unofficial mirror of guix-patches@gnu.org 
 help / color / mirror / code / Atom feed
blob 6dd605ef0396dbc3816ede3f5abbef08f65b7473 3592 bytes (raw)
name: etc/upgrade-manifest.scm 	 # note: path name is non-authoritative(*)

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
 
;;; GNU Guix --- Functional package management for GNU
;;; Copyright © 2024 Ludovic Courtès <ludo@gnu.org>
;;;
;;; This file is part of GNU Guix.
;;;
;;; GNU Guix is free software; you can redistribute it and/or modify it
;;; under the terms of the GNU General Public License as published by
;;; the Free Software Foundation; either version 3 of the License, or (at
;;; your option) any later version.
;;;
;;; GNU Guix is distributed in the hope that it will be useful, but
;;; WITHOUT ANY WARRANTY; without even the implied warranty of
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
;;; GNU General Public License for more details.
;;;
;;; You should have received a copy of the GNU General Public License
;;; along with GNU Guix.  If not, see <http://www.gnu.org/licenses/>.

;; This manifest computes upgrades of key packages using the 'with-latest'
;; package transformation.

(use-modules (guix monads)
             (guix graph)
             (guix packages)
             (guix profiles)
             (guix store)
             (guix transformations)
             ((guix scripts build) #:select (dependents))
             ((guix scripts graph) #:select (%bag-node-type))
             ((guix import github) #:select (%github-api))
             (guix build-system gnu)
             (guix build-system cmake)
             ((gnu packages) #:select (all-packages))
             (ice-9 match)
             (srfi srfi-1))

;; Bypass the GitHub updater: we'd need an API token or we would hit the rate
;; limit.
(%github-api "http://example.org")

(define (leaf-packages)
  (with-store store
    (run-with-store store
      (mlet %store-monad ((edges (node-back-edges %bag-node-type (all-packages))))
        (return (filter (lambda (package)
                          (null? (edges package)))
                        (all-packages)))))))

(define security-packages
  '("git" "git-minimal"
    "xorg-server"
    "elogind"
    "openssl"
    "gnutls"
    "libarchive"
    "libgit2"
    "libssh"

    ;; GnuPG.
    "libassuan"
    "libgpg-error"
    "libgcrypt"
    "libksba"
    "npth"
    "gnupg"
    "gpgme"
    "pinentry"))

(define security-upgrades
  ;; Upgrades of individual packages with their dependents built against that
  ;; upgrade.
  (manifest
   (with-store store
     (append-map (match-lambda
                   ((package . output)
                    (let* ((name (package-name package))
                           (latest (options->transformation
                                    `((with-latest . ,name)))))
                      (map (lambda (package)
                             (manifest-entry
                               (inherit (package->manifest-entry
                                         (latest (pk 'latest package))))
                               (name (string-append (package-name package)
                                                    "-with-latest-" name))))
                           (dependents store (list package) 2)))))
                 (specifications->packages security-packages)))))

(define leaf-package-updates
  ;; Select a subset (~22%) of all the leaf packages, typically small C/C++
  ;; packages not part of a bigger "collection" or repo (CRAN, PyPI, etc.).
  (manifest
   (filter-map (lambda (package)
                 (and (memq (package-build-system package)
                            (list gnu-build-system cmake-build-system))
                      (package-with-upstream-version (pk 'up package))))
               (leaf-packages))))

(concatenate-manifest (list leaf-package-updates security-upgrades))

debug log:

solving 6dd605ef03 ...
found 6dd605ef03 in https://yhetil.org/guix-patches/c55d9c57d99b50436c3afa607beaf62ae46d3c40.1732615193.git.ludo@gnu.org/

applying [1/1] https://yhetil.org/guix-patches/c55d9c57d99b50436c3afa607beaf62ae46d3c40.1732615193.git.ludo@gnu.org/
diff --git a/etc/upgrade-manifest.scm b/etc/upgrade-manifest.scm
new file mode 100644
index 0000000000..6dd605ef03

Checking patch etc/upgrade-manifest.scm...
Applied patch etc/upgrade-manifest.scm cleanly.

index at:
100644 6dd605ef0396dbc3816ede3f5abbef08f65b7473	etc/upgrade-manifest.scm

(*) Git path names are given by the tree(s) the blob belongs to.
    Blobs themselves have no identifier aside from the hash of its contents.^

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).