The `sparseCheckout` argument allows the user to specify directories or
patterns of files, which Git uses to filter files it should check-out.
Git expects a multi-line string on stdin ("newline-delimited list", see
`git-sparse-checkout(1)`), but within nixpkgs it is more consistent to
use a list of strings instead. The list elements are joined to a
multi-line string only before passing it to the builder script.
A deprecation warning is emitted if a (multi-line) string is passed to
`sparseCheckout`, but for the time being it is still accepted.
30 KiB
Release 22.11 (“Raccoon”, 2022.11/??)
Support is planned until the end of June 2023, handing over to 23.05.
Highlights
In addition to numerous new and upgraded packages, this release has the following highlights:
-
GNOME has been upgraded to 43. Please take a look at their Release Notes for details.
-
During cross-compilation, tests are now executed if the test suite can be executed by the build platform. This is the case when doing “native” cross-compilation where the build and host platforms are largely the same, but the nixpkgs' cross compilation infrastructure is used, e.g.
pkgsStaticandpkgsLLVM. Another possibility is that the build platform is a superset of the host platform, e.g. when cross-compiling fromx86_64-unknown-linuxtoi686-unknown-linux. The predicate gating test suite execution is the newly addedcanExecutepredicate: You can e.g. check ifstdenv.buildPlatformcan execute binaries built forstdenv.hostPlatform(i.e. produced bystdenv.cc) by evaluatingstdenv.buildPlatform.canExecute stdenv.hostPlatform. -
The
nixpkgs.hostPlatformandnixpkgs.buildPlatformoptions have been added. These cover and override thenixpkgs.{system,localSystem,crossSystem}options.hostPlatformis the platform or "system" string of the NixOS system described by the configuration.buildPlatformis the platform that is responsible for building the NixOS configuration. It defaults to thehostPlatform, for a non-cross build configuration. To cross compile, setbuildPlatformto a different value.
The new options convey the same information, but with fewer options, and following the Nixpkgs terminology.
The existing options
nixpkgs.{system,localSystem,crossSystem}have not been formally deprecated, to allow for evaluation of the change and to allow for a transition period so that in time the ecosystem can switch without breaking compatibility with any supported NixOS release. -
emacsenables native compilation which means:- emacs packages from nixpkgs, builtin or not, will do native compilation ahead of time so you can enjoy the benefit of native compilation without compiling them on you machine;
- emacs packages from somewhere else, e.g.
package-install, will do asynchronously deferred native compilation. If you do not want this, maybe to avoid CPU consumption for compilation, you can use(setq native-comp-deferred-compilation nil)to disable it while still enjoy the benefit of native compilation for packages from nixpkgs.
-
nixos-generate-confignow generates configurations that can be built in pure mode. This is achieved by setting the newnixpkgs.hostPlatformoption.You may have to unset the
systemparameter inlib.nixosSystem, or similarly remove definitions of thenixpkgs.{system,localSystem,crossSystem}options.Alternatively, you can remove the
hostPlatformline and use NixOS like you would in NixOS 22.05 and earlier. -
PHP now defaults to PHP 8.1, updated from 8.0.
-
Perl has been updated to 5.36, and its core module
HTTP::Tinywas patched to verify SSL/TLS certificates by default. -
Improved performances of
lib.closePropagationwhich was previously quadratic. This is used in e.g.ghcWithPackages. Please see backward incompatibilities notes below. -
Cinnamon has been updated to 5.4. While at it, the cinnamon module now defaults to blueman as bluetooth manager and slick-greeter as lightdm greeter to match upstream.
-
OpenSSL now defaults to OpenSSL 3, updated from 1.1.1.
-
An image configuration and generator has been added for Linode images, largely based on the present GCE configuration and image.
-
hardware.nvidiahas a new optionopenthat can be used to opt in the opensource version of NVIDIA kernel driver. Note that the driver's support for GeForce and Workstation GPUs is still alpha quality, see NVIDIA Releases Open-Source GPU Kernel Modules for the official announcement.
New Services
-
appvm, Nix based app VMs. Available as virtualisation.appvm.
-
[xray] (https://github.com/XTLS/Xray-core), a fully compatible v2ray-core replacement. Features XTLS, which when enabled on server and client, brings UDP FullCone NAT to proxy setups. Available as services.xray.
-
syncstorage-rs, a self-hostable sync server for Firefox. Available as services.firefox-syncserver.
-
dragonflydb, a modern replacement for Redis and Memcached. Available as services.dragonflydb.
-
Komga, a free and open source comics/mangas media server. Available as services.komga.
-
Tandoor Recipes, a self-hosted multi-tenant recipe collection. Available as services.tandoor-recipes.
-
HBase cluster, a distributed, scalable, big data store. Available as services.hadoop.hbase.
-
Please, a Sudo clone written in Rust. Available as security.please
-
Sachet, an SMS alerting tool for the Prometheus Alertmanager. Available as services.prometheus.sachet.
-
infnoise, a hardware True Random Number Generator dongle. Available as services.infnoise.
-
kthxbye, an alert acknowledgement management daemon for Prometheus Alertmanager. Available as services.kthxbye
-
kanata, a tool to improve keyboard comfort and usability with advanced customization. Available as services.kanata.
-
karma, an alert dashboard for Prometheus Alertmanager. Available as services.karma
-
languagetool, a multilingual grammar, style, and spell checker. Available as services.languagetool.
-
OpenRGB, a FOSS tool for controlling RGB lighting. Available as services.hardware.openrgb.enable.
-
Outline, a wiki and knowledge base similar to Notion. Available as services.outline.
-
ntfy.sh, a push notification service. Available as services.ntfy-sh
-
alps, a simple and extensible webmail. Available as services.alps.
-
endlessh, an SSH tarpit. Available as services.endlessh.
-
endlessh-go, an SSH tarpit that exposes Prometheus metrics. Available as services.endlessh-go.
-
Garage, a simple object storage server for geodistributed deployments, alternative to MinIO. Available as services.garage.
-
netbird, a zero configuration VPN. Available as services.netbird.
-
persistent-evdev, a daemon to add virtual proxy devices that mirror a physical input device but persist even if the underlying hardware is hot-plugged. Available as services.persistent-evdev.
-
schleuder, a mailing list manager with PGP support. Enable using services.schleuder.
-
Dolibarr, an enterprise resource planning and customer relationship manager. Enable using services.dolibarr.
-
FreshRSS, a free, self-hostable RSS feed aggregator. Available as services.freshrss.
-
expressvpn, the CLI client for ExpressVPN. Available as services.expressvpn.
-
merecat, a small and easy HTTP server based on thttpd. Available as services.merecat
-
go-autoconfig, IMAP/SMTP autodiscover server. Available as services.go-autoconfig.
-
tmate-ssh-server, server side part of tmate. Available as services.tmate-ssh-server.
-
Grafana Tempo, a distributed tracing store. Available as services.tempo.
-
AusweisApp2, the authentication software for the German ID card. Available as programs.ausweisapp.
-
Patroni, a template for PostgreSQL HA with ZooKeeper, etcd or Consul. Available as services.patroni.
-
Prometheus IPMI exporter, an IPMI exporter for Prometheus. Available as services.prometheus.exporters.ipmi.
-
WriteFreely, a simple blogging platform with ActivityPub support. Available as services.writefreely.
-
Listmonk, a self-hosted newsletter manager. Enable using services.listmonk.
-
Uptime Kuma, a fancy self-hosted monitoring tool. Available as services.uptime-kuma.
Backward Incompatibilities
-
Nixpkgs now requires Nix 2.3 or newer.
-
The
isCompatiblepredicate checking CPU compatibility is no longer exposed by the platform sets generated usinglib.systems.elaborate. In most cases you will want to use the newcanExecutepredicate instead which also considers the kernel / syscall interface. It is briefly described in the release's highlights section.lib.systems.parse.isCompatiblestill exists, but has changed semantically: Architectures with differing endianness modes are no longer considered compatible. -
ngrokhas been upgraded from 2.3.40 to 3.0.4. Please see the upgrade guide and changelog. Notably, breaking changes are that the config file format has changed and support for single hypen arguments was dropped. -
i18n.supportedLocalesis now by default only generated with the locales set ini18n.defaultLocaleandi18n.extraLocaleSettings. This got partially copied over from the minimal profile and reduces the final system size by up to 200MB. If you require all locales installed set the option to[ "all" ]. -
Deprecated settings
logrotate.pathsandlogrotate.extraConfighave been removed. Please convert any uses to services.logrotate.settings instead. -
The
isPowerPCpredicate, found onplatformattrsets (hostPlatform,buildPlatform,targetPlatform, etc) has been removed in order to reduce confusion. The predicate was was defined such that it matches only the 32-bit big-endian members of the POWER/PowerPC family, despite having a name which would imply a broader set of systems. If you were using this predicate, you can replacefoo.isPowerPCwith(with foo; isPower && is32bit && isBigEndian). -
The
fetchgitfetcher now uses cone mode by default for sparse checkouts. Non-cone mode can be enabled by passingnonConeMode = true, but note that non-cone mode is deprecated and this option may be removed alongside a future Git update without notice. -
The
fetchgitfetcher supports sparse checkouts via thesparseCheckoutoption. This used to accept a multi-line string with directories/patterns to check out, but now requires a list of strings. -
opensshwas updated to version 9.1, disabling the generation of DSA keys when usingssh-keygen -Aas they are insecure. Also,SetEnvdirectives inssh_configandsshd_configare now first-match-wins -
bsp-layoutno longer uses the commandcycleto switch to other window layouts, as it got replaced by the commandspreviousandnext. -
The Barco ClickShare driver/client package
pkgs.clickshare-csc1and the optionprograms.clickshare-csc1.enablehave been removed, as it requiresqt4, which reached its end-of-life 2015 and will no longer be supported by nixpkgs. According to Barco many of their base unit models can be used with Google Chrome and the Google Cast extension. -
services.hbasehas been renamed toservices.hbase-standalone. For production HBase clusters, useservices.hadoop.hbaseinstead. -
The
p4package now only includes the open-source Perforce Helix Core command-line client and APIs. It no longer installs the unfree Helix Core Server binariesp4d,p4broker, andp4p. To install the Helix Core Server binaries, use thep4dpackage instead. -
The
coqpackage and versioned variants starting atcoq_8_14no longer include CoqIDE, which is now available throughcoqPackages.coqide. It is still possible to get CoqIDE as part of thecoqpackage by overriding thebuildIdeargument of the derivation. -
PHP 7.4 is no longer supported due to upstream not supporting this version for the entire lifecycle of the 22.11 release.
-
The ipfs package and module were renamed to kubo. The kubo module now uses an RFC42-style
settingsoption instead ofextraConfigand thegatewayAddress,apiAddressandswarmAddressoptions were renamed. Using the old names will print a warning but still work. -
pkgs.cosigndoes not provide thecosignedbinary anymore. Thesgetbinary has been moved into its own package. -
Emacs now uses the Lucid toolkit by default instead of GTK because of stability and compatibility issues. Users who still wish to remain using GTK can do so by using
emacs-gtk. -
riak package removed along with
services.riakmodule, due to lack of maintainer to update the package. -
ppd files in
pkgs.cups-drv-rastertosag-gdiare now gzipped. If you refer to such a ppd file with its path (e.g. via hardware.printers.ensurePrinters) you will need to append.gzto the path. -
xow package removed along with the
hardware.xowmodule, due to the project being deprecated in favor ofxone, which is available via thehardware.xonemodule. -
dd-agent package removed along with the
services.dd-agentmodule, due to the project being deprecated in favor ofdatadog-agent, which is available via theservices.datadog-agentmodule. -
teleporthas been upgraded to major version 10. Please see upstream upgrade instructions and release notes. -
lib.closePropagationnow needs that all gathered sets have anoutPathattribute. -
lemmy module option
services.lemmy.settings.database.createLocallymoved toservices.lemmy.database.createLocally. -
virtlyst package and
services.virtlystmodule removed, due to lack of maintainers. -
The
nix.checkConfigoption now fully disables the config check. The newnix.checkAllErrorsoption behaves likenix.checkConfigpreviously did. -
generateOptparseApplicativeCompletionsandgenerateOptparseApplicativeCompletionfromhaskell.lib.compose(andhaskell.lib) have been deprecated in favor ofgenerateOptparseApplicativeCompletions(plural!) as provided by the haskell package sets (sohaskellPackages.generateOptparseApplicativeCompletionsetc.). The latter allows for cross-compilation (by automatically disabling generation of completion in the cross case). For it to work properly you need to make sure that the function comes from the same context as the package you are trying to override, i.e. always use the same package set as your package is coming from or – even better – useself.generateOptparseApplicativeCompletionsif you are overriding a haskell package set. The old functions are retained for backwards compatibility, but yield are warning. -
The
services.graphite.apiandservices.graphite.beaconNixOS options, and thepython3.pkgs.graphite_api,python3.pkgs.graphite_beaconandpython3.pkgs.influxgraphpackages, have been removed due to lack of upstream maintenance. -
The
tracebinary fromperf-linuxpackage has been removed, due to being a duplicate of theperfbinary. -
The
awspackage has been removed due to being abandoned by the upstream. It is recommended to useawscliorawscli2instead. -
The CEmu TI-84 Plus CE emulator package has been renamed to
cemu-ti. The Cemu Wii U emulator is now packaged ascemu. -
systemd-networkdv250 deprecated, renamed, and moved some sections and settings which leads to the following breaking module changes:systemd.network.networks.<name>.dhcpV6PrefixDelegationConfigis renamed tosystemd.network.networks.<name>.dhcpPrefixDelegationConfig.systemd.network.networks.<name>.dhcpV6Configno longer accepts theForceDHCPv6PDOtherInformation=setting. Please use theWithoutRA=andUseDelegatedPrefix=settings in yoursystemd.network.networks.<name>.dhcpV6Configand theDHCPv6Client=setting in yoursystemd.network.networks.<name>.ipv6AcceptRAConfigto control when the DHCPv6 client is started and how the delegated prefixes are handled by the DHCPv6 client.systemd.network.networks.<name>.networkConfigno longer accepts theIPv6Token=setting. Use theToken=setting in yoursystemd.network.networks.<name>.ipv6AcceptRAConfiginstead. Thesystemd.network.networks.<name>.ipv6Prefixes.*.ipv6PrefixConfignow also accepts theToken=setting.
-
The
meta.mainProgramattribute of packages inwineWowPackagesnow defaults to"wine64". -
The
paperlessmodule now defaultsPAPERLESS_TIME_ZONEto your configured system timezone. -
The top-level
termonad-with-packagesalias fortermonadhas been removed. -
(Neo)Vim can not be configured with
configure.pathogenanymore to reduce maintainance burden. Useconfigure.packagesinstead. -
Neovim can not be configured with plug anymore (still works for vim).
-
The
adguardhomemodule no longer useshostandportoptions, usesettings.bind_hostandsettings.bind_portinstead. -
The default
kopsversion is now 1.25.1 and support for 1.22 and older has been dropped. -
k3sno longer supports docker as runtime due to upstream dropping support. -
cassandra_2_1andcassandra_2_2have been removed. Please update tocassandra_3_11orcassandra_3_0. See the changelog for more information about the upgrade process. -
mysql57has been removed. Please update tomysql80ormariadb. See the upgrade guide for more information. -
Consequently,
cqrlogandamoroknow usemariadbinstead ofmysql57for their embedded databases. Runningmysql_upgrademay be neccesary. -
k3ssupportsclusterInitoption, and it is enabled by default, for servers. -
percona-server56has been removed. Please migrate tomysqlormariadbif possible. -
styluano longer acceptslua52SupportandluauSupportoverrides, usefeaturesinstead, which defaults to[ "lua54" "luau" ]. -
pkgs.fetchNextcloudApphas been rewritten to circumvent impurities in e.g. tarballs from GitHub and to make it easier to apply patches. This means that your hashes are out-of-date and the (previously required) attributesnameandversionare no longer accepted.
Other Notable Changes
-
The
xplrpackage has been updated from 0.18.0 to 0.19.0, which brings some breaking changes. See the upstream release notes for more details. -
github-runnergained support for ephemeral runners and registrations using a personal access token (PAT) instead of a registration token. Seeservices.github-runner.ephemeralandservices.github-runner.tokenFilefor details. -
A new module was added for the Saleae Logic device family, providing the options
hardware.saleae-logic.enableandhardware.saleae-logic.package. -
ZFS module will not allow hibernation by default, this is a safety measure to prevent data loss cases like the ones described at OpenZFS/260 and OpenZFS/12842. Use the
boot.zfs.allowHibernationoption to configure this behaviour. -
mastodonnow automatically removes remote media attachments older than 30 days. This is configurable throughservices.mastodon.mediaAutoRemove. -
The Redis module now disables RDB persistence when
services.redis.servers.<name>.save = []instead of using the Redis default. -
Neo4j was updated from version 3 to version 4. See this migration guide on how to migrate your Neo4j instance.
-
The
networking.wireguardmodule now can set the mtu on interfaces and tag its packets with an fwmark. -
The option
overrideStrategywas added to the different systemd unit options (systemd.services.<name>,systemd.sockets.<name>, …) to allow enforcing the creation of a dropin file, rather than the main unit file, by setting it toasDropin. This is useful in cases where the existence of the main unit file is not known to Nix at evaluation time, for example when the main unit file is provided by adding a package tosystemd.packages. See the fix proposed in NixOS's systemd abstraction doesn't work with systemd template units for an example. -
The
polymcpackage has been removed due to a rogue maintainer. It has been replaced byprismlauncher, a fork by the rest of the maintainers. For more details, see the pull request that made this change and this issue detailing the vulnerability. Users with existing installations should rename~/.local/share/polymcto~/.local/share/PrismLauncher. The main config file's path has also moved from~/.local/share/polymc/polymc.cfgto~/.local/share/PrismLauncher/prismlauncher.cfg. -
The
bloatpackage has been updated from unstable-2022-03-31 to unstable-2022-10-25, which brings a breaking change. See this upstream commit message for details. -
The
services.matrix-synapsesystemd unit has been hardened. -
The
services.grafanaoptions were converted to a RFC 0042 configuration. -
The
services.grafana.provision.datasourcesandservices.grafana.provision.dashboardsoptions were converted to a RFC 0042 configuration. They also now support specifying the provisioning YAML file withpathoption. -
The
services.grafana.provision.alertingoption was added. It includes suboptions for every alerting-related objects (with the exception ofnotifiers), which means it's now possible to configure modern Grafana alerting declaratively. -
Matrix Synapse now requires entries in the
state_group_edgestable to be unique, in order to prevent accidentally introducing duplicate information (for example, because a database backup was restored multiple times). If your Synapse database already has duplicate rows in this table, this could fail with an error and require manual remediation. -
The
diamondpackage has been update from 0.8.36 to 2.0.15. See the upstream release notes for more details. -
The
guakepackage has been updated from 3.6.3 to 3.9.0, see the changelog for more details. -
dockerTools.buildImagedeprecates the misunderstoodcontentsparameter, in favor ofcopyToRoot. UsecopyToRoot = buildEnv { ... };or similar if you intend to add packages to/bin. -
memtest86+ was updated from 5.00-coreboot-002 to 6.00-beta2. It is now the upstream version from https://www.memtest.org/, as coreboot's fork is no longer available.
-
Option descriptions, examples, and defaults writting in DocBook are now deprecated. Using CommonMark is preferred and will become the default in a future release.
-
The
documentation.nixos.options.allowDocBookoption was added to ease the transition to CommonMark option documentation. Setting this option tofalsecauses an error for every option included in the manual that uses DocBook documentation; it defaults totrueto preserve the previous behavior and will be removed once the transition to CommonMark is complete. -
The udisks2 service, available at
services.udisks2.enable, is now disabled by default. It will automatically be enabled through services and desktop environments as needed. This also means that polkit will now actually be disabled by default. The default forsecurity.polkit.enablewas already flipped in the previous release, but udisks2 being enabled by default re-enabled it. -
Nextcloud has been updated to version 25. Additionally the following things have changed for Nextcloud in NixOS:
- For Nextcloud >=24, the default PHP version is 8.1.
- Nextcloud 23 has been removed since it will reach its end of life in December 2022.
- For
system.stateVersionbeing >=22.11, Nextcloud 25 will be installed by default. For older versions, Nextcloud 24 will be installed. - Please ensure that you only upgrade on major release at a time! Nextcloud doesn't support upgrades across multiple versions, i.e. an upgrade from 23 to 25 is only possible when upgrading to 24 first.
-
Add udev rules for the Teensy family of microcontrollers.
-
systemd-oomd is enabled by default. Depending on which systemd units have
ManagedOOMSwap=killorManagedOOMMemoryPressure=kill, systemd-oomd will SIGKILL all the processes under the appropriate descendant cgroups when the configured limits are exceeded. NixOS does currently not configure cgroups with oomd by default, this can be enabled using systemd.oomd.enableRootSlice, systemd.oomd.enableSystemSlice, and systemd.oomd.enableUserServices. -
The
tt-rssservice performs two database migrations when you first use its web UI after upgrade. Consider backing up its database before updating. -
The
pass-secret-servicepackage now includes systemd units from upstream, so adding it to the NixOSservices.dbus.packagesoption will make it start automatically as a systemd user service when an application tries to talk to the libsecret D-Bus API. -
There is a new module for AMD SEV CPU functionality, which grants access to the hardware.
-
The Wordpress module got support for installing language packs through
services.wordpress.sites.<site>.languages. -
The default package for
services.mullvad-vpn.packagewas changed topkgs.mullvad, allowing cross-platform usage of Mullvad.pkgs.mullvadonly contains the Mullvad CLI tool, so users who rely on the Mullvad GUI will want to change it back topkgs.mullvad-vpn, or addpkgs.mullvad-vpnto their environment. -
PowerDNS has been updated from
4.6.xto4.7.x. Please be sure to review the Upgrade Notes provided by upstream before upgrading. Worth specifically noting is that the new Catalog Zones feature comes with a mandatory schema change for the gsql database backends, which has to be manually applied. -
There is a new module for the
thunarprogram (the Xfce file manager), which depends on thexfconfdbus service, and also has a dbus service and a systemd unit. The optionservices.xserver.desktopManager.xfce.thunarPluginshas been renamed toprograms.thunar.plugins, and in a future release it may be removed. -
There is a new module for the
xfconfprogram (the Xfce configuration storage system), which has a dbus service. -
The
nomadpackage now defaults to 1.3, which no longer has a downgrade path to releases 1.2 or older. -
The
nodePackagespackage set now defaults to the LTS release in thenodejspackage again, instead of being pinned tonodejs-14_x. Several updates to node2nix have been made for compatibility with newer Node.js and npm versions and a newpostRebuildhook has been added for packages to perform extra build steps before the npm install step prunes dev dependencies.