Commit graph

286946 commits

Author SHA1 Message Date
Martin Weinelt
7d09d7f571
nixos/home-assistant: harden systemd service
This is what is still exposed, and it should still allow things to work
as usual.

✗ PrivateNetwork=                    Service has access to the host's …      0.5
✗ RestrictAddressFamilies=~AF_(INET… Service may allocate Internet soc…      0.3
✗ DeviceAllow=                       Service has a device ACL with som…      0.1
✗ IPAddressDeny=                     Service does not define an IP add…      0.2
✗ PrivateDevices=                    Service potentially has access to…      0.2
✗ PrivateUsers=                      Service has access to other users       0.2
✗ SystemCallFilter=~@resources       System call allow list defined fo…      0.2
✗ RootDirectory=/RootImage=          Service runs within the host's ro…      0.1
✗ SupplementaryGroups=               Service runs with supplementary g…      0.1
✗ RestrictAddressFamilies=~AF_UNIX   Service may allocate local sockets      0.1

→ Overall exposure level for home-assistant.service: 1.6 OK :-)

This can grow to as much as ~1.9 if you use one of the bluetooth or nmap
trackers or the emulated_hue component, all of which required elevated
permisssions.
2021-05-03 00:21:24 +02:00
Mario Rodas
8b0515eb9a
pngquant: 2.12.5 -> 2.14.1 (#121470) 2021-05-02 23:59:08 +02:00
Luke Granger-Brown
f2a91ec2b7 nixos/tests/gitdaemon: deflake by using systemd-tmpfiles
git-daemon won't start up if its project directory (here /git) doesn't
exist. If we try to create it using the test harness, then we're racing
whether we manage to connect to the backdoor vs. the startup speed of
git-daemon.

Instead, use systemd-tmpfiles, which is guaranteed(?) to run before
network.target and thus before git-daemon.service starts.
2021-05-02 21:58:43 +00:00
Luke Granger-Brown
a6fb22a689 nixos/tests/rspamd: increase memory
rspamd seems to be consuming more memory now sometimes, causing OOMs in
the test.

Increase the memory given to these VMs to make the tests pass more
reliably.
2021-05-02 21:50:17 +00:00
Luke Granger-Brown
649672e76e nixos/postfix: fix compatibility level
Postfix has started outputting an error on startup that it can't parse
the compatibility level 9999.

Instead, just set the compatibility level to be identical to the current
version, which seems to be the (new) intent for the compatibility level.
2021-05-02 21:49:33 +00:00
Luke Granger-Brown
da000ae239 nixos/tests/custom-ca: fix by setting Content-Type
This test was failing because Firefox was displaying a download prompt
rather than the page content, presumably because mumble mumble
content-type sniffing.

By explicitly setting a content-type, the test now passes.
2021-05-02 21:38:56 +00:00
Rick van Schijndel
742adf762b graphene: fix build by allowing newer versions of aniso8601
All tests seem to pass, which gives some confidence that this is ok.
2021-05-02 22:56:53 +02:00
Martin Weinelt
d942d4473d neovim, neovimUtils, neovim-qt: drop python2 support
In 2a00e53bd pynvim support for python2 was disabled, this broke the
neovim build. I really think it is time to let go of python2 support in
neovim.
2021-05-02 22:43:53 +02:00
R. RyanTM
f5e695bf3a
kubelogin-oidc: 1.23.0 -> 1.23.1 (#121440) 2021-05-02 16:39:45 -04:00
Jonathan Ringer
a060b84b32 vscod{e,ium}-fhs: add top-level aliases, add description 2021-05-02 13:38:52 -07:00
Jonathan Ringer
9bd292c929 vscod{e,ium}: Add fhs passthru 2021-05-02 13:38:52 -07:00
Jonathan Ringer
73a0b6c826 buildFHSUserEnvBubblewrap: add dieWithParent option, and /etc/nix
Allows for processes which fork to not be immediately
killed when the parent process dies.
2021-05-02 13:38:52 -07:00
Luke Granger-Brown
4518794ee5
Merge pull request #121534 from lukegb/bogus-mk2
tela-icon-theme: more changes to change the hash
2021-05-02 21:25:34 +01:00
Martin Weinelt
6c022654f6 python3Packages.csvw: 1.10.1 -> 1.10.2 2021-05-02 13:24:22 -07:00
Luke Granger-Brown
134c68a411 tela-icon-theme: use stdenvNoCC
This doesn't use any of the compilers tools, so it may as well use the
compilerless version of the stdenv.
2021-05-02 20:18:48 +00:00
Luke Granger-Brown
a494e0ce56 tela-icon-theme: switch to gpl3Only
Since the license isn't documented anywhere other than COPYING, it must
be assumed that the intent was to license only under the included
license, without any extra clauses such as the "(at your option) any
later version" clause.
2021-05-02 20:18:01 +00:00
Luke Granger-Brown
6f55db13eb tela-icon-theme: skip patchelf and symlink rewrite steps
* We don't have any ELFs to patch.
* Scanning all the symlinks is slow, and jdupes already makes them
  relative anyway.
2021-05-02 20:17:16 +00:00
Leo Gaskin
f4ec650cde texlive.bin.dvisvgm: Use version provided by TeXLive
The dvisvgm version provided by TeXLive now includes the fixes
mentioned in the attached issue and thus can be used again instead of
relying on upstream sources.
2021-05-02 22:05:29 +02:00
Leo Gaskin
dbc6e67bb3 texlive.bin: Use xpdf provided by TeXLive
This is done because the xpdf provided by Nixpkgs is marked as
insecure.  Granted, the version provided by TeXLive also has these
vulnerabilities, but it might be okay to treat them as irrelevant in
the context of TeX.
2021-05-02 22:05:29 +02:00
Leo Gaskin
7bf9a3b250 texlive.bin: fix for replacement of poppler with pplib
TeXLive no longer depends on or supports poppler, instead using the
homegrown pplib library.
2021-05-02 22:05:29 +02:00
Leo Gaskin
2ffe681e66 texlive: 2020 -> 2021 2021-05-02 21:50:09 +02:00
Robert Schütz
7b3df91236 libadwaita: init at unstable-2021-05-01 2021-05-02 21:27:21 +02:00
Michael Weiss
501956b985
glances: 3.1.6.2 -> 3.1.7 2021-05-02 21:22:56 +02:00
Andreas Rammhold
e3ad419b87
Merge pull request #121461 from marsam/update-gopass
gopass: 1.12.5 -> 1.12.6
2021-05-02 20:11:54 +02:00
Anderson Torres
4e78613c05
Merge pull request #121424 from dotlambda/ophis-fix
ophis: fix build
2021-05-02 14:58:43 -03:00
Anderson Torres
bebfaab5ba
Merge pull request #121405 from branwright1/revert-121357-new-river
Revert "river: refactor"
2021-05-02 14:57:41 -03:00
Mario Rodas
fb5a9e4095
Merge pull request #121466 from marsam/update-lxc
lxc: 4.0.7 -> 4.0.8
2021-05-02 12:55:16 -05:00
José Romildo Malaquias
a611906544 xfce: add release note about dropping lighter gvfs package 2021-05-02 14:26:52 -03:00
R. RyanTM
7985d9e4ac
lego: 4.2.0 -> 4.3.1
https://github.com/go-acme/lego/releases/tag/v4.3.0
https://github.com/go-acme/lego/releases/tag/v4.3.1
2021-05-02 19:12:48 +02:00
Luke Granger-Brown
9775b39fd4
Merge pull request #121519 from NixOS/lukegb-tela-icon-theme
tela-icon-theme: format slightly differently
2021-05-02 17:34:25 +01:00
Bjørn Forsman
13cadfac15 zoom-us: fix overriding source
Without this using .overrideAttrs to change the source still uses the
old source.
2021-05-02 17:38:55 +02:00
fortuneteller2k
4b5ab91904 xcolor: init at unstable-2021-02-02 2021-05-02 23:38:24 +08:00
Luke Granger-Brown
8142fd653f
tela-icon-theme: format slightly differently
This change is intended to cause the package hash to change, to work around a bug in Hydra that's causing the nixos-unstable channel advancement to fail (due to an invalid .ls file).
2021-05-02 15:49:37 +01:00
Atemu
1b10b0d579 kernel: clarify license 2021-05-02 14:44:54 +00:00
Ethan Edwards
e3763e4799
piston-cli: 1.2.2 -> 1.3.0 (#121448) 2021-05-02 16:33:41 +02:00
Martin Weinelt
2c21dba881
Merge pull request #121392 from daneads/mopidy-podcast
mopidy-podcast: init at 3.0.0
2021-05-02 15:52:24 +02:00
Sandro
a0842dff29
Merge pull request #121360 from r-ryantm/auto-update/krankerl
krankerl: 0.13.0 -> 0.13.1
2021-05-02 15:50:23 +02:00
Sandro
ed845591ad
Merge pull request #121291 from r-ryantm/auto-update/krapslog
krapslog: 0.1.2 -> 0.1.3
2021-05-02 15:49:58 +02:00
Sandro
b71e70b45a
Merge pull request #121271 from samuelgrf/libfaketime-add-meta.mainProgram
libfaketime: add meta.mainProgram
2021-05-02 15:48:53 +02:00
Sandro
333ed43c4b
Merge pull request #121273 from ktor/timeular-3.9.1
timeular: 3.4.1 -> 3.9.1
2021-05-02 15:48:30 +02:00
031d7e3e-4476-4fef-a076-26150f8ecc2f
75468c3907 mopidy-podcast: init at 3.0.0
Mopidy extension for browsing and playing podcasts

Update maintainer + add py3 tests
2021-05-02 09:38:06 -04:00
Martin Weinelt
4642f4809f
Merge pull request #121503 from daneads/patch-1
Add daneads to maintainers
2021-05-02 15:30:10 +02:00
Jan Tojnar
86ec321e63 link-grammar: 5.8.1 -> 5.9.1
https://github.com/opencog/link-grammar/blob/link-grammar-5.9.1/ChangeLog

Remove libz dependency since that has only been used by minisat.

Also clean up the expression.
2021-05-02 15:17:26 +02:00
239
9e94b036a1
pcloud: fix runtime dependencies (#121495) 2021-05-02 15:16:04 +02:00
Dan Eads
33682a80a1 maintainers: add daneads 2021-05-02 09:15:45 -04:00
Sandro
df3c94e6c8
Merge pull request #110562 from r-k-b/cypress/updateScript
cypress: add updateScript
2021-05-02 15:15:17 +02:00
Sandro
c6d2f34e88
Merge pull request #121353 from otavio/topic-add-cargo-rr
cargo-rr: init at 0.1.3
2021-05-02 15:13:46 +02:00
Martin Weinelt
e26c6b55ae
Merge pull request #121506 from fabaff/bump-pywizlight
python3Packages.pywizlight: 0.4.6 -> 0.4.7
2021-05-02 15:07:23 +02:00
Michael Raskin
3a07a89802
Merge pull request #119383 from jtojnar/geoclue-custom-key
geoclue2: Use our own mozilla API key
2021-05-02 13:05:38 +00:00
Fabian Affolter
12714a4726 python3Packages.pywizlight: 0.4.6 -> 0.4.7 2021-05-02 14:54:09 +02:00