Commit Graph
252168 Commits
Author SHA1 Message Date
R. RyanTM 4e1db3daf0 pcm: 202008 -> 202009 2020-11-04 00:18:43 +00:00
Kevin Cox e84d30d4dd Merge pull request #101217 from hardselius/master
nodePackages.fauna-shell: init at 0.11.5
2020-11-03 19:06:35 -05:00
R. RyanTM ea4201e198 opendht: 2.1.4 -> 2.1.6 2020-11-04 00:02:29 +00:00
John Ericson 617f3140b5 Merge pull request #98299 from Kloenk/homed
systemd: enable homed
2020-11-03 18:53:55 -05:00
Kevin Cox dc79731ae0 Merge pull request #99631 from glittershark/graalvm-ce
graalvm{8,11}-ce: init at 20.2.0
2020-11-03 18:39:11 -05:00
Fabián Heredia Montiel acd3d3dd20 nixos/modules/services/network-filesystems/ipfs: refactor
Add `package` option to change the package used for the service.
2020-11-03 17:35:06 -06:00
Martin Hardselius fdb8cb598b nodePackages.fauna-shell: init at 0.11.5 2020-11-04 00:33:39 +01:00
WilliButz 13bc774904 Merge pull request #102629 from WilliButz/init/tempo/v0.2.0
tempo: init at 0.2.0
2020-11-04 00:32:20 +01:00
Maximilian Bosch cb1a522d76 Merge pull request #102548 from r-ryantm/auto-update/libfilezilla
libfilezilla: 0.24.1 -> 0.25.0
2020-11-04 00:24:49 +01:00
Kevin Cox c4a2a453be Merge pull request #101446 from OPNA2608/package/ptcollab/21.03
ptcollab: init at 0.3.4.1
2020-11-03 18:24:00 -05:00
Kevin Cox e031671e19 Merge pull request #100202 from OPNA2608/update/halide-10.0.0
halide: 2019.08.27 -> 10.0.0, enable on aarch64-linux
2020-11-03 18:19:40 -05:00
Maximilian Bosch 988e44c3e6 Merge pull request #102567 from VirtusLab/git-machete-2.15.7
gitAndTools.git-machete: 2.15.6 -> 2.15.7
2020-11-04 00:18:52 +01:00
Maximilian Bosch d225f494c2 Merge pull request #102597 from r-ryantm/auto-update/memtester
memtester: 4.3.0 -> 4.5.0
2020-11-04 00:17:29 +01:00
Maximilian Bosch d556639eae Merge pull request #102673 from zowoq/fzf
fzf: 0.24.1 -> 0.24.2
2020-11-04 00:14:45 +01:00
Maximilian Bosch 13839daecc Merge pull request #102663 from Frostman/hugo-0.78.0
hugo: 0.77.0 -> 0.78.0
2020-11-04 00:13:27 +01:00
Maximilian Bosch d6b804db2f Merge pull request #102530 from Ma27/fix-initrd-network-ssh-test
nixos/initrd-network-ssh: fix test
2020-11-04 00:01:10 +01:00
Ryan Mulligan 4ee1f7bc2c Merge pull request #102582 from r-ryantm/auto-update/marvin
marvin: 20.17.0 -> 20.19.0
2020-11-03 14:56:38 -08:00
Finn Behrens 7787fd2413 systemd: Add an option for homed
This is disabled by default to indicate that is hasn't been adiquately
tested with NixOS yet.
2020-11-03 17:35:26 -05:00
Finn Behrens cb764dbc24 top-level: Use systemdMinimal in a few more places 2020-11-03 17:35:14 -05:00
Doron Behar d5560be0df Merge pull request #98400 from doronbehar/pkg/bump
bump: init at 0.2.2
2020-11-04 00:30:09 +02:00
Doron Behar 89d9069c12 Merge pull request #100706 from doronbehar/pkg/rtsp-simple-server
rtsp-simple-server: init at 0.10.0
2020-11-04 00:29:57 +02:00
Sascha Grunert d48026dc5b crun: 0.15 -> 0.15.1
Signed-off-by: Sascha Grunert <sgrunert@suse.com>
2020-11-04 08:28:22 +10:00
zowoq 93c4fad2c3 fzf: 0.24.1 -> 0.24.2
https://github.com/junegunn/fzf/releases/tag/0.24.2
2020-11-04 08:25:03 +10:00
Doron Behar 80b96cf4ad Merge pull request #100660 from fzakaria/faridzakaria/maven-documentation 2020-11-04 00:24:19 +02:00
Bas van Dijk 64cbf9f0de mlc: init at 3.9
https://software.intel.com/content/www/us/en/develop/articles/intelr-memory-latency-checker.html
2020-11-03 23:02:47 +01:00
R. RyanTM fd12c2efcd olm: 3.1.5 -> 3.2.1 2020-11-03 20:51:51 +00:00
squalus 744ea3d944 ungoogled-chromium: 85.0.4183.102-1 -> 86.0.4240.111-1
based on chromium master@26d3fbf2
2020-11-03 12:42:58 -08:00
RonanMacF 84884a4938 vimPlugins.LanguageTool-nvim: init at 2020-10-19 2020-11-03 12:36:44 -08:00
RonanMacF 5517b3b985 vimPlugins: update 2020-11-03 12:36:44 -08:00
OPNA2608 ec38b50c67 ptcollab: init at 0.3.4.1 2020-11-03 21:24:10 +01:00
Sergey Lukjanov 30804e21c7 hugo: 0.77.0 -> 0.78.0 2020-11-03 12:09:22 -08:00
Florian Klink cc496fd42d Merge pull request #102618 from flokli/terraform-providers
terraform-providers.*: update
2020-11-03 20:40:21 +01:00
José Romildo Malaquias 4dc4b62ee5 Merge pull request #102007 from stephaneyfx/fix-numix-cursor-theme-generation
numix-cursor-theme: patch inkscape command
2020-11-03 16:18:17 -03:00
Michael Weiss 4b2c7fb106 gn: Add myself as maintainer
Since I maintain Chromium (I'll have to make sure that gnChromium always
builds and it would be good to get notified on any PRs/issues).
2020-11-03 20:01:28 +01:00
Michael Weiss d7f5386474 chromium: Extend update.py to automatically update gn
The gn version depends on the channel and new gn versions aren't always
backward compatible. Therefore we should also include it in
upstream-info.json (I've scoped it under "deps" as we'll likely have to
add more like this in the future).
2020-11-03 20:00:25 +01:00
Vladimír Čunát a31fd3cb7f Merge #102614: haskell.compiler.ghc8102BinaryMinimal: init 2020-11-03 19:54:09 +01:00
Thomas Depierre 3fbb1f7e4c python3Packages.credstash: fix nativeBuildInputs 2020-11-03 10:53:53 -08:00
José Romildo Malaquias caf4851352 Merge pull request #102619 from r-ryantm/auto-update/numix-icon-theme-square
numix-icon-theme-square: 20.07.11 -> 20.09.19
2020-11-03 15:50:05 -03:00
José Romildo Malaquias a5cc1469aa Merge pull request #102627 from r-ryantm/auto-update/numix-icon-theme-circle
numix-icon-theme-circle: 20.07.11 -> 20.09.19
2020-11-03 15:45:29 -03:00
R. RyanTM 97637b479d krita: 4.4.0 -> 4.4.1 2020-11-03 10:39:48 -08:00
Andreas Rammhold 8222839796 Merge pull request #102643 from mweinelt/salt
salt: 3002 -> 3002.1
2020-11-03 19:39:29 +01:00
Michael Weiss 3531d0d0b7 Merge pull request #102608 from primeos/chromium
chromium: 86.0.4240.111 -> 86.0.4240.183
2020-11-03 19:23:41 +01:00
Andreas Rammhold 5903ea5395 nixos/unbond: unbound should be required for nss-lookup.target
Other units depend on nss-lookup.target and expect the DNS resolution to
work once that target is reached. The previous version
`wants=nss-lookup.target` made this unit require the nss-lookup.target
to be reached before this was started.

Another change that we can probalby do is drop the before relationship
with the nss-lookup.target. That might just be implied with the current
version.
2020-11-03 19:21:39 +01:00
Andreas Rammhold 5c16c31e06 nixos/unbound: add release notes for the changes that were introduced
As part of this patch series a few changes have been made to the unbound
serivce the deserve proper documentation.
2020-11-03 19:21:25 +01:00
Andreas Rammhold 2aa64e5df5 nixos/unbound: add option to configure the local control socket path
This option allows users to specify a local UNIX control socket to
"remote control" the daemon. System users, that should be permitted to
access the daemon, must be in the `unbound` group in order to access the
socket. When a socket path is configured we are also creating the
required group.

Currently this only supports the UNIX socket mode while unbound actually
supports more advanced types. Users are still able to configure more
complex scenarios via the `extraConfig` attribute.

When this option is set to `null` (the default) it doesn't affect the
system configuration at all. The unbound defaults for control sockets
apply and no additional groups are created.
2020-11-03 19:21:25 +01:00
Andreas Rammhold b67cc6298e nixos/tests/unbound: add test to verify control sockets work 2020-11-03 19:21:24 +01:00
Andreas Rammhold a040a8a2e3 nixos/tests/unbound: init 2020-11-03 19:21:24 +01:00
Andreas Rammhold aadc07618a nixos/unbound: drop ReadWritePaths from systemd unit configuration
Both of the configured paths should be implicit due to RuntimeDirectory
& StateDirectory.
2020-11-03 19:21:24 +01:00
Andreas Rammhold 72fbf05c17 nixos/unbound: note about the AmbientCapabilities 2020-11-03 19:21:24 +01:00
Andreas Rammhold 5e602f88d1 nixos/modules/services/networking/unbound: update systemd unit
Previously we just applied a very minimal set of restrictions and
trusted unbound to properly drop root privs and capabilities.

With this change I am (for the most part) just using the upstream
example unit file for unbound. The main difference is that we start
unbound was `unbound` user with the required capabilities instead of
letting unbound do the chroot & uid/gid changes.

The upstream unit configuration this is based on is a lot stricter with
all kinds of permissions then our previous variant. It also came with
the default of having the `Type` set to `notify`, therefore we are also
using the `unbound-with-systemd` package here. Unbound will start up,
read the configuration files and start listening on the configured ports
before systemd will declare the unit "running". This will likely help
with startup order and the occasional race condition during system
activation where the DNS service is started but not yet ready to answer
queries.

Aditionally to the much stricter runtime environmet I removed the
`/dev/urandom` mount lines we previously had in the code (that would
randomly fail during `stop`-phase).

The `preStart` script is now only required if we enabled the trust
anchor updates (which are still enabled by default).

Another beneefit of the refactoring is that we can now issue reloads via
either `pkill -HUP unbound` or `systemctl reload unbound` to reload the
running configuration without taking the daemon offline. A prerequisite
of this was that unbound configuration is available on a well known path
on the file system. I went for /etc/unbound/unbound.conf as that is the
default in the CLI tooling which in turn enables us to use
`unbound-control` without passing a custom configuration location.
2020-11-03 19:21:24 +01:00