Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: audit 4.2 -> 4.2.1 https://github.com/linux-audit/audit-userspace/releases attrpath: audit Checking auto update branch... [version] [version] skipping because derivation has updateScript [rustCrateVersion] [rustCrateVersion] No cargoHash found [golangModuleVersion] [golangModuleVersion] Not a buildGoModule package with vendorHash [npmDepsVersion] [npmDepsVersion] No npmDepsHash [updateScript] [updateScript] Success [updateScript] this derivation will be built: /nix/store/kn1y5lf10fagddxp3vgyba1zrgph5gwf-packages.json.drv building '/nix/store/kn1y5lf10fagddxp3vgyba1zrgph5gwf-packages.json.drv'... Going to be running update for following packages: - audit-4.2 Press Enter key to continue... Running update for: Enqueuing group of 1 packages - audit-4.2: UPDATING ... - audit-4.2: DONE. Packages updated! Diff after rewrites: diff --git a/pkgs/by-name/au/audit/package.nix b/pkgs/by-name/au/audit/package.nix index 657e74647d6f..da35f91c2092 100644 --- a/pkgs/by-name/au/audit/package.nix +++ b/pkgs/by-name/au/audit/package.nix @@ -30,13 +30,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "audit"; - version = "4.2"; + version = "4.2.1"; src = fetchFromGitHub { owner = "linux-audit"; repo = "audit-userspace"; tag = "v${finalAttrs.version}"; - hash = "sha256-poldhsF+ccutCxK7KE/gYpxa1x3wUQJWoCwU6pGFj6A="; + hash = "sha256-W8VyeOYQGPAvvmQUe3F22u5ldWwIuxrVJ/sXyu0Qrl4="; }; postPatch = '' An auto update branch exists with message `audit: 4.1.2-unstable-2025-09-06 -> 4.1.4`. New version is 4.2.1. The auto update branch does not match or exceed the new version. Old version 4.2" not present in staging derivation file with contents: { lib, stdenv, fetchFromGitHub, autoreconfHook, bash, bashNonInteractive, buildPackages, linuxHeaders, python3Packages, swig, libcap_ng, installShellFiles, makeWrapper, gawk, gnugrep, coreutils, enablePython ? !stdenv.hostPlatform.isStatic && stdenv.hostPlatform.parsed.cpu.bits == stdenv.buildPlatform.parsed.cpu.bits, # passthru nix-update-script, testers, nixosTests, pkgsStatic ? { }, # CI has allowVariants = false, in which case pkgsMusl would not be passed. So, instead add a default here. pkgsMusl ? { }, callPackage, }: stdenv.mkDerivation (finalAttrs: { pname = "audit"; version = "4.2.1"; src = fetchFromGitHub { owner = "linux-audit"; repo = "audit-userspace"; tag = "v${finalAttrs.version}"; hash = "sha256-W8VyeOYQGPAvvmQUe3F22u5ldWwIuxrVJ/sXyu0Qrl4="; }; postPatch = '' substituteInPlace bindings/swig/src/auditswig.i \ --replace-fail "/usr/include/linux/audit.h" \ "${linuxHeaders}/include/linux/audit.h" '' + lib.optionalString (enablePython && finalAttrs.finalPackage.doCheck) '' patchShebangs auparse/test/auparse_test.py ''; outputs = [ "bin" "lib" "dev" "out" "man" "scripts" ]; strictDeps = true; depsBuildBuild = [ buildPackages.stdenv.cc ]; nativeBuildInputs = [ autoreconfHook installShellFiles makeWrapper ] ++ lib.optionals enablePython [ python3Packages.python # for python3-config swig ]; buildInputs = [ bash libcap_ng ]; configureFlags = [ # z/OS plugin is not useful on Linux, and pulls in an extra openldap # dependency otherwise "--disable-zos-remote" # remove legacy start/stop scripts to remove a bash dependency in $lib # People interested in logging auditd interactions (e.g. for compliance) can start/stop audit using `auditctl --signal` # See also https://github.com/linux-audit/audit-userspace?tab=readme-ov-file#starting-and-stopping-the-daemon "--disable-legacy-actions" "--with-arm" "--with-aarch64" "--with-riscv" "--with-io_uring" # allows putting audit files in /run/audit, which removes the requirement # to wait for tmpfiles to set up the /var/run -> /run symlink "--runstatedir=/run" # capability dropping, currently mostly for plugins as those get spawned as root # see auditd-plugins(5) "--with-libcap-ng=yes" (lib.withFeature enablePython "python3") ]; __structuredAttrs = true; # lib output is part of the mandatory nixos system closure, so avoid bash here outputChecks.lib.disallowedRequisites = [ bash bashNonInteractive ]; # bin output is used if audit is enabled, becoming part of the system closure. outputChecks.bin.disallowedRequisites = [ bash bashNonInteractive ]; nativeCheckInputs = lib.optionals enablePython [ python3Packages.pythonImportsCheckHook ]; pythonImportsCheck = [ "audit" ]; doCheck = false; postInstall = '' installShellCompletion --bash init.d/audit.bash_completion ''; # augenrules is a bit broken, but may be helpful to collect audit rules in a builder. # It is not required on a running system, it can just go into its own output. # audit-rules.service relies on augenrules, and is not useful on a nixos system. # It is intended to collect rule files from /etc/audit/rules.d, which we don't set up. # Instead, we load audit rules in a dedicated module. postFixup = '' moveToOutput bin/augenrules $scripts wrapProgram $scripts/bin/augenrules \ --prefix PATH : ${ lib.makeBinPath [ gawk gnugrep coreutils ] } rm $out/lib/systemd/system/audit-rules.service ''; enableParallelBuilding = true; passthru = { updateScript = nix-update-script { }; testsuite = callPackage ./testsuite.nix { }; tests = { musl = pkgsMusl.audit or null; static = pkgsStatic.audit or null; pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; inherit (nixosTests) audit audit-testsuite utmp; # Broken on a hardened kernel package = finalAttrs.finalPackage.overrideAttrs (previousAttrs: { pname = previousAttrs.pname + "-test"; doCheck = true; }); }; }; meta = { homepage = "https://people.redhat.com/sgrubb/audit/"; description = "Audit Library"; changelog = "https://github.com/linux-audit/audit-userspace/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.gpl2Plus; maintainers = with lib.maintainers; [ grimmauld ]; teams = [ lib.teams.security-review ]; pkgConfigModules = [ "audit" "auparse" ]; platforms = lib.platforms.linux; identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "linux_audit_project" finalAttrs.version // { product = "linux_audit"; }; }; })