 56ca3a0104cf..f9f1934bb566 100644
--- a/pkgs/development/compilers/unison/default.nix
+++ b/pkgs/development/compilers/unison/default.nix
@@ -11,17 +11,17 @@
stdenv.mkDerivation (finalAttrs: {
pname = "unison-code-manager";
- version = "0.5.15";
+ version = "0.5.17";
src = if stdenv.isDarwin then
fetchurl {
url = "https://github.com/unisonweb/unison/releases/download/release/${finalAttrs.version}/ucm-macos.tar.gz";
- hash = "sha256-Umpu9WQhg6ln6aBb6bPVUZSax1Zeh6vcYHwmQuFRx2Y=";
+ hash = "sha256-ymnioW+phbwIshs8DZupfe14oPUuunxSsT8rmifh914=";
}
else
fetchurl {
url = "https://github.com/unisonweb/unison/releases/download/release/${finalAttrs.version}/ucm-linux.tar.gz";
- hash = "sha256-cFucBQcyye4F6Vep6O9buENFzqJ96q8/2cVr9NFvHB8=";
+ hash = "sha256-vaK7dKkjCPCfEb9GvkOiJ3jY/Jxb31sf98de3WTMG/A=";
};
# The tarball is just the prebuilt binary, in the archive root.
diff --git a/pkgs/development/java-modules/postgresql_jdbc/default.nix b/pkgs/development/java-modules/postgresql_jdbc/default.nix
index 3dc82f9c0761..f1e93e352eb8 100644
--- a/pkgs/development/java-modules/postgresql_jdbc/default.nix
+++ b/pkgs/development/java-modules/postgresql_jdbc/default.nix
@@ -2,12 +2,12 @@
stdenv.mkDerivation rec {
pname = "postgresql-jdbc";
- version = "42.6.0";
+ version = "42.6.1";
src = fetchMavenArtifact {
artifactId = "postgresql";
groupId = "org.postgresql";
- hash = "sha256-uBfGekDJQkn9WdTmhuMyftDT0/rkJrINoPHnVlLPxGE=";
+ hash = "sha256-ywd0/X0JsjniHp0Es3RKQId7/0Y6jVjD9AfPfZdsNVc=";
inherit version;
};
diff --git a/pkgs/development/libraries/java/commons/compress/default.nix b/pkgs/development/libraries/java/commons/compress/default.nix
index 53265baaf8fe..7827c1788dca 100644
--- a/pkgs/development/libraries/java/commons/compress/default.nix
+++ b/pkgs/development/libraries/java/commons/compress/default.nix
@@ -1,12 +1,12 @@
{ lib, stdenv, fetchurl }:
stdenv.mkDerivation rec {
- version = "1.25.0";
+ version = "1.26.0";
pname = "commons-compress";
src = fetchurl {
url = "mirror://apache/commons/compress/binaries/${pname}-${version}-bin.tar.gz";
- sha256 = "sha256-isxV/gTOjVQW3716cr8ZrlLnOn8YWWr6p1SHYlwhdvA=";
+ sha256 = "sha256-AXdkqMrzTtURpPXKOmXxo0RnfFtflcDf6mmVmqVFz5k=";
};
installPhase = ''
diff --git a/pkgs/development/tools/rust/cargo-semver-checks/default.nix b/pkgs/development/tools/rust/cargo-semver-checks/default.nix
index 39b933e85f5f..77e46ececc5a 100644
--- a/pkgs/development/tools/rust/cargo-semver-checks/default.nix
+++ b/pkgs/development/tools/rust/cargo-semver-checks/default.nix
@@ -10,16 +10,16 @@
rustPlatform.buildRustPackage rec {
pname = "cargo-semver-checks";
- version = "0.29.0";
+ version = "0.29.1";
src = fetchFromGitHub {
owner = "obi1kenobi";
repo = pname;
rev = "v${version}";
- hash = "sha256-RclZ52E8xslHO5M+jwwC3BVe8QFam9/j7rlh/FoNgN8=";
+ hash = "sha256-Eq8NLfgFoO/Upq+eO8kKDMtxgEMQYTG9B6TdCZjGdzc=";
};
- cargoHash = "sha256-On6MU76Ehk2b+9hzUXN/PHr5BQTNcGIgQZUkPFBIl2Y=";
+ cargoHash = "sha256-AMI997Tz1l7qUmdGPVOtb2KENX27ZfM0P7snzP3aRXU=";
nativeBuildInputs = [
cmake
diff --git a/pkgs/servers/mastodon/gemset.nix b/pkgs/servers/mastodon/gemset.nix
index e888bfe750bb..bc556d4f3673 100644
--- a/pkgs/servers/mastodon/gemset.nix
+++ b/pkgs/servers/mastodon/gemset.nix
@@ -5,10 +5,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "117vxic67jnw6q637kmsb3ryj0x485295pz9a9y4z8xn9bdlsl0z";
+ sha256 = "0j86qjs1zw34p0p7d5napa1vvwqlvm9nmv7ckxxhcba1qv4dspmw";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
actionmailbox = {
dependencies = ["actionpack" "activejob" "activerecord" "activestorage" "activesupport" "mail" "net-imap" "net-pop" "net-smtp"];
@@ -16,10 +16,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1r8ldj2giaz8cn49qkdqn5zc29gbsr5ky4fg6r7ali0yh1xh684l";
+ sha256 = "1f68h8cl6dqbz7mq3x43s0s82291nani3bz1hrxkk2qpgda23mw9";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
actionmailer = {
dependencies = ["actionpack" "actionview" "activejob" "activesupport" "mail" "net-imap" "net-pop" "net-smtp" "rails-dom-testing"];
@@ -27,10 +27,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0w6gvj7ybniq89834hqww9rj2xypz9l91f8niwaws2yq1qklymr2";
+ sha256 = "077j47jsg0wqwx5b13n4h0g3g409b6kfrlazpzgjpa3pal74f7sc";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
actionpack = {
dependencies = ["actionview" "activesupport" "rack" "rack-test" "rails-dom-testing" "rails-html-sanitizer"];
@@ -38,10 +38,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1l319p0gipfgq8bp8dvbv97qqb72rad9zcqn5snhgv20cmpqr69b";
+ sha256 = "0jh83rqd6glys1b2wsihzsln8yk6zdwgiyn9xncyiav9rcwjpkax";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
actiontext = {
dependencies = ["actionpack" "activerecord" "activestorage" "activesupport" "globalid" "nokogiri"];
@@ -49,10 +49,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0i47r3n2m8qm002gx7c0lx1pv15pr2zy57dm8j38x960rsb655pp";
+ sha256 = "044qi3zhzxlfq7slc2pb9ky9mdivp1m1sjyhjvnsi64ggq7cvr22";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
actionview = {
dependencies = ["activesupport" "builder" "erubi" "rails-dom-testing" "rails-html-sanitizer"];
@@ -60,10 +60,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0xnpdwj1d8m6c2d90jp9cs50ggiz0jj02ls2h9lg68k4k8mnjbd2";
+ sha256 = "1ygpg75f3ffdcbxvf7s14xw3hcjin1nnx1nk3mg9mj2xc1nb60aa";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
active_model_serializers = {
dependencies = ["actionpack" "activemodel" "case_transform" "jsonapi-renderer"];
@@ -82,10 +82,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1cn1ic7ml75jm0c10s7cm5mvcgfnafj0kjvvjavpjcxgz6lxcqyb";
+ sha256 = "0yql9v4cd1xbqgnzlf3cv4a6sm26v2y4gsgcbbfgvfc0hhlfjklg";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
activemodel = {
dependencies = ["activesupport"];
@@ -93,10 +93,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "004w8zaz2g3y6lnrsvlcmljll0m3ndqpgwf0wfscgq6iysibiglm";
+ sha256 = "0grdpvglh0cj96qhlxjj9bcfqkh13c1pfpcwc9ld3aw0yzvsw5a1";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
activerecord = {
dependencies = ["activemodel" "activesupport"];
@@ -104,10 +104,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "04wavps80q3pvhvfbmi4gs102y1p6mxbg8xylzvib35b6m92adpj";
+ sha256 = "0rlky1cr5kcdl0jad3nk5jpim6vjzbgkfhxnk7y492b3j2nznpcf";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
activestorage = {
dependencies = ["actionpack" "activejob" "activerecord" "activesupport" "marcel" "mini_mime"];
@@ -115,10 +115,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0d6vm6alsp0g6f3548b615zxbz8l2wrmaikwgsf8kv11wf6swb4c";
+ sha256 = "0f4g3589i5ii4gdfazv6d9rjinr16aarh6g12v8378ck7jll3mhz";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
activesupport = {
dependencies = ["concurrent-ruby" "i18n" "minitest" "tzinfo"];
@@ -126,10 +126,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "188kbwkn1lbhz40ala8ykp20jzqphgc68g3d8flin8cqa2xid0s5";
+ sha256 = "0ff3x7q400flzhml131ix8zfwmh13h70rs6yzbzf513g781gbbxh";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
addressable = {
dependencies = ["public_suffix"];
@@ -694,10 +694,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "03skfikihpx37rc27vr3hwrb057gxnmdzxhmzd4bf4jpkl0r55w1";
+ sha256 = "149jknsq999gnhy865n33fkk22s0r447k76x9pmcnnwldfv2q7wp";
type = "gem";
};
- version = "3.3.3";
+ version = "3.3.4";
};
debug_inspector = {
groups = ["default" "development"];
@@ -1609,10 +1609,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1p744kjpb5zk2ihklbykzii77alycjc04vpnm2ch2f3cp65imlj3";
+ sha256 = "0d5p9vg2qkqfy60i93mpd3b25kw4bdxfai034y5a94pxp5fws61c";
type = "gem";
};
- version = "2.21.3";
+ version = "2.21.4";
};
mail = {
dependencies = ["mini_mime" "net-imap" "net-pop" "net-smtp"];
@@ -1828,10 +1828,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0dxckrlw4q1lcn3qg4mimmjazmg9bma5gllv72f8js3p36fb3b91";
+ sha256 = "1a32l4x73hz200cm587bc29q8q9az278syw3x6fkc9d1lv5y0wxa";
type = "gem";
};
- version = "0.2.1";
+ version = "0.2.2";
};
net-scp = {
dependencies = ["net-ssh"];
@@ -1850,10 +1850,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1c6md06hm5bf6rv53sk54dl2vg038pg8kglwv3rayx0vk2mdql9x";
+ sha256 = "0hwiqplhi29kfjl8jm0rhl51qv6wmxfynl4qap1dhv9xdwc4bm1x";
type = "gem";
};
- version = "0.3.3";
+ version = "0.3.4";
};
net-ssh = {
groups = ["default" "development"];
@@ -2178,10 +2178,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "15rdwbyk71c9nxvd527bvb8jxkcys8r3dj3vqra5b3sa63qs30vv";
+ sha256 = "10mpk0hl6hnv324fp1pfimi2nw9acj0z4gyhrph36qg84pk1s4m7";
type = "gem";
};
- version = "2.2.8";
+ version = "2.2.8.1";
};
rack-attack = {
dependencies = ["rack"];
@@ -2255,10 +2255,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0rsqin156dawz7gzpy1ijs02afqcr4704vqj56s6yxng3a9ayhwf";
+ sha256 = "1v9dp9sgh8kk32r23mj66zjni7w1dv2h7mbaxgmazsf59a43gsvx";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
rails-controller-testing = {
dependencies = ["actionpack" "actionview" "activesupport"];
@@ -2323,10 +2323,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0sfc16zrcn4jgf5xczb08n6prhmqqgg9f0b4mn73zlzg6cwmqchj";
+ sha256 = "08ga56kz6a37dnlmi7y45r19fcc7jzb62mrc3ifavbzggmhy7r62";
type = "gem";
};
- version = "7.0.8";
+ version = "7.0.8.1";
};
rainbow = {
groups = ["default" "development"];
@@ -3043,10 +3043,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1d9cvm0f4zdpwa795v3zv4973y5zk59j7s1x3yn90jjrhcz1yvfd";
+ sha256 = "16mvvsmx90023wrhf8dxc1lpqh0m8alk65shb7xcya6a9gflw7vg";
type = "gem";
};
- version = "0.4.0";
+ version = "0.4.1";
};
tpm-key_attestation = {
dependencies = ["bindata" "openssl" "openssl-signature_algorithm"];
@@ -3342,10 +3342,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1mwdd445w63khz13hpv17m2br5xngyjl3jdj08xizjbm78i2zrxd";
+ sha256 = "1m67qmsak3x8ixs8rb971azl3l7wapri65pmbf5z886h46q63f1d";
type = "gem";
};
- version = "2.6.11";
+ version = "2.6.13";
};
}
diff --git a/pkgs/servers/mastodon/source.nix b/pkgs/servers/mastodon/source.nix
index 4036b5b48135..13165c3405fb 100644
--- a/pkgs/servers/mastodon/source.nix
+++ b/pkgs/servers/mastodon/source.nix
@@ -1,7 +1,7 @@
# This file was generated by pkgs.mastodon.updateScript.
{ fetchFromGitHub, applyPatches, patches ? [] }:
let
- version = "4.2.7";
+ version = "4.2.8";
in
(
applyPatches {
@@ -9,7 +9,7 @@ in
owner = "mastodon";
repo = "mastodon";
rev = "v${version}";
- hash = "sha256-lz1HMg/B6BOqGxypzDTTO5yY7C5B6QRNIpRnDZW2eGs=";
+ hash = "sha256-7/E7iHqJxmYSorXYti7h8EbP7wcOAaD04ToLeU2I/nY=";
};
patches = patches ++ [];
}) // {
diff --git a/pkgs/servers/monitoring/plugins/default.nix b/pkgs/servers/monitoring/plugins/default.nix
index ba8a742bcb89..ae0db59d0b32 100644
--- a/pkgs/servers/monitoring/plugins/default.nix
+++ b/pkgs/servers/monitoring/plugins/default.nix
@@ -34,7 +34,6 @@ let
lm_sensors
net-snmp
procps
- unixtools.ping
];
mailq = runCommand "mailq-wrapper" { preferLocalBuild = true; } ''
@@ -84,8 +83,8 @@ stdenv.mkDerivation rec {
-e 's|^DEFAULT_PATH=.*|DEFAULT_PATH=\"${binPath}\"|'
configureFlagsArray+=(
- --with-ping-command='ping -4 -n -U -w %d -c %d %s'
- --with-ping6-command='ping -6 -n -U -w %d -c %d %s'
+ --with-ping-command='${lib.getBin unixtools.ping}/bin/ping -4 -n -U -w %d -c %d %s'
+ --with-ping6-command='${lib.getBin unixtools.ping}/bin/ping -6 -n -U -w %d -c %d %s'
)
'';
diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix
index 434e035561f2..9581150e75e8 100644
--- a/pkgs/top-level/all-packages.nix
+++ b/pkgs/top-level/all-packages.nix
@@ -16643,6 +16643,8 @@ with pkgs;
llvm_16 = llvmPackages_16.llvm;
llvm_17 = llvmPackages_17.llvm;
+ mlir_17 = llvmPackages_17.mlir;
+
libllvm = llvmPackages.libllvm;
llvm-manpages = llvmPackages.llvm-manpages;