Running nixpkgs-update (https://nix-community.org/update-bot/) with UPDATE_INFO: checkpolicy 3.10 -> 3.11 https://repology.org/project/checkpolicy/versions
attrpath: checkpolicy
Checking auto update branch...
No auto update branch exists
[version]
[version] updated version and sha256
[rustCrateVersion]
[rustCrateVersion] No cargoHash found
[golangModuleVersion]
[golangModuleVersion] Not a buildGoModule package with vendorHash
[npmDepsVersion]
[npmDepsVersion] No npmDepsHash
[updateScript]
[updateScript] skipping because derivation has no updateScript
Diff after rewrites:
diff --git a/pkgs/by-name/ch/checkpolicy/package.nix b/pkgs/by-name/ch/checkpolicy/package.nix
index b2d6a59daedf..9422f0807d29 100644
--- a/pkgs/by-name/ch/checkpolicy/package.nix
+++ b/pkgs/by-name/ch/checkpolicy/package.nix
@@ -9,12 +9,12 @@
stdenv.mkDerivation (finalAttrs: {
pname = "checkpolicy";
- version = "3.10";
+ version = "3.11";
inherit (libsepol) se_url;
src = fetchurl {
url = "${finalAttrs.se_url}/${finalAttrs.version}/checkpolicy-${finalAttrs.version}.tar.gz";
- hash = "sha256-LZKVHfywkNYXnnojhWYi4Py8Mr4Dvx5grOncnL2hHlk=";
+ hash = "sha256-m4G/zu9/qdAvmHLlanhvND3FjvS1cT3ODVxBbluEzvo=";
};
nativeBuildInputs = [
Successfully finished processing
[check][nixpkgs-review]
## `nixpkgs-review` result
Generated using [`nixpkgs-review`](https://github.com/Mic92/nixpkgs-review).
Command: `nixpkgs-review --extra-nixpkgs-config '{ allowBroken = false; }'`
Commit: `5fd4aa12e09f7eaf75ec6a9cdc997f9403647989`
---
### `x86_64-linux`
:white_check_mark: 5 packages built:
- checkpolicy
- selinux-python
- selinux-refpolicy
- selinux-sandbox
- selinuxPackages.setools
Automatic update generated by [nixpkgs-update](https://github.com/nix-community/nixpkgs-update) tools. This update was made based on information from https://repology.org/project/checkpolicy/versions.
meta.description for checkpolicy is: SELinux policy compiler
meta.homepage for checkpolicy is: http://userspace.selinuxproject.org
###### Updates performed
- Version update
###### To inspect upstream changes
- [Release on GitHub](https://github.com/SELinuxProject/selinux/releases/tag/3.11)
- [Compare changes on GitHub](https://github.com/SELinuxProject/selinux/compare/3.10...3.11)
###### Impact
Checks done
---
- built on NixOS
- The tests defined in `passthru.tests`, if any, passed
- found 3.11 in filename of file in /nix/store/05rkzisk6cjg4xj1w4r3b3d7fbr35q2n-checkpolicy-3.11
---
Rebuild report (if merged into master) (click to expand)
```
13 total rebuild path(s)
11 package rebuild(s)
First fifty rebuilds by attrpath
checkpolicy
selinux-python
selinux-refpolicy
selinux-sandbox
selinuxPackages.checkpolicy
selinuxPackages.selinux-python
selinuxPackages.selinux-refpolicy
selinuxPackages.selinux-sandbox
selinuxPackages.setools
setools
```
Instructions to test this update (click to expand)
---
Either **download from the cache**:
```
nix-store -r /nix/store/05rkzisk6cjg4xj1w4r3b3d7fbr35q2n-checkpolicy-3.11 \
--option binary-caches 'https://cache.nixos.org/ https://nixpkgs-update-cache.nix-community.org/' \
--option trusted-public-keys '
nixpkgs-update-cache.nix-community.org-1:U8d6wiQecHUPJFSqHN9GSSmNkmdiFW7GW7WNAnHW0SM=
cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=
'
```
(The nixpkgs-update cache is only trusted for this store-path realization.)
For the cached download to work, your user must be in the `trusted-users` list or you can use `sudo` since root is effectively trusted.
Or, **build yourself**:
```
nix-build -A checkpolicy https://github.com/r-ryantm/nixpkgs/archive/5fd4aa12e09f7eaf75ec6a9cdc997f9403647989.tar.gz
```
Or:
```
nix build github:r-ryantm/nixpkgs/5fd4aa12e09f7eaf75ec6a9cdc997f9403647989#checkpolicy
```
After you've downloaded or built it, look at the files and if there are any, run the binaries:
```
ls -la /nix/store/05rkzisk6cjg4xj1w4r3b3d7fbr35q2n-checkpolicy-3.11
ls -la /nix/store/05rkzisk6cjg4xj1w4r3b3d7fbr35q2n-checkpolicy-3.11/bin
```
---
### Pre-merge build results
We have automatically built all packages that will get rebuilt due to
this change.
This gives evidence on whether the upgrade will break dependent packages.
Note sometimes packages show up as _failed to build_ independent of the
change, simply because they are already broken on the target branch.
## `nixpkgs-review` result
Generated using [`nixpkgs-review`](https://github.com/Mic92/nixpkgs-review).
Command: `nixpkgs-review --extra-nixpkgs-config '{ allowBroken = false; }'`
Commit: `5fd4aa12e09f7eaf75ec6a9cdc997f9403647989`
---
### `x86_64-linux`
:white_check_mark: 5 packages built:
- checkpolicy
- selinux-python
- selinux-refpolicy
- selinux-sandbox
- selinuxPackages.setools
---
###### Maintainer pings
cc @RossComputerGuy @numinit for [testing](https://github.com/nix-community/nixpkgs-update/blob/main/doc/nixpkgs-maintainer-faq.md#r-ryantm-opened-a-pr-for-my-package-what-do-i-do).
> [!TIP]
> As a maintainer, if your package is located under `pkgs/by-name/*`, you can comment **`@NixOS/nixpkgs-merge-bot merge`** to automatically merge this update using the [`nixpkgs-merge-bot`](https://github.com/NixOS/nixpkgs/blob/master/ci/README.md#nixpkgs-merge-bot).
https://api.github.com/repos/NixOS/nixpkgs/pulls/537627