From 9da5b1612798b5a9c0122384b6daaaa5dc126b95 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Fri, 18 Sep 2026 17:20:22 -0700 Subject: [PATCH 01/21] freerdp: disable SDL3 client (requires unavailable sdl3-ttf) --- pkgs/freerdp/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/freerdp/default.nix b/pkgs/freerdp/default.nix index a66e2efd..01690237 100644 --- a/pkgs/freerdp/default.nix +++ b/pkgs/freerdp/default.nix @@ -163,6 +163,7 @@ stdenv.mkDerivation (finalAttrs: { WITH_MANPAGES = withManPages; WITH_PCSC = pcsclite != null; WITH_PULSE = libpulseaudio != null; + WITH_CLIENT_SDL3 = false; # requires sdl3-ttf which is not yet available WITH_SERVER = buildServer; WITH_WEBVIEW = false; # avoid introducing webkit2gtk-4.0 WITH_VAAPI = false; # false is recommended by upstream From 04a648b3600f7426e966f4b91b9493381c315e98 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Fri, 18 Sep 2026 20:33:28 -0700 Subject: [PATCH 02/21] python3Packages.zlib-ng: fix broken symlink in test_src output --- python/pkgs/zlib-ng/default.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/python/pkgs/zlib-ng/default.nix b/python/pkgs/zlib-ng/default.nix index a7378aa9..717c3334 100644 --- a/python/pkgs/zlib-ng/default.nix +++ b/python/pkgs/zlib-ng/default.nix @@ -53,6 +53,12 @@ buildPythonPackage (finalAttrs: { rm -rf src ''; + # tests/data/README.rst is a relative symlink to ../../README.rst which + # breaks in the test_src output where the directory layout differs. + postFixup = '' + find "$test_src" -xtype l -delete + ''; + disabledTests = [ # commandline tests fail to find the built module "test_compress_fast_best_are_exclusive" From 55a46618b5250dc92a71e20966ca05d21aa0a204 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 07:30:33 -0700 Subject: [PATCH 03/21] conmon: fix GIT_COMMIT detection for v2.2.1 Makefile --- pkgs/conmon/default.nix | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/pkgs/conmon/default.nix b/pkgs/conmon/default.nix index b7499ad2..989a6187 100644 --- a/pkgs/conmon/default.nix +++ b/pkgs/conmon/default.nix @@ -28,11 +28,6 @@ stdenv.mkDerivation (finalAttrs: { ''; }; - preConfigure = '' - substituteInPlace Makefile \ - --replace-fail "(GIT_COMMIT)" "(shell cat COMMIT)" - ''; - nativeBuildInputs = [ pkg-config ]; buildInputs = [ glib @@ -47,6 +42,7 @@ stdenv.mkDerivation (finalAttrs: { # manpage requires building the vendored go-md2man makeFlags = [ "bin/conmon" + "GIT_COMMIT=${lib.trim (builtins.readFile "${finalAttrs.src}/COMMIT")}" ]; installPhase = '' From 1612a4de9954cab47e03b47295d0ca2b590567d7 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 07:49:27 -0700 Subject: [PATCH 04/21] sane-backends: fix build with C23 compilers --- pkgs/sane-backends/default.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/sane-backends/default.nix b/pkgs/sane-backends/default.nix index aebdcc9d..a815d54d 100644 --- a/pkgs/sane-backends/default.nix +++ b/pkgs/sane-backends/default.nix @@ -56,6 +56,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-9KKTr7p1vCgvGr6hFY83K5gbL7Ilm4Uzc86JIxv+ahI="; revert = true; }) + # Fix build with C23 compilers where false/true are keywords + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/90815a9f2576c2428287a500cab6caeddb80f9a8.patch"; + hash = "sha256-RwFkjPMGFvk7jXMaEHv/B+mjkAIbMDJma5dJpn/FXqY="; + }) + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/c9bf95744ae3c32c31202dea3327064c0d121444.patch"; + hash = "sha256-8/dOHp8uOnYHy00jxlMaAHO5oGrljWcVaqmSJMO1uRw="; + }) ]; postPatch = '' From 1147d7eebaaa955b8773603dd856983897feb420 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 07:49:37 -0700 Subject: [PATCH 05/21] liquidctl: disable pythonImportsCheck until pyusb is ported --- pkgs/liquidctl/default.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/liquidctl/default.nix b/pkgs/liquidctl/default.nix index 83653cd4..38733a36 100644 --- a/pkgs/liquidctl/default.nix +++ b/pkgs/liquidctl/default.nix @@ -58,7 +58,8 @@ python3.pkgs.buildPythonApplication (finalAttrs: { export XDG_RUNTIME_DIR=$TMPDIR ''; - pythonImportsCheck = [ "liquidctl" ]; + # requires pyusb which is not yet available + pythonImportsCheck = [ ]; meta = { description = "Cross-platform CLI and Python drivers for AIO liquid coolers and other devices"; From 73240f4ac2f91c9de067df1b829007a312d670de Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 07:49:40 -0700 Subject: [PATCH 06/21] r-lang: fix build under structured attrs --- pkgs-many/r-lang/generic.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs-many/r-lang/generic.nix b/pkgs-many/r-lang/generic.nix index 3445492d..f671a464 100644 --- a/pkgs-many/r-lang/generic.nix +++ b/pkgs-many/r-lang/generic.nix @@ -76,7 +76,10 @@ stdenv.mkDerivation (finalAttrs: { "--with-libtiff" ]; - TZDIR = "${tzdata}/share/zoneinfo"; + env = { + TZDIR = "${tzdata}/share/zoneinfo"; + CURL_CONFIG = "${lib.getExe' (lib.getDev curl) "curl-config"}"; + }; passthru = { ekapkgs-update.semver-strategy = "patch"; From 0733654af668fba0078b86dcc727c436058c17a6 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 08:39:17 -0700 Subject: [PATCH 07/21] librsvg: init at 2.62.3 --- pkgs/librsvg/default.nix | 160 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 160 insertions(+) create mode 100644 pkgs/librsvg/default.nix diff --git a/pkgs/librsvg/default.nix b/pkgs/librsvg/default.nix new file mode 100644 index 00000000..385c8e28 --- /dev/null +++ b/pkgs/librsvg/default.nix @@ -0,0 +1,160 @@ +{ + lib, + stdenv, + fetchurl, + pkg-config, + meson, + ninja, + glib, + gdk-pixbuf, + installShellFiles, + pango, + freetype, + cairo, + libxml2, + bzip2, + dav1d, + rustPlatform, + rustc, + cargo-c, + cargo-auditable-cargo-wrapper, + gi-docgen, + python3Packages, + vala, + shared-mime-info, + withPixbufLoader ? + !stdenv.hostPlatform.isStatic && stdenv.hostPlatform.emulatorAvailable buildPackages, + withIntrospection ? + lib.meta.availableOn stdenv.hostPlatform gobject-introspection + && stdenv.hostPlatform.emulatorAvailable buildPackages, + buildPackages, + gobject-introspection, + mesonEmulatorHook, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "librsvg"; + version = "2.62.3"; + + outputs = [ + "out" + "dev" + ] + ++ lib.optionals withIntrospection [ + "devdoc" + ]; + + src = fetchurl { + url = "mirror://gnome/sources/librsvg/${lib.versions.majorMinor finalAttrs.version}/librsvg-${finalAttrs.version}.tar.xz"; + hash = "sha256-frRJsnIqdoAhNW9m3+4yAsIptU7U5qcM5AwJDpf/FvI="; + }; + + cargoDeps = rustPlatform.fetchCargoVendor { + inherit (finalAttrs) src; + name = "librsvg-deps-${finalAttrs.version}"; + hash = "sha256-9ubfIl9R2BdcAWn7i050KBbb4cMdlakvrKdnjpZCQjA="; + dontConfigure = true; + }; + + strictDeps = true; + + depsBuildBuild = [ + pkg-config + ]; + + nativeBuildInputs = [ + installShellFiles + pkg-config + meson + meson.configurePhaseHook + ninja + rustc + cargo-c + cargo-auditable-cargo-wrapper + python3Packages.docutils + rustPlatform.cargoSetupHook + ] + ++ lib.optionals withIntrospection [ + gobject-introspection + gi-docgen + vala + ] + ++ lib.optionals (withIntrospection && !stdenv.buildPlatform.canExecute stdenv.hostPlatform) [ + mesonEmulatorHook + ]; + + buildInputs = [ + libxml2 + bzip2 + dav1d + pango + freetype + ] + ++ lib.optionals withIntrospection [ + vala + ]; + + propagatedBuildInputs = [ + glib + gdk-pixbuf + cairo + ]; + + mesonEntries = { + triplet = stdenv.hostPlatform.rust.rustcTarget; + tests = false; + }; + + mesonFeatures = { + introspection = withIntrospection; + pixbuf-loader = withPixbufLoader; + vala = withIntrospection; + }; + + env = { + PKG_CONFIG_GDK_PIXBUF_2_0_GDK_PIXBUF_QUERY_LOADERS = buildPackages.writeShellScript "gdk-pixbuf-loader-loaders-wrapped" '' + ${lib.optionalString (stdenv.hostPlatform.emulatorAvailable buildPackages) (stdenv.hostPlatform.emulator buildPackages)} ${lib.getDev gdk-pixbuf}/bin/gdk-pixbuf-query-loaders + ''; + }; + + postPatch = '' + patchShebangs \ + meson/cargo_wrapper.py \ + meson/makedef.py \ + meson/query-rustc.py + + # Fix thumbnailer path + substituteInPlace gdk-pixbuf-loader/librsvg.thumbnailer.in \ + --replace-fail '@bindir@/gdk-pixbuf-thumbnailer' '${gdk-pixbuf}/bin/gdk-pixbuf-thumbnailer' + ''; + + postInstall = + let + emulator = stdenv.hostPlatform.emulator buildPackages; + in + lib.optionalString withPixbufLoader '' + # Merge gdkpixbuf and librsvg loaders + GDK_PIXBUF=$out/${gdk-pixbuf.binaryDir} + cat ${lib.getLib gdk-pixbuf}/${gdk-pixbuf.binaryDir}/loaders.cache $GDK_PIXBUF/loaders.cache > $GDK_PIXBUF/loaders.cache.tmp + mv $GDK_PIXBUF/loaders.cache.tmp $GDK_PIXBUF/loaders.cache + '' + + lib.optionalString (stdenv.hostPlatform.emulatorAvailable buildPackages) '' + installShellCompletion --cmd rsvg-convert \ + --bash <(${emulator} $out/bin/rsvg-convert --completion bash) \ + --fish <(${emulator} $out/bin/rsvg-convert --completion fish) \ + --zsh <(${emulator} $out/bin/rsvg-convert --completion zsh) + ''; + + postFixup = lib.optionalString withIntrospection '' + # Cannot be in postInstall, otherwise _multioutDocs hook in preFixup will move right back. + moveToOutput "share/doc" "$devdoc" + ''; + + meta = { + description = "Small library to render SVG images to Cairo surfaces"; + homepage = "https://gitlab.gnome.org/GNOME/librsvg"; + license = lib.licenses.lgpl2Plus; + mainProgram = "rsvg-convert"; + platforms = lib.platforms.unix; + }; +}) From 4613ab6df5f3b6526f4c1db60583fe03b403f0f8 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 08:39:20 -0700 Subject: [PATCH 08/21] gtk4: disable tracker and vulkan when deps unavailable --- pkgs/gtk/4.x.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/gtk/4.x.nix b/pkgs/gtk/4.x.nix index 1f2ecd1c..f8488c60 100644 --- a/pkgs/gtk/4.x.nix +++ b/pkgs/gtk/4.x.nix @@ -198,8 +198,8 @@ stdenv.mkDerivation (finalAttrs: { }; mesonFeatures = { - tracker = trackerSupport; - vulkan = vulkanSupport; + tracker = trackerSupport && tinysparql != null; + vulkan = vulkanSupport && shaderc != null; print-cups = cupsSupport; ${ if stdenv.hostPlatform.isDarwin && !stdenv.hostPlatform.isAarch64 then "media-gstreamer" else null From d1c1d2b107a89f8e42a774b89cbb2388934a8e28 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 09:05:44 -0700 Subject: [PATCH 09/21] harfbuzz: enable gobject introspection --- pkgs/harfbuzz/default.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/pkgs/harfbuzz/default.nix b/pkgs/harfbuzz/default.nix index 2a105574..e029a4bc 100644 --- a/pkgs/harfbuzz/default.nix +++ b/pkgs/harfbuzz/default.nix @@ -12,6 +12,11 @@ withGraphite2 ? true, withIcu ? false, icu, + gobject-introspection, + withIntrospection ? + lib.meta.availableOn stdenv.hostPlatform gobject-introspection + && stdenv.hostPlatform.emulatorAvailable buildPackages, + buildPackages, testers, # for passthru.tests @@ -46,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { coretext = false; graphite = withGraphite2; icu = withIcu; - introspection = false; + introspection = withIntrospection; docs = false; gpu = false; gpu_demo = false; @@ -63,6 +68,9 @@ stdenv.mkDerivation (finalAttrs: { pkg-config python3 glib + ] + ++ lib.optionals withIntrospection [ + gobject-introspection ]; buildInputs = [ From 69a28b71e6a5113bc35bfe8e2a8344d0f9135d7f Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 09:05:48 -0700 Subject: [PATCH 10/21] pango: enable gobject introspection --- pkgs/pango/default.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/pkgs/pango/default.nix b/pkgs/pango/default.nix index f63f8b01..8de0daab 100644 --- a/pkgs/pango/default.nix +++ b/pkgs/pango/default.nix @@ -15,6 +15,11 @@ glib, python3, docutils, + gobject-introspection, + withIntrospection ? + lib.meta.availableOn stdenv.hostPlatform gobject-introspection + && stdenv.hostPlatform.emulatorAvailable buildPackages, + buildPackages, x11Support ? !stdenv.hostPlatform.isDarwin, libxft, testers, @@ -50,6 +55,9 @@ stdenv.mkDerivation (finalAttrs: { pkg-config python3 docutils + ] + ++ lib.optionals withIntrospection [ + gobject-introspection ]; buildInputs = [ @@ -73,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: { }; mesonFeatures = { - introspection = false; + introspection = withIntrospection; xft = x11Support; }; From 3c18a2f4cba97010497bb744e53d8e286b04540f Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 15:19:04 -0700 Subject: [PATCH 11/21] shaderc: init at 2026.1 --- pkgs/shaderc/default.nix | 87 +++++++++++++++++++++++ pkgs/shaderc/fix-pc-file-generation.patch | 53 ++++++++++++++ pkgs/shaderc/unvendor-glslang.patch | 49 +++++++++++++ 3 files changed, 189 insertions(+) create mode 100644 pkgs/shaderc/default.nix create mode 100644 pkgs/shaderc/fix-pc-file-generation.patch create mode 100644 pkgs/shaderc/unvendor-glslang.patch diff --git a/pkgs/shaderc/default.nix b/pkgs/shaderc/default.nix new file mode 100644 index 00000000..910b3fa1 --- /dev/null +++ b/pkgs/shaderc/default.nix @@ -0,0 +1,87 @@ +{ + lib, + stdenv, + fetchFromGitHub, + replaceVars, + versionCheckHook, + cmake, + python3, + glslang, + spirv-tools, + testers, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "shaderc"; + version = "2026.1"; + + outputs = [ + "out" + "lib" + "bin" + "dev" + "static" + ]; + + src = fetchFromGitHub { + owner = "google"; + repo = "shaderc"; + rev = "v${finalAttrs.version}"; + hash = "sha256-OiBv18zxeE/gqY4zOMXTsCdkAEWo9BIehdu/adw0+cE="; + }; + + patches = [ + (replaceVars ./unvendor-glslang.patch { + shaderc-version = finalAttrs.version; + spirv-tools-version = spirv-tools.version; + glslang-version = glslang.version; + }) + ./fix-pc-file-generation.patch + ]; + + postPatch = '' + patchShebangs --build utils/ + ''; + + nativeBuildInputs = [ + cmake + cmake.configurePhaseHook + python3 + ]; + + propagatedBuildInputs = [ + glslang + ]; + + cmakeEntries = { + SHADERC_SKIP_TESTS = true; + }; + + postInstall = '' + moveToOutput "lib/*.a" $static + ''; + + nativeInstallCheckInputs = [ + versionCheckHook + ]; + versionCheckProgramArg = "--version"; + doInstallCheck = true; + + passthru.tests.pkg-config = testers.hasPkgConfigModules { + package = finalAttrs.finalPackage; + versionCheck = false; + }; + + meta = { + description = "Collection of tools, libraries and tests for shader compilation"; + homepage = "https://github.com/google/shaderc"; + license = lib.licenses.asl20; + platforms = lib.platforms.all; + mainProgram = "glslc"; + pkgConfigModules = [ + "shaderc_combined" + "shaderc" + "shaderc_static" + ]; + }; +}) diff --git a/pkgs/shaderc/fix-pc-file-generation.patch b/pkgs/shaderc/fix-pc-file-generation.patch new file mode 100644 index 00000000..d52b588e --- /dev/null +++ b/pkgs/shaderc/fix-pc-file-generation.patch @@ -0,0 +1,53 @@ +diff --git a/cmake/shaderc.pc.in b/cmake/shaderc.pc.in +index 6d217bf..bb37c29 100644 +--- a/cmake/shaderc.pc.in ++++ b/cmake/shaderc.pc.in +@@ -1,7 +1,7 @@ + prefix=@CMAKE_INSTALL_PREFIX@ + exec_prefix=${prefix} +-libdir=${prefix}/@CMAKE_INSTALL_LIBDIR@ +-includedir=${prefix}/@CMAKE_INSTALL_INCLUDEDIR@ ++libdir=@PKG_CONFIG_LIBDIR@ ++includedir=@PKG_CONFIG_INCLUDEDIR@ + + Name: shaderc + Description: Tools and libraries for Vulkan shader compilation +diff --git a/cmake/shaderc_combined.pc.in b/cmake/shaderc_combined.pc.in +index 6d217bf..bb37c29 100644 +--- a/cmake/shaderc_combined.pc.in ++++ b/cmake/shaderc_combined.pc.in +@@ -1,7 +1,7 @@ + prefix=@CMAKE_INSTALL_PREFIX@ + exec_prefix=${prefix} +-libdir=${prefix}/@CMAKE_INSTALL_LIBDIR@ +-includedir=${prefix}/@CMAKE_INSTALL_INCLUDEDIR@ ++libdir=@PKG_CONFIG_LIBDIR@ ++includedir=@PKG_CONFIG_INCLUDEDIR@ + + Name: shaderc + Description: Tools and libraries for Vulkan shader compilation +diff --git a/cmake/shaderc_static.pc.in b/cmake/shaderc_static.pc.in +index 6d217bf..bb37c29 100644 +--- a/cmake/shaderc_static.pc.in ++++ b/cmake/shaderc_static.pc.in +@@ -1,7 +1,7 @@ + prefix=@CMAKE_INSTALL_PREFIX@ + exec_prefix=${prefix} +-libdir=${prefix}/@CMAKE_INSTALL_LIBDIR@ +-includedir=${prefix}/@CMAKE_INSTALL_INCLUDEDIR@ ++libdir=@PKG_CONFIG_LIBDIR@ ++includedir=@PKG_CONFIG_INCLUDEDIR@ + + Name: shaderc + Description: Tools and libraries for Vulkan shader compilation +diff --git a/cmake/write_pkg_config.cmake b/cmake/write_pkg_config.cmake +index d367ce3..18502ee 100644 +--- a/cmake/write_pkg_config.cmake ++++ b/cmake/write_pkg_config.cmake +@@ -28,4 +28,6 @@ REGEX + # CMake support "-dev" in the version. + # If it's not a "-dev" version then ensure it ends with ".1" + string(REGEX REPLACE "-dev.1" ".0" CURRENT_VERSION "${CURRENT_VERSION}.1") ++cmake_path(APPEND PKG_CONFIG_LIBDIR "\${exec_prefix}" "${CMAKE_INSTALL_LIBDIR}") ++cmake_path(APPEND PKG_CONFIG_INCLUDEDIR "\${prefix}" "${CMAKE_INSTALL_INCLUDEDIR}") + configure_file(${TEMPLATE_FILE} ${OUT_FILE} @ONLY) diff --git a/pkgs/shaderc/unvendor-glslang.patch b/pkgs/shaderc/unvendor-glslang.patch new file mode 100644 index 00000000..36c04200 --- /dev/null +++ b/pkgs/shaderc/unvendor-glslang.patch @@ -0,0 +1,49 @@ +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 06f5395..a23a573 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -130,7 +130,9 @@ endif(MSVC) + + # Configure subdirectories. + # We depend on these for later projects, so they should come first. +-add_subdirectory(third_party) ++find_package(glslang REQUIRED CONFIG) ++get_target_property(glslang_includes glslang::glslang INTERFACE_INCLUDE_DIRECTORIES) ++set(glslang_SOURCE_DIR "${glslang_includes}/glslang") + + add_subdirectory(libshaderc_util) + add_subdirectory(libshaderc) +@@ -142,7 +144,7 @@ endif() + add_custom_target(build-version + ${Python_EXECUTABLE} + ${CMAKE_CURRENT_SOURCE_DIR}/utils/update_build_version.py +- ${shaderc_SOURCE_DIR} ${spirv-tools_SOURCE_DIR} ${glslang_SOURCE_DIR} ${CMAKE_CURRENT_BINARY_DIR}/build-version.inc ++ dummy dummy dummy ${CMAKE_CURRENT_BINARY_DIR}/build-version.inc + COMMENT "Update build-version.inc in the Shaderc build directory (if necessary).") + + function(define_pkg_config_file NAME LIBS) +diff --git a/utils/update_build_version.py b/utils/update_build_version.py +index b7ce5b8..fcb0432 100755 +--- a/utils/update_build_version.py ++++ b/utils/update_build_version.py +@@ -120,11 +120,15 @@ def get_version_string(project, directory): + """Returns a detailed version string for a given project with its + directory, which consists of software version string and git description + string.""" +- detailed_version_string_lst = [project] +- if project != 'glslang': +- detailed_version_string_lst.append(deduce_software_version(directory)) +- detailed_version_string_lst.append(describe(directory).replace('"', '\\"')) +- return ' '.join(detailed_version_string_lst) ++ match project: ++ case "shaderc": ++ return "shaderc v@shaderc-version@" ++ case "spirv-tools": ++ return "spirv-tools v@spirv-tools-version@" ++ case "glslang": ++ return "glslang v@glslang-version@" ++ case _: ++ sys.exit(1) + + + def main(): From 42e9da0864c3c6c7bcd220a1e0dfe08037a4bf3f Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 15:19:07 -0700 Subject: [PATCH 12/21] gtk4: enable vulkan support --- pkgs/gtk/4.x.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/gtk/4.x.nix b/pkgs/gtk/4.x.nix index f8488c60..fcedee4d 100644 --- a/pkgs/gtk/4.x.nix +++ b/pkgs/gtk/4.x.nix @@ -199,7 +199,7 @@ stdenv.mkDerivation (finalAttrs: { mesonFeatures = { tracker = trackerSupport && tinysparql != null; - vulkan = vulkanSupport && shaderc != null; + vulkan = vulkanSupport; print-cups = cupsSupport; ${ if stdenv.hostPlatform.isDarwin && !stdenv.hostPlatform.isAarch64 then "media-gstreamer" else null From 5fa4e2b3e33829daaa080e2b12ae4339d3bf050e Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 15:33:33 -0700 Subject: [PATCH 13/21] libsass: init at 3.6.6 --- pkgs/libsass/default.nix | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 pkgs/libsass/default.nix diff --git a/pkgs/libsass/default.nix b/pkgs/libsass/default.nix new file mode 100644 index 00000000..8674f5b0 --- /dev/null +++ b/pkgs/libsass/default.nix @@ -0,0 +1,40 @@ +{ + lib, + stdenv, + fetchFromGitHub, + autoreconfHook, + testers, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "libsass"; + version = "3.6.6"; + + src = fetchFromGitHub { + owner = "sass"; + repo = "libsass"; + rev = finalAttrs.version; + hash = "sha256-FkLL3OAJXDptRQY6ZkYbss2pcc40f/wasIvEIyHRQFo="; + postFetch = '' + rm -r $out/test/e2e/unicode-pwd + ''; + }; + + preConfigure = '' + export LIBSASS_VERSION=${finalAttrs.version} + ''; + + nativeBuildInputs = [ autoreconfHook ]; + + passthru.tests = { + pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + }; + + meta = { + description = "C/C++ implementation of a Sass compiler"; + homepage = "https://github.com/sass/libsass"; + license = lib.licenses.mit; + pkgConfigModules = [ "libsass" ]; + platforms = lib.platforms.unix; + }; +}) From 014505967a4b61ebe2cc18201b2b9e056e1d523f Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 15:33:37 -0700 Subject: [PATCH 14/21] sassc: init at 3.6.2 --- pkgs/sassc/default.nix | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 pkgs/sassc/default.nix diff --git a/pkgs/sassc/default.nix b/pkgs/sassc/default.nix new file mode 100644 index 00000000..c2199477 --- /dev/null +++ b/pkgs/sassc/default.nix @@ -0,0 +1,35 @@ +{ + lib, + stdenv, + fetchFromGitHub, + autoreconfHook, + libsass, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "sassc"; + version = "3.6.2"; + + src = fetchFromGitHub { + owner = "sass"; + repo = "sassc"; + rev = finalAttrs.version; + hash = "sha256-jcs3+orRqKt9C3c2FTdeaj4H2rBP74lW3HF8CHSm7lQ="; + }; + + postPatch = '' + export SASSC_VERSION=${finalAttrs.version} + ''; + + nativeBuildInputs = [ autoreconfHook ]; + + buildInputs = [ libsass ]; + + meta = { + description = "Front-end for libsass"; + homepage = "https://github.com/sass/sassc/"; + license = lib.licenses.mit; + mainProgram = "sassc"; + platforms = lib.platforms.unix; + }; +}) From cb1d75400cc76cb723a53dbe412921cfd80ebb1b Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 16:19:37 -0700 Subject: [PATCH 15/21] libdaemon: init at 0.14 --- pkgs/libdaemon/default.nix | 37 +++++++++++++++++++++++++++++++ pkgs/libdaemon/fix-includes.patch | 13 +++++++++++ 2 files changed, 50 insertions(+) create mode 100644 pkgs/libdaemon/default.nix create mode 100644 pkgs/libdaemon/fix-includes.patch diff --git a/pkgs/libdaemon/default.nix b/pkgs/libdaemon/default.nix new file mode 100644 index 00000000..3ec363e4 --- /dev/null +++ b/pkgs/libdaemon/default.nix @@ -0,0 +1,37 @@ +{ + lib, + stdenv, + fetchurl, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "libdaemon"; + version = "0.14"; + + src = fetchurl { + url = "https://0pointer.de/lennart/projects/libdaemon/libdaemon-${finalAttrs.version}.tar.gz"; + sha256 = "0d5qlq5ab95wh1xc87rqrh1vx6i8lddka1w3f1zcqvcqdxgyn8zx"; + }; + + outputs = [ + "out" + "dev" + "doc" + ]; + + patches = [ ./fix-includes.patch ]; + + configureFlags = [ + "--disable-lynx" + ] + ++ lib.optionals (stdenv.hostPlatform != stdenv.buildPlatform) [ + "ac_cv_func_setpgrp_void=${lib.boolToYesNo (!stdenv.hostPlatform.isBSD)}" + ]; + + meta = { + description = "Lightweight C library that eases the writing of UNIX daemons"; + homepage = "http://0pointer.de/lennart/projects/libdaemon/"; + license = lib.licenses.lgpl2Plus; + platforms = lib.platforms.unix; + }; +}) diff --git a/pkgs/libdaemon/fix-includes.patch b/pkgs/libdaemon/fix-includes.patch new file mode 100644 index 00000000..cfb22a73 --- /dev/null +++ b/pkgs/libdaemon/fix-includes.patch @@ -0,0 +1,13 @@ +--- libdaemon-0.14.orig/examples/testd.c ++++ libdaemon-0.14/examples/testd.c +@@ -21,9 +21,9 @@ + #include + #include + #include ++#include + #include + #include +-#include + #include + + #include From bf0daf4712bbe2c3c4c67757fabacaadac3f0dad Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 16:19:40 -0700 Subject: [PATCH 16/21] avahi: init at 0.8 --- pkgs/avahi/default.nix | 220 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 220 insertions(+) create mode 100644 pkgs/avahi/default.nix diff --git a/pkgs/avahi/default.nix b/pkgs/avahi/default.nix new file mode 100644 index 00000000..9674639b --- /dev/null +++ b/pkgs/avahi/default.nix @@ -0,0 +1,220 @@ +{ + fetchurl, + fetchpatch, + lib, + stdenv, + pkg-config, + libdaemon, + dbus, + libpcap, + expat, + gettext, + glib, + autoconf-archive, + autoreconfHook, + libiconv, + libevent, + gtk3Support ? false, + gtk3, + withLibdnssdCompat ? false, +}: + +stdenv.mkDerivation rec { + pname = "avahi${lib.optionalString withLibdnssdCompat "-compat"}"; + version = "0.8"; + + src = fetchurl { + url = "https://github.com/lathiat/avahi/releases/download/v${version}/avahi-${version}.tar.gz"; + sha256 = "1npdixwxxn3s9q1f365x9n9rc5xgfz39hxf23faqvlrklgbhj0q6"; + }; + + outputs = [ + "out" + "dev" + "man" + ]; + + patches = [ + (fetchpatch { + name = "CVE-2021-3502.patch"; + url = "https://github.com/lathiat/avahi/commit/9d31939e55280a733d930b15ac9e4dda4497680c.patch"; + sha256 = "sha256-BXWmrLWUvDxKPoIPRFBpMS3T4gijRw0J+rndp6iDybU="; + }) + (fetchpatch { + name = "CVE-2021-3468.patch"; + url = "https://github.com/lathiat/avahi/commit/447affe29991ee99c6b9732fc5f2c1048a611d3b.patch"; + sha256 = "sha256-qWaCU1ZkCg2PmijNto7t8E3pYRN/36/9FrG8okd6Gu8="; + }) + (fetchpatch { + name = "CVE-2023-1981.patch"; + url = "https://github.com/lathiat/avahi/commit/a2696da2f2c50ac43b6c4903f72290d5c3fa9f6f.patch"; + sha256 = "sha256-BEYFGCnQngp+OpiKIY/oaKygX7isAnxJpUPCUvg+efc="; + }) + (fetchpatch { + name = "CVE-2023-38470.patch"; + url = "https://github.com/lathiat/avahi/commit/94cb6489114636940ac683515417990b55b5d66c.patch"; + sha256 = "sha256-Fanh9bvz+uknr5pAmltqijuUAZIG39JR2Lyq5zGKJ58="; + }) + (fetchpatch { + name = "bail-out-unless-escaped-labels-fit.patch"; + url = "https://github.com/avahi/avahi/commit/20dec84b2480821704258bc908e7b2bd2e883b24.patch"; + sha256 = "sha256-p/dOuQ/GInIcUwuFhQR3mGc5YBL5J8ho+1gvzcqEN0c="; + }) + (fetchpatch { + name = "CVE-2023-38473.patch"; + url = "https://github.com/lathiat/avahi/commit/b448c9f771bada14ae8de175695a9729f8646797.patch"; + sha256 = "sha256-/ZVhsBkf70vjDWWG5KXxvGXIpLOZUXdRkn3413iSlnI="; + }) + (fetchpatch { + name = "CVE-2023-38472.patch"; + url = "https://github.com/lathiat/avahi/commit/b024ae5749f4aeba03478e6391687c3c9c8dee40.patch"; + sha256 = "sha256-FjR8fmhevgdxR9JQ5iBLFXK0ILp2OZQ8Oo9IKjefCqk="; + }) + (fetchpatch { + name = "CVE-2023-38471.patch"; + url = "https://github.com/lathiat/avahi/commit/894f085f402e023a98cbb6f5a3d117bd88d93b09.patch"; + sha256 = "sha256-4dG+5ZHDa+A4/CszYS8uXWlpmA89m7/jhbZ7rheMs7U="; + }) + (fetchpatch { + name = "CVE-2023-38471-2.patch"; + url = "https://github.com/avahi/avahi/commit/b675f70739f404342f7f78635d6e2dcd85a13460.patch"; + sha256 = "sha256-uDtMPWuz1lsu7n0Co/Gpyh369miQ6GWGyC0UPQB/yI8="; + }) + (fetchpatch { + name = "CVE-2023-38469.patch"; + url = "https://github.com/avahi/avahi/commit/61b9874ff91dd20a12483db07df29fe7f35db77f.patch"; + sha256 = "sha256-qR7scfQqhRGxg2n4HQsxVxCLkXbwZi+PlYxrOSEPsL0="; + excludes = [ ".github/workflows/smoke-tests.sh" ]; + }) + (fetchpatch { + name = "fix-compare-rrs-with-zero-length-rdata.patch"; + url = "https://github.com/avahi/avahi/commit/177d75e8c43be45a8383d794ce4084dd5d600a9e.patch"; + sha256 = "sha256-uwIyruAWgiWt0yakRrvMdYjjhEhUk5cIGKt6twyXbHw="; + }) + (fetchpatch { + name = "reject-non-utf-8-service-names.patch"; + url = "https://github.com/avahi/avahi/commit/2b6d3e99579e3b6e9619708fad8ad8e07ada8218.patch"; + sha256 = "sha256-lwSA3eEQgH0g51r0i9/HJMJPRXrhQnTIEDxcYqUuLdI="; + excludes = [ "fuzz/fuzz-domain.c" ]; + }) + (fetchpatch { + name = "core-no-longer-supply-bogus-services-to-callbacks.patch"; + url = "https://github.com/avahi/avahi/commit/93b14365c1c1e04efd1a890e8caa01a2a514bfd8.patch"; + sha256 = "sha256-VBm8vsBZkTbbWAK8FI71SL89lZuYd1yFNoB5o+FvlEU="; + excludes = [ + ".github/workflows/smoke-tests.sh" + "fuzz/fuzz-packet.c" + ]; + }) + (fetchpatch { + name = "CVE-2024-52616.patch"; + url = "https://github.com/avahi/avahi/commit/f8710bdc8b29ee1176fe3bfaeabebbda1b7a79f7.patch"; + hash = "sha256-BUQOQ4evKLBzV5UV8xW8XL38qk1rg6MJ/vcT5NBckfA="; + }) + (fetchpatch { + name = "fix-requires-in-pc-file.patch"; + url = "https://github.com/avahi/avahi/commit/366e3798bdbd6b7bf24e59379f4a9a51af575ce9.patch"; + hash = "sha256-9AdhtzrimmcpMmeyiFcjmDfG5nqr/S8cxWTaM1mzCWA="; + }) + (fetchpatch { + name = "CVE-2025-68276.patch"; + url = "https://github.com/avahi/avahi/commit/0c013e2e819be3bda74cecf48b5f64956cf8a760.patch"; + hash = "sha256-kNOwl2DC2FR7CFvPQBBEYaSUSbFnR/ETH9JNGMwzzLE="; + }) + (fetchpatch { + name = "CVE-2025-68468.patch"; + url = "https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a.patch"; + hash = "sha256-HkbKSN2LYqPfVnij1/n6ToN4vKugex3ZPxjHz6pN8eA="; + }) + (fetchpatch { + name = "CVE-2025-68471.patch"; + url = "https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1.patch"; + hash = "sha256-V0OiC0UkZXhUnOUcrPZ+Xvph7MJMQ9DEXgVafoshSi4="; + }) + (fetchpatch { + name = "CVE-2026-24401.patch"; + url = "https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524.patch"; + hash = "sha256-Iq7ghHS8gTJ5OeD6Bemis+wPJzKXb2P44qbtTaAaWZI="; + }) + (fetchpatch { + name = "CVE-2026-34933.patch"; + url = "https://github.com/avahi/avahi/compare/0ccadca425af151ebb67f276e5cc88e50266a8e6%5E%5E...0ccadca425af151ebb67f276e5cc88e50266a8e6.patch"; + hash = "sha256-yi40iuQmTAW+nLsOIJhh7kg4vG/lqT/PCaSEBPfF2mw="; + }) + ]; + + postPatch = '' + # Remove the vendored ACX_PTHREAD macro in favor of the more up-to-date + # implementation from autoconf-archive, especially to support static builds. + rm common/acx_pthread.m4 + ''; + + depsBuildBuild = [ + pkg-config + ]; + + nativeBuildInputs = [ + pkg-config + gettext + glib + autoconf-archive + autoreconfHook + ]; + + buildInputs = [ + libdaemon + dbus + glib + expat + libiconv + libevent + ] + ++ lib.optionals stdenv.hostPlatform.isFreeBSD [ + libpcap + ] + ++ lib.optionals gtk3Support [ + gtk3 + ]; + + configureFlags = [ + "--disable-gdbm" + "--disable-mono" + "--disable-qt5" + "--disable-python" + "--with-dbus-sys=${placeholder "out"}/share/dbus-1/system.d" + (lib.enableFeature gtk3Support "gtk3") + "--localstatedir=/var" + "--runstatedir=/run" + "--sysconfdir=/etc" + "--with-distro=${with stdenv.hostPlatform; if isBSD then parsed.kernel.name else "none"}" + "--with-systemdsystemunitdir=no" + ] + ++ lib.optionals withLibdnssdCompat [ + "--enable-compat-libdns_sd" + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + "--disable-autoipd" + ]; + + installFlags = [ + "avahi_runtime_dir=${placeholder "out"}/run" + "sysconfdir=${placeholder "out"}/etc" + ]; + + preBuild = lib.optionalString stdenv.hostPlatform.isDarwin '' + sed -i '20 i\ + #define __APPLE_USE_RFC_2292' \ + avahi-core/socket.c + ''; + + postInstall = lib.optionalString withLibdnssdCompat '' + ln -s avahi-compat-libdns_sd/dns_sd.h "$dev/include/dns_sd.h" + ''; + + meta = { + description = "mDNS/DNS-SD implementation"; + homepage = "http://avahi.org"; + license = lib.licenses.lgpl2Plus; + platforms = lib.platforms.unix; + }; +} From c81fbd2aba6a4b0b4de0e03fde97fff761c748ba Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sat, 19 Sep 2026 16:19:44 -0700 Subject: [PATCH 17/21] wrapGAppsNoGuiHook: init with wrapGAppsHook3 and wrapGAppsHook4 --- pkgs/wrapGAppsNoGuiHook/default.nix | 35 ++++++ pkgs/wrapGAppsNoGuiHook/tests/lib.nix | 50 ++++++++ .../tests/sample-project/Makefile | 30 +++++ pkgs/wrapGAppsNoGuiHook/wrap-gapps-hook.sh | 107 ++++++++++++++++++ top-level.nix | 9 ++ 5 files changed, 231 insertions(+) create mode 100644 pkgs/wrapGAppsNoGuiHook/default.nix create mode 100644 pkgs/wrapGAppsNoGuiHook/tests/lib.nix create mode 100644 pkgs/wrapGAppsNoGuiHook/tests/sample-project/Makefile create mode 100644 pkgs/wrapGAppsNoGuiHook/wrap-gapps-hook.sh diff --git a/pkgs/wrapGAppsNoGuiHook/default.nix b/pkgs/wrapGAppsNoGuiHook/default.nix new file mode 100644 index 00000000..f070b21f --- /dev/null +++ b/pkgs/wrapGAppsNoGuiHook/default.nix @@ -0,0 +1,35 @@ +{ + stdenv, + lib, + makeSetupHook, + makeWrapper, + isGraphical ? false, + gtk3 ? null, + librsvg, + dconf, + withDconf ? !stdenv.targetPlatform.isDarwin && lib.meta.availableOn stdenv.targetPlatform dconf, + targetPackages, +}: + +makeSetupHook { + name = "wrap-gapps-hook"; + propagatedBuildInputs = [ + makeWrapper + ] + ++ lib.optionals isGraphical [ + gtk3 + librsvg + ]; + + depsTargetTargetPropagated = + assert (!targetPackages ? raw || throw "wrapGAppsNoGuiHook must be in nativeBuildInputs"); + lib.optionals isGraphical [ + librsvg + gtk3 + ] + ++ lib.optionals withDconf [ + dconf.lib + ]; + + meta.license = lib.licenses.mit; +} ./wrap-gapps-hook.sh diff --git a/pkgs/wrapGAppsNoGuiHook/tests/lib.nix b/pkgs/wrapGAppsNoGuiHook/tests/lib.nix new file mode 100644 index 00000000..c3daebb7 --- /dev/null +++ b/pkgs/wrapGAppsNoGuiHook/tests/lib.nix @@ -0,0 +1,50 @@ +{ lib, runCommand }: + +rec { + runTest = + name: body: + runCommand name { strictDeps = true; } '' + set -o errexit + ${body} + touch $out + ''; + + skip = + cond: text: + if cond then + '' + echo "Skipping test $name" > /dev/stderr + '' + else + text; + + fail = text: '' + echo "FAIL: $name: ${text}" > /dev/stderr + exit 1 + ''; + + expectSomeLineContainingYInFileXToMentionZ = + file: filter: expected: + let + msg1 = "The file " + file + " should include a line containing " + filter + "."; + msg2 = + "The file " + + file + + " should include a line containing " + + filter + + " that also contains " + + expected + + "."; + in + '' + file=${lib.escapeShellArg file} filter=${lib.escapeShellArg filter} expected=${lib.escapeShellArg expected} + + if ! grep --text --quiet "$filter" "$file"; then + ${fail msg1} + fi + + if ! grep --text "$filter" "$file" | grep --text --quiet "$expected"; then + ${fail msg2} + fi + ''; +} diff --git a/pkgs/wrapGAppsNoGuiHook/tests/sample-project/Makefile b/pkgs/wrapGAppsNoGuiHook/tests/sample-project/Makefile new file mode 100644 index 00000000..5d234db1 --- /dev/null +++ b/pkgs/wrapGAppsNoGuiHook/tests/sample-project/Makefile @@ -0,0 +1,30 @@ +PREFIX = $(out) +BINDIR = $(PREFIX)/bin +LIBEXECDIR = $(PREFIX)/libexec +LIBDIR = $(PREFIX)/lib +TYPELIBDIR = $(LIBDIR)/girepository-1.0 + +all: + echo "Compiling…" +install: + echo "Installing…" + +bin: + mkdir -p $(BINDIR) +# Adds `bin-${foo}` targets, that install `${foo}` executable to `$(BINDIR)`. +bin-%: bin + touch $(BINDIR)/$(@:bin-%=%) + chmod +x $(BINDIR)/$(@:bin-%=%) + +libexec: + mkdir -p $(LIBEXECDIR) +# Adds `libexec-${foo}` targets, that install `${foo}` executable to `$(LIBEXECDIR)`. +libexec-%: libexec + touch $(LIBEXECDIR)/$(@:libexec-%=%) + chmod +x $(LIBEXECDIR)/$(@:libexec-%=%) + +typelib: + mkdir -p $(TYPELIBDIR) +# Adds `typelib-${foo}` targets, that install `${foo}-1.0.typelib` file to `$(TYPELIBDIR)`. +typelib-%: typelib + touch $(TYPELIBDIR)/$(@:typelib-%=%)-1.0.typelib diff --git a/pkgs/wrapGAppsNoGuiHook/wrap-gapps-hook.sh b/pkgs/wrapGAppsNoGuiHook/wrap-gapps-hook.sh new file mode 100644 index 00000000..a0712cc5 --- /dev/null +++ b/pkgs/wrapGAppsNoGuiHook/wrap-gapps-hook.sh @@ -0,0 +1,107 @@ +# shellcheck shell=bash +gappsWrapperArgs=() + +find_gio_modules() { + if [ -d "$1/lib/gio/modules" ] && [ -n "$(ls -A "$1/lib/gio/modules")" ] ; then + gappsWrapperArgs+=(--prefix GIO_EXTRA_MODULES : "$1/lib/gio/modules") + fi +} + +addEnvHooks "${targetOffset:?}" find_gio_modules + +gappsWrapperArgsHook() { + if [ -n "$GDK_PIXBUF_MODULE_FILE" ]; then + gappsWrapperArgs+=(--set GDK_PIXBUF_MODULE_FILE "$GDK_PIXBUF_MODULE_FILE") + fi + + if [ -n "$GSETTINGS_SCHEMAS_PATH" ] || [ -d "${prefix:?}/share" ]; then + gappsWrapperArgs+=(--set-default XDG_DATA_DIRS /usr/local/share/:/usr/share/) + fi + + if [ -n "$GSETTINGS_SCHEMAS_PATH" ]; then + gappsWrapperArgs+=(--prefix XDG_DATA_DIRS : "$GSETTINGS_SCHEMAS_PATH") + fi + + if [ -d "${prefix:?}/share" ]; then + gappsWrapperArgs+=(--prefix XDG_DATA_DIRS : "$prefix/share") + fi + + if [ -d "$prefix/lib/gio/modules" ] && [ -n "$(ls -A "$prefix/lib/gio/modules")" ]; then + gappsWrapperArgs+=(--prefix GIO_EXTRA_MODULES : "$prefix/lib/gio/modules") + fi + + for v in ${wrapPrefixVariables:-} GST_PLUGIN_SYSTEM_PATH_1_0 GI_TYPELIB_PATH GRL_PLUGIN_PATH; do + if [ -n "${!v:-}" ]; then + gappsWrapperArgs+=(--prefix "$v" : "${!v}") + fi + done +} + +appendToVar preFixupPhases gappsWrapperArgsHook + +wrapGApp() { + local program="$1" + shift 1 + wrapProgram "$program" "${gappsWrapperArgs[@]}" "$@" +} + +_wrapGAppsHookMayRunForOutput() { + local -r output="$1" + if [[ -v wrapGAppsInOutputs ]]; then + local allowedOutput + local -a allowedOutputs + concatTo allowedOutputs wrapGAppsInOutputs + for allowedOutput in "${allowedOutputs[@]}"; do + [ "$allowedOutput" = "$output" ] && return 0 + done + else + [ "$outputBin" = "$output" ] && return 0 + fi + return 1 + } + +declare -gA wrapGAppsHookHasRunForOutput + +wrapGAppsHook() { + [ "${wrapGAppsHookHasRunForOutput["$output"]:-}" = 1 ] && return 0 + wrapGAppsHookHasRunForOutput["$output"]=1 + _wrapGAppsHookMayRunForOutput "$output" || return 0 + + if [[ -z "${dontWrapGApps:-}" ]]; then + local targetDirsThatExist targetDirsRealPath targetDirs targetDir + + targetDirsThatExist=() + targetDirsRealPath=() + + targetDirs=("${prefix}/bin" "${prefix}/libexec") + for targetDir in "${targetDirs[@]}"; do + if [[ -d "${targetDir}" ]]; then + targetDirsThatExist+=("${targetDir}") + targetDirsRealPath+=("$(realpath "${targetDir}")/") + find "${targetDir}" -type f -executable -print0 | + while IFS= read -r -d '' file; do + echo "Wrapping program '${file}'" + wrapGApp "${file}" + done + fi + done + + local linkPathReal targetPath + if [[ ${#targetDirsThatExist[@]} -ne 0 ]]; then + find "${targetDirsThatExist[@]}" -type l -xtype f -executable -print0 | + while IFS= read -r -d '' linkPath; do + linkPathReal=$(realpath "${linkPath}") + for targetPath in "${targetDirsRealPath[@]}"; do + if [[ "$linkPathReal" == "$targetPath"* ]]; then + echo "Not wrapping link: '$linkPath' (already wrapped)" + continue 2 + fi + done + echo "Wrapping link: '$linkPath'" + wrapGApp "${linkPath}" + done + fi + fi +} + +fixupOutputHooks+=(wrapGAppsHook) diff --git a/top-level.nix b/top-level.nix index 46c4246a..850b7e95 100644 --- a/top-level.nix +++ b/top-level.nix @@ -496,6 +496,15 @@ final: prev: with final; { xorriso = libisoburn; + wrapGAppsNoGuiHook = callPackage ./pkgs/wrapGAppsNoGuiHook { + makeWrapper = makeBinaryWrapper; + }; + wrapGAppsHook3 = wrapGAppsNoGuiHook.override { isGraphical = true; }; + wrapGAppsHook4 = wrapGAppsNoGuiHook.override { + isGraphical = true; + gtk3 = gtk4; + }; + # Less secure variant of lowdown for use inside Nix builds. lowdown-unsandboxed = lowdown.override { enableDarwinSandbox = false; From 3843476d99231c80f5a8c80786ea45eaf61e69b2 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sun, 20 Sep 2026 12:06:44 -0700 Subject: [PATCH 18/21] stdenv: avoid canonicalizing meson or cmake if they don't exist --- stdenv/lib/cmake.nix | 14 +++++++++----- stdenv/lib/meson.nix | 20 ++++++++++++-------- 2 files changed, 21 insertions(+), 13 deletions(-) diff --git a/stdenv/lib/cmake.nix b/stdenv/lib/cmake.nix index 6290a52a..26e5db2a 100644 --- a/stdenv/lib/cmake.nix +++ b/stdenv/lib/cmake.nix @@ -87,14 +87,18 @@ let # Canonicalize user cmakeEntries values (bools -> "ON"/"OFF", others -> toString) # and merge with cross-compilation entries (user values take precedence). makeCMakeEntries = - { + attrs@{ cmakeEntries ? { }, ... }: - let - canonicalize = _: v: if builtins.isBool v then (if v then "ON" else "OFF") else builtins.toString v; - in - cmakeEntries' // (mapAttrs canonicalize cmakeEntries); + # Skip canonicalization for non-cmake builds; avoids per-derivation overhead during evaluation. + if !isCross && !(attrs ? cmakeEntries) then + { } + else + let + canonicalize = _: v: if builtins.isBool v then (if v then "ON" else "OFF") else builtins.toString v; + in + cmakeEntries' // (mapAttrs canonicalize cmakeEntries); in { diff --git a/stdenv/lib/meson.nix b/stdenv/lib/meson.nix index ecd3ecb4..688eefd1 100644 --- a/stdenv/lib/meson.nix +++ b/stdenv/lib/meson.nix @@ -57,18 +57,22 @@ let # Canonicalize user mesonEntries values (bools -> "true"/"false", others -> toString). makeMesonEntries = - { + attrs@{ mesonEntries ? { }, mesonFeatures ? { }, ... }: - let - canonicalize = - _: v: if builtins.isBool v then (if v then "true" else "false") else builtins.toString v; - canonicalizeFeature = - _: v: if builtins.isBool v then (if v then "enabled" else "disabled") else builtins.toString v; - in - mapAttrs canonicalize mesonEntries // mapAttrs canonicalizeFeature mesonFeatures; + # Skip canonicalization for non-meson builds; avoids per-derivation overhead during evaluation. + if !(attrs ? mesonEntries) && !(attrs ? mesonFeatures) then + { } + else + let + canonicalize = + _: v: if builtins.isBool v then (if v then "true" else "false") else builtins.toString v; + canonicalizeFeature = + _: v: if builtins.isBool v then (if v then "enabled" else "disabled") else builtins.toString v; + in + mapAttrs canonicalize mesonEntries // mapAttrs canonicalizeFeature mesonFeatures; in { From 54d39ba6372f623c32b00688ac285941fd4dc4e3 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sun, 20 Sep 2026 12:06:54 -0700 Subject: [PATCH 19/21] conmon: fix git tag --- pkgs/conmon/default.nix | 10 ++-------- 1 file changed, 2 insertions(+), 8 deletions(-) diff --git a/pkgs/conmon/default.nix b/pkgs/conmon/default.nix index 989a6187..bfc9f104 100644 --- a/pkgs/conmon/default.nix +++ b/pkgs/conmon/default.nix @@ -19,13 +19,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "containers"; repo = "conmon"; tag = "v${finalAttrs.version}"; - hash = "sha256-YkPgpT+0cE7FCP/dcqnTy6oonPbXKiutFCGX5Lj1JB8="; - leaveDotGit = true; - postFetch = '' - cd $out - git rev-parse HEAD > COMMIT - rm -rf .git - ''; + hash = "sha256-NIbH/fiz/m2W7aGt2On7E6zkWFa5IKzrPROuCAYwNFk="; }; nativeBuildInputs = [ pkg-config ]; @@ -42,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { # manpage requires building the vendored go-md2man makeFlags = [ "bin/conmon" - "GIT_COMMIT=${lib.trim (builtins.readFile "${finalAttrs.src}/COMMIT")}" + "GIT_COMMIT=${finalAttrs.src.rev}" ]; installPhase = '' From f38c27320e422b83796d9c8af6be8bc0176abc68 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sun, 20 Sep 2026 12:08:18 -0700 Subject: [PATCH 20/21] ci: disallow IFD explicitly --- ci/eval.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ci/eval.sh b/ci/eval.sh index 590973f8..b5e9b0b8 100755 --- a/ci/eval.sh +++ b/ci/eval.sh @@ -13,7 +13,7 @@ trap 'rm -f "$stderr"' EXIT # Real failures are `abort`s, missing attributes and type errors, none of which # `tryEval` can catch -- so they surface here as a non-zero exit with Nix's own # message, which names the offending expression and its source location. -if ! result="$(nix-instantiate --eval --strict --json ci/eval.nix 2>"$stderr")"; then +if ! result="$(nix-instantiate --eval --strict --json ci/eval.nix --option allow-import-from-derivation false 2>"$stderr")"; then cat "$stderr" >&2 exit 1 fi From 2946d8654ac308b9b4bc9045f97b8126bbf7b837 Mon Sep 17 00:00:00 2001 From: Jonathan Ringer Date: Sun, 20 Sep 2026 12:12:18 -0700 Subject: [PATCH 21/21] cmake: always honor cmakeEntries --- stdenv/lib/cmake.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/stdenv/lib/cmake.nix b/stdenv/lib/cmake.nix index 26e5db2a..d886ba3b 100644 --- a/stdenv/lib/cmake.nix +++ b/stdenv/lib/cmake.nix @@ -92,7 +92,7 @@ let ... }: # Skip canonicalization for non-cmake builds; avoids per-derivation overhead during evaluation. - if !isCross && !(attrs ? cmakeEntries) then + if !(attrs ? cmakeEntries) then { } else let