Roger Qiu
bb6a5b079f
nixos/xserver: Changed xrandrHeads to support corresponding monitor section configuration in Xorg
2017-04-21 22:01:29 +10:00
Jörg Thalheim
c84dd4f09e
Merge pull request #24526 from miltador/jetbrains
...
idea: numerous fixes and improvements
2017-04-11 13:56:20 +02:00
Carles Pagès
d5a623cb39
Update 17.03 release notes
2017-04-03 22:54:34 +02:00
Théo Zimmermann
72070e6dfc
doc: improve "getting the sources" chapter
2017-04-01 17:56:29 +02:00
Vasiliy Solovey
4fc2a86795
rl-notes 17.09: add note about idea -> jetbrains renaming
2017-04-01 12:46:27 +03:00
Robin Gloster
cbd6fb1b3a
Release Notes: tracking UIDs/GIDs is in 17.09
2017-03-31 15:51:37 +02:00
Eelco Dolstra
e241fb87a1
Update 17.03 release notes
2017-03-31 15:00:30 +02:00
Robin Gloster
163668f6c4
Release Notes 17.03: update on master
2017-03-30 22:52:08 +02:00
Joachim Fasting
c504e14c87
rl-notes 17.03: add notes about changes to the dnscrypt-proxy interface
...
(cherry picked from commit 9613677176
)
2017-03-30 13:36:08 +02:00
Joachim Fasting
8427222eca
rl-notes 17.03: add note about pre-NSS dnscrypt-proxy
...
(cherry picked from commit de5d4dc147
)
2017-03-29 00:05:48 +02:00
Christine Koppelt
e5c927cb8d
NixOS Manual: Update version numbers
2017-03-25 20:14:04 +01:00
goibhniu
170b8da281
Merge pull request #24304 from matklad/uefi-install-docs
...
docs: clarify UEFI bootloader setup
2017-03-25 13:08:06 +01:00
Aleksey Kladov
edac1d3e7a
docs: clarify UEFI bootloader setup
2017-03-25 00:48:27 +03:00
Vladimír Čunát
c1a9dc3d37
Merge branch 'master' into staging
2017-03-23 13:31:28 +01:00
Eelco Dolstra
86721a5f78
Allow attaching to non-child processes by default
...
The inability to run strace or gdb is the kind of
developer-unfriendliness that we're used to from OS X, let's not do it
on NixOS.
This restriction can be re-enabled by setting
boot.kernel.sysctl."kernel.yama.ptrace_scope" = 1;
It might be nice to have a NixOS module for enabling hardened defaults.
Xref #14392 .
Thanks @abbradar.
2017-03-21 18:48:35 +01:00
Carlos D
e6a02918ce
Expand on creating USB bootable for OS X
2017-03-21 17:31:10 +01:00
Robin Gloster
c93eb74e6a
Merge pull request #23838 from mayflower/remove-md5
...
fetch-*: remove md5 support
2017-03-21 13:27:51 +01:00
Frederik Rietdijk
94eb74eaad
Merge remote-tracking branch 'upstream/master' into HEAD
2017-03-21 13:04:37 +01:00
Frederik Rietdijk
4263c53f66
Python changelog
2017-03-21 11:05:03 +01:00
Robin Gloster
5e0f932de0
rl-notes 17.03: info on python module location
...
closes #11567
2017-03-20 23:28:51 +01:00
Robin Gloster
c066dc8416
fetch-*: add md5 support removal to rl-notes
2017-03-20 22:26:02 +01:00
Thomas Tuegel
d458b5401a
nixos/fontconfig: add Changelog message about FreeType update
2017-03-20 10:39:48 -05:00
Franz Pletz
8ab2d2ee27
rmilter service: support only one socket
2017-03-17 23:00:34 +01:00
Graham Christensen
0705346de4
Merge pull request #23512 from matthiasbeyer/doc-fix-xfce
...
doc: Remove indention from program listings
2017-03-06 17:33:13 -05:00
Matthias Beyer
87f57de8e5
Wrap command in <command>
2017-03-05 14:21:45 +01:00
Matthias Beyer
0a18a56375
nixos doc xfce: Tabs -> spaces
2017-03-05 14:20:49 +01:00
Matthias Beyer
1e3dec3baa
nixos doc xfce: Fix missing space
2017-03-05 14:20:48 +01:00
Matthias Beyer
c56587eb30
doc: Remove indention from program listings
2017-03-05 14:20:47 +01:00
Daiderd Jordan
35a65a6704
release-nodes: move disabledModules to 17.09
2017-03-05 14:17:00 +01:00
Thomas Tuegel
044c7d091b
Merge pull request #23388 from ttuegel/nixos-plasma5
...
NixOS: Plasma 5 tests and warnings
2017-03-03 09:50:08 -06:00
Thomas Tuegel
ecb65eceaa
nixos/doc/manual: rename plasma5 desktop
2017-03-03 07:29:16 -06:00
Daiderd Jordan
d88721e440
modules: add support for module replacement with disabledModules
...
This is based on a prototype Nicolas B. Pierron worked on during a
discussion we had at FOSDEM.
A new version with a workaround for problems of the reverted original.
Discussion: 3f2566689
2017-03-03 13:45:22 +01:00
Vladimír Čunát
fcec3e1c72
Revert "modules: add support for module replacement with disabledModules"
...
This reverts commit 3f2566689d
for now.
Evaluation of the tested job got broken, blocking nixos-unstable.
2017-03-01 21:56:01 +01:00
Vladimír Čunát
b43614a6bb
Merge branch 'staging'
...
(Truly, this time :-)
2017-03-01 11:34:44 +01:00
Daiderd Jordan
3f2566689d
modules: add support for module replacement with disabledModules
...
This is based on a prototype Nicolas B. Pierron worked on during a
discussion we had at FOSDEM.
2017-02-28 00:14:48 +01:00
Vladimír Čunát
81b43ccd57
17.09 release notes: fix typos
2017-02-27 23:03:16 +01:00
Robin Gloster
755902b543
release-notes: add 17.09
2017-02-27 20:46:34 +01:00
Vladimír Čunát
a1919db7cd
Merge branch 'master' into staging
2017-02-27 20:15:27 +01:00
Frederik Rietdijk
f69292ddc0
Python: explain deterministic builds in release notes
2017-02-26 14:51:26 +01:00
Graham Christensen
a9c875fc2e
nixpkgs: allow packages to be marked insecure
...
If a package's meta has `knownVulnerabilities`, like so:
stdenv.mkDerivation {
name = "foobar-1.2.3";
...
meta.knownVulnerabilities = [
"CVE-0000-00000: remote code execution"
"CVE-0000-00001: local privilege escalation"
];
}
and a user attempts to install the package, they will be greeted with
a warning indicating that maybe they don't want to install it:
error: Package ‘foobar-1.2.3’ in ‘...default.nix:20’ is marked as insecure, refusing to evaluate.
Known issues:
- CVE-0000-00000: remote code execution
- CVE-0000-00001: local privilege escalation
You can install it anyway by whitelisting this package, using the
following methods:
a) for `nixos-rebuild` you can add ‘foobar-1.2.3’ to
`nixpkgs.config.permittedInsecurePackages` in the configuration.nix,
like so:
{
nixpkgs.config.permittedInsecurePackages = [
"foobar-1.2.3"
];
}
b) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add
‘foobar-1.2.3’ to `permittedInsecurePackages` in
~/.config/nixpkgs/config.nix, like so:
{
permittedInsecurePackages = [
"foobar-1.2.3"
];
}
Adding either of these configurations will permit this specific
version to be installed. A third option also exists:
NIXPKGS_ALLOW_INSECURE=1 nix-build ...
though I specifically avoided having a global file-based toggle to
disable this check. This way, users don't disable it once in order to
get a single package, and then don't realize future packages are
insecure.
2017-02-24 07:41:05 -05:00
Franz Pletz
9b81dcfda2
nixos/release-notes: fix typos
2017-02-22 08:45:30 +01:00
Jörg Thalheim
27d4f8c717
Merge pull request #23046 from Zimmi48/patch-2
...
nixos/manual/networkmanager: add info on nm-applet
2017-02-22 01:40:50 +01:00
Jörg Thalheim
6a044f1841
Merge pull request #23045 from Zimmi48/patch-1
...
nixos/manual/xserver: propose more alternatives
2017-02-22 01:38:25 +01:00
Jörg Thalheim
5b14e91717
Merge pull request #22822 from Mic92/iputils
...
iputils: 20151218 -> 20161105
2017-02-22 00:37:13 +01:00
Jörg Thalheim
45719174c3
nixos/release-notes: mention iputils changes
2017-02-22 00:32:52 +01:00
Théo Zimmermann
0994d6af9d
nixos/manual/networkmanager: add info on nm-applet
2017-02-21 15:20:10 +01:00
Théo Zimmermann
361d730f35
nixos/manual/xserver: propose more alternatives
2017-02-21 14:56:26 +01:00
Lorenzo Manacorda
2c4d9c9228
manual: Add link to config section ( #22994 )
...
Add link to "Configuration" chapter from "Changing the Configuration" section.
Also, fix grammar error.
(cherry picked from commit a585f987fa
)
2017-02-20 14:32:49 +01:00
Graham Christensen
7483ba0932
Revert "nix-daemon: default useSandbox to true"
...
This reverts commit d0a086770a
.
2017-02-14 14:13:39 -05:00
Graham Christensen
3be1388963
Merge pull request #22767 from grahamc/sandbox-by-default
...
nix-daemon: default useSandbox to true
2017-02-14 13:57:44 -05:00