-
Notifications
You must be signed in to change notification settings - Fork 11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[24.11] nginx changes for 24.11 #1145
base: fc-24.11-dev
Are you sure you want to change the base?
Commits on Oct 30, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 1add6d3 - Browse repository at this point
Copy the full SHA 1add6d3View commit details -
Configuration menu - View commit details
-
Copy full SHA for a81bbf7 - Browse repository at this point
Copy the full SHA a81bbf7View commit details -
Configuration menu - View commit details
-
Copy full SHA for f8436e7 - Browse repository at this point
Copy the full SHA f8436e7View commit details -
Configuration menu - View commit details
-
Copy full SHA for fe82dfd - Browse repository at this point
Copy the full SHA fe82dfdView commit details -
Configuration menu - View commit details
-
Copy full SHA for a0446a3 - Browse repository at this point
Copy the full SHA a0446a3View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2af7413 - Browse repository at this point
Copy the full SHA 2af7413View commit details -
Configuration menu - View commit details
-
Copy full SHA for 4b6b2e1 - Browse repository at this point
Copy the full SHA 4b6b2e1View commit details -
Configuration menu - View commit details
-
Copy full SHA for d63efda - Browse repository at this point
Copy the full SHA d63efdaView commit details -
Configuration menu - View commit details
-
Copy full SHA for 12393a4 - Browse repository at this point
Copy the full SHA 12393a4View commit details -
Configuration menu - View commit details
-
Copy full SHA for fe094c6 - Browse repository at this point
Copy the full SHA fe094c6View commit details -
Configuration menu - View commit details
-
Copy full SHA for 31ef8dd - Browse repository at this point
Copy the full SHA 31ef8ddView commit details -
- -oss seems to be broken at the moment due to a failing test relying on x-pack. We have to re-check this later. - Use upstream packages.
Configuration menu - View commit details
-
Copy full SHA for c1892ec - Browse repository at this point
Copy the full SHA c1892ecView commit details -
Pull upstream NixOS changes, security fixes and package updates: - awscli2: 2.17.18 -> 2.17.42 - containerd: 1.7.20 -> 1.7.21 - haproxy: 3.0.3 -> 3.0.4 - imagemagick: 7.1.1-37 -> 7.1.1-38 - imagemagick: add willow to passthru.tests - k3s_1_30: 1.30.3+k3s1 -> 1.30.4+k3s1 - libmodsecurity: 3.0.12 -> 3.0.13 - linux_5_15: 5.15.165 -> 5.15.166 - mongodb-5_0: 5.0.28 -> 5.0.29 - nss_latest: 3.103 -> 3.104 - php82: 8.2.22 -> 8.2.23 - php83: 8.3.10 -> 8.3.11 - prometheus: 2.53.1 → 2.54.1 - qemu: 9.0.2 -> 9.1.0 - roundcube: 1.6.8 -> 1.6.9 - runc: 1.1.13 -> 1.1.14 - unifi8: 8.3.32 -> 8.4.59
Configuration menu - View commit details
-
Copy full SHA for de41629 - Browse repository at this point
Copy the full SHA de41629View commit details -
release: add releaseSmall and releaseUntested jobs
This way we get to a channel faster that we can use for development. Before, we used to disable tests and packages to keep `release` green which is error-prone and takes away the feedback we get from failing tests in Hydra.
Configuration menu - View commit details
-
Copy full SHA for bc74421 - Browse repository at this point
Copy the full SHA bc74421View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8fe4746 - Browse repository at this point
Copy the full SHA 8fe4746View commit details -
Remove vendored opensearch service
This was taken from NixOS 23.05 and is obsolete now. Had to remove the code that depends on cfgUpstream.configFile but it's just for informational purposes and we can fix that later.
Configuration menu - View commit details
-
Copy full SHA for 15abaa0 - Browse repository at this point
Copy the full SHA 15abaa0View commit details -
php81: fix php81 build, pick up missing patches for others
Our patch logic used for adding our log patch to older PHP versions left out `patches` which skipped a patch needed for building 8.1.
Configuration menu - View commit details
-
Copy full SHA for 71447a7 - Browse repository at this point
Copy the full SHA 71447a7View commit details -
Downgrade slurm to 23.11, known to work with pyslurm
slurm 24.05 doesn't work with pyslurm at the moment and there's no visible work going on in the repo to make it compatible. Go back to slurm 23.11 in the meantime. If the problem still persists in 1-2 months, we should think about how we can resolve this properly.
Configuration menu - View commit details
-
Copy full SHA for 83bc2fe - Browse repository at this point
Copy the full SHA 83bc2feView commit details -
Pull upstream NixOS changes, security fixes and package updates: - asterisk: 20.9.2 -> 20.9.3 - curl: enable configure flag `--enable-versioned-symbols` - curl: enable flag `--enable-versioned-symbols` (#336712) - nodejs_20: 20.16.0 -> 20.17.0, (#336388) - nodejs_22: 22.6.0 -> 22.8.0, (#336556) - podman: drop slirp4netns which has been replaced by passt - postgresql: move dynamic modules to default output - postgresql: move libecpq to lib output - postgresql: refactor removal of references in bitcode files - postgresql: refactor to simplify condition - postgresql: remove references to llvm-dev on darwin as well - postgresql: split dev output - postgresql: use systemdLibs (#337441) - unifi7: mark insecure due to CVE-2024-42025 (#340341) - vim: 9.1.0689 -> 9.1.0707
Configuration menu - View commit details
-
Copy full SHA for 0538c27 - Browse repository at this point
Copy the full SHA 0538c27View commit details -
Configuration menu - View commit details
-
Copy full SHA for 94b73f1 - Browse repository at this point
Copy the full SHA 94b73f1View commit details -
Pull upstream NixOS changes, security fixes and package updates: - calibre: enable tests (#338867) - containerd: 1.7.21 -> 1.7.22, (#340887) - gitlab-container-registry: 4.7.0 -> 4.9.0 - gitlab: 17.2.4 -> 17.2.5, (#341398) - keycloak: 25.0.4 -> 25.0.5, (#341062) - openssl: expose 'enable-md2' option (#337885) - python39: 3.9.19 -> 3.9.20; python310: 3.10.14 -> 3.10.15; python313: 3.13.0rc1 -> 3.13.0rc2, (#340330) - rabbitmq-server: 3.13.6 -> 3.13.7, (#337489) - subversion: fix darwin (#341232) - telegraf: 1.31.3 -> 1.32.0, (#341515)
Configuration menu - View commit details
-
Copy full SHA for e3fdb87 - Browse repository at this point
Copy the full SHA e3fdb87View commit details -
Configuration menu - View commit details
-
Copy full SHA for 77c52c8 - Browse repository at this point
Copy the full SHA 77c52c8View commit details -
security.acme.defaults.server: customise only for stateVersion <= 24.05
In PL-132659, we've decided to override security.acme.defaults.server from the upstream value to avoid triggering mass letsencrypt account re-registrations. **Re-**registrations are only an issue for existing machines. Freshly bootstrapped systems won't cause any problems. As we cannot be certain that our workaround is going to work for all future NixOS releases, I propose to make this conditional on the VM state version <= 24.05. If ever necessary, this reduces the number of VMs in need of a state migration for the account in the future. PL-133038
Configuration menu - View commit details
-
Copy full SHA for 1c3b0aa - Browse repository at this point
Copy the full SHA 1c3b0aaView commit details -
Configuration menu - View commit details
-
Copy full SHA for c09ed6c - Browse repository at this point
Copy the full SHA c09ed6cView commit details -
Configuration menu - View commit details
-
Copy full SHA for 3dc9261 - Browse repository at this point
Copy the full SHA 3dc9261View commit details -
Pull upstream NixOS changes, security fixes and package updates: - calibre: exclude test test_websocket_basic (#341843) - clamav: 1.4.0 -> 1.4.1 (#341437) - curl: apply patch for CVE-2024-8096 (#342030) - docker-compose: 2.29.2 -> 2.29.3, (#341583) - keycloak: 25.0.5 -> 25.0.6 (#343113) - kubernetes-helm: 3.15.4 -> 3.16.1 (#341294) - nix: 2.18 -> 2.24 (#335342) - strace: 6.10 -> 6.11 - tomcat9: 9.0.93 -> 9.0.94 - tomcat10: 10.1.28 -> 10.1.29 (#341440)
Configuration menu - View commit details
-
Copy full SHA for 62ba7b6 - Browse repository at this point
Copy the full SHA 62ba7b6View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8ee0207 - Browse repository at this point
Copy the full SHA 8ee0207View commit details -
nginx: remove masterUser option
The masterUser option is remove since it caused many problems and brings us closer to upstream. PL-131381
Philipp Neumann committedOct 30, 2024 Configuration menu - View commit details
-
Copy full SHA for fe2f427 - Browse repository at this point
Copy the full SHA fe2f427View commit details -
nginx: pull in upstream changes
This is done to reduce the diff once we switch to the upstream module. It is also part of the preparations for 24.11 PL-131381
Philipp Neumann committedOct 30, 2024 Configuration menu - View commit details
-
Copy full SHA for a18b990 - Browse repository at this point
Copy the full SHA a18b990View commit details -
Philipp Neumann committed
Oct 30, 2024 Configuration menu - View commit details
-
Copy full SHA for ed72765 - Browse repository at this point
Copy the full SHA ed72765View commit details