Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion ci/eval.sh
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ trap 'rm -f "$stderr"' EXIT
# Real failures are `abort`s, missing attributes and type errors, none of which
# `tryEval` can catch -- so they surface here as a non-zero exit with Nix's own
# message, which names the offending expression and its source location.
if ! result="$(nix-instantiate --eval --strict --json ci/eval.nix 2>"$stderr")"; then
if ! result="$(nix-instantiate --eval --strict --json ci/eval.nix --option allow-import-from-derivation false 2>"$stderr")"; then
cat "$stderr" >&2
exit 1
fi
Expand Down
5 changes: 4 additions & 1 deletion pkgs-many/r-lang/generic.nix
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,10 @@ stdenv.mkDerivation (finalAttrs: {
"--with-libtiff"
];

TZDIR = "${tzdata}/share/zoneinfo";
env = {
TZDIR = "${tzdata}/share/zoneinfo";
CURL_CONFIG = "${lib.getExe' (lib.getDev curl) "curl-config"}";
};

passthru = {
ekapkgs-update.semver-strategy = "patch";
Expand Down
220 changes: 220 additions & 0 deletions pkgs/avahi/default.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,220 @@
{
fetchurl,
fetchpatch,
lib,
stdenv,
pkg-config,
libdaemon,
dbus,
libpcap,
expat,
gettext,
glib,
autoconf-archive,
autoreconfHook,
libiconv,
libevent,
gtk3Support ? false,
gtk3,
withLibdnssdCompat ? false,
}:

stdenv.mkDerivation rec {
pname = "avahi${lib.optionalString withLibdnssdCompat "-compat"}";
version = "0.8";

src = fetchurl {
url = "https://github.com/lathiat/avahi/releases/download/v${version}/avahi-${version}.tar.gz";
sha256 = "1npdixwxxn3s9q1f365x9n9rc5xgfz39hxf23faqvlrklgbhj0q6";
};

outputs = [
"out"
"dev"
"man"
];

patches = [
(fetchpatch {
name = "CVE-2021-3502.patch";
url = "https://github.com/lathiat/avahi/commit/9d31939e55280a733d930b15ac9e4dda4497680c.patch";
sha256 = "sha256-BXWmrLWUvDxKPoIPRFBpMS3T4gijRw0J+rndp6iDybU=";
})
(fetchpatch {
name = "CVE-2021-3468.patch";
url = "https://github.com/lathiat/avahi/commit/447affe29991ee99c6b9732fc5f2c1048a611d3b.patch";
sha256 = "sha256-qWaCU1ZkCg2PmijNto7t8E3pYRN/36/9FrG8okd6Gu8=";
})
(fetchpatch {
name = "CVE-2023-1981.patch";
url = "https://github.com/lathiat/avahi/commit/a2696da2f2c50ac43b6c4903f72290d5c3fa9f6f.patch";
sha256 = "sha256-BEYFGCnQngp+OpiKIY/oaKygX7isAnxJpUPCUvg+efc=";
})
(fetchpatch {
name = "CVE-2023-38470.patch";
url = "https://github.com/lathiat/avahi/commit/94cb6489114636940ac683515417990b55b5d66c.patch";
sha256 = "sha256-Fanh9bvz+uknr5pAmltqijuUAZIG39JR2Lyq5zGKJ58=";
})
(fetchpatch {
name = "bail-out-unless-escaped-labels-fit.patch";
url = "https://github.com/avahi/avahi/commit/20dec84b2480821704258bc908e7b2bd2e883b24.patch";
sha256 = "sha256-p/dOuQ/GInIcUwuFhQR3mGc5YBL5J8ho+1gvzcqEN0c=";
})
(fetchpatch {
name = "CVE-2023-38473.patch";
url = "https://github.com/lathiat/avahi/commit/b448c9f771bada14ae8de175695a9729f8646797.patch";
sha256 = "sha256-/ZVhsBkf70vjDWWG5KXxvGXIpLOZUXdRkn3413iSlnI=";
})
(fetchpatch {
name = "CVE-2023-38472.patch";
url = "https://github.com/lathiat/avahi/commit/b024ae5749f4aeba03478e6391687c3c9c8dee40.patch";
sha256 = "sha256-FjR8fmhevgdxR9JQ5iBLFXK0ILp2OZQ8Oo9IKjefCqk=";
})
(fetchpatch {
name = "CVE-2023-38471.patch";
url = "https://github.com/lathiat/avahi/commit/894f085f402e023a98cbb6f5a3d117bd88d93b09.patch";
sha256 = "sha256-4dG+5ZHDa+A4/CszYS8uXWlpmA89m7/jhbZ7rheMs7U=";
})
(fetchpatch {
name = "CVE-2023-38471-2.patch";
url = "https://github.com/avahi/avahi/commit/b675f70739f404342f7f78635d6e2dcd85a13460.patch";
sha256 = "sha256-uDtMPWuz1lsu7n0Co/Gpyh369miQ6GWGyC0UPQB/yI8=";
})
(fetchpatch {
name = "CVE-2023-38469.patch";
url = "https://github.com/avahi/avahi/commit/61b9874ff91dd20a12483db07df29fe7f35db77f.patch";
sha256 = "sha256-qR7scfQqhRGxg2n4HQsxVxCLkXbwZi+PlYxrOSEPsL0=";
excludes = [ ".github/workflows/smoke-tests.sh" ];
})
(fetchpatch {
name = "fix-compare-rrs-with-zero-length-rdata.patch";
url = "https://github.com/avahi/avahi/commit/177d75e8c43be45a8383d794ce4084dd5d600a9e.patch";
sha256 = "sha256-uwIyruAWgiWt0yakRrvMdYjjhEhUk5cIGKt6twyXbHw=";
})
(fetchpatch {
name = "reject-non-utf-8-service-names.patch";
url = "https://github.com/avahi/avahi/commit/2b6d3e99579e3b6e9619708fad8ad8e07ada8218.patch";
sha256 = "sha256-lwSA3eEQgH0g51r0i9/HJMJPRXrhQnTIEDxcYqUuLdI=";
excludes = [ "fuzz/fuzz-domain.c" ];
})
(fetchpatch {
name = "core-no-longer-supply-bogus-services-to-callbacks.patch";
url = "https://github.com/avahi/avahi/commit/93b14365c1c1e04efd1a890e8caa01a2a514bfd8.patch";
sha256 = "sha256-VBm8vsBZkTbbWAK8FI71SL89lZuYd1yFNoB5o+FvlEU=";
excludes = [
".github/workflows/smoke-tests.sh"
"fuzz/fuzz-packet.c"
];
})
(fetchpatch {
name = "CVE-2024-52616.patch";
url = "https://github.com/avahi/avahi/commit/f8710bdc8b29ee1176fe3bfaeabebbda1b7a79f7.patch";
hash = "sha256-BUQOQ4evKLBzV5UV8xW8XL38qk1rg6MJ/vcT5NBckfA=";
})
(fetchpatch {
name = "fix-requires-in-pc-file.patch";
url = "https://github.com/avahi/avahi/commit/366e3798bdbd6b7bf24e59379f4a9a51af575ce9.patch";
hash = "sha256-9AdhtzrimmcpMmeyiFcjmDfG5nqr/S8cxWTaM1mzCWA=";
})
(fetchpatch {
name = "CVE-2025-68276.patch";
url = "https://github.com/avahi/avahi/commit/0c013e2e819be3bda74cecf48b5f64956cf8a760.patch";
hash = "sha256-kNOwl2DC2FR7CFvPQBBEYaSUSbFnR/ETH9JNGMwzzLE=";
})
(fetchpatch {
name = "CVE-2025-68468.patch";
url = "https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a.patch";
hash = "sha256-HkbKSN2LYqPfVnij1/n6ToN4vKugex3ZPxjHz6pN8eA=";
})
(fetchpatch {
name = "CVE-2025-68471.patch";
url = "https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1.patch";
hash = "sha256-V0OiC0UkZXhUnOUcrPZ+Xvph7MJMQ9DEXgVafoshSi4=";
})
(fetchpatch {
name = "CVE-2026-24401.patch";
url = "https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524.patch";
hash = "sha256-Iq7ghHS8gTJ5OeD6Bemis+wPJzKXb2P44qbtTaAaWZI=";
})
(fetchpatch {
name = "CVE-2026-34933.patch";
url = "https://github.com/avahi/avahi/compare/0ccadca425af151ebb67f276e5cc88e50266a8e6%5E%5E...0ccadca425af151ebb67f276e5cc88e50266a8e6.patch";
hash = "sha256-yi40iuQmTAW+nLsOIJhh7kg4vG/lqT/PCaSEBPfF2mw=";
})
];

postPatch = ''
# Remove the vendored ACX_PTHREAD macro in favor of the more up-to-date
# implementation from autoconf-archive, especially to support static builds.
rm common/acx_pthread.m4
'';

depsBuildBuild = [
pkg-config
];

nativeBuildInputs = [
pkg-config
gettext
glib
autoconf-archive
autoreconfHook
];

buildInputs = [
libdaemon
dbus
glib
expat
libiconv
libevent
]
++ lib.optionals stdenv.hostPlatform.isFreeBSD [
libpcap
]
++ lib.optionals gtk3Support [
gtk3
];

configureFlags = [
"--disable-gdbm"
"--disable-mono"
"--disable-qt5"
"--disable-python"
"--with-dbus-sys=${placeholder "out"}/share/dbus-1/system.d"
(lib.enableFeature gtk3Support "gtk3")
"--localstatedir=/var"
"--runstatedir=/run"
"--sysconfdir=/etc"
"--with-distro=${with stdenv.hostPlatform; if isBSD then parsed.kernel.name else "none"}"
"--with-systemdsystemunitdir=no"
]
++ lib.optionals withLibdnssdCompat [
"--enable-compat-libdns_sd"
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
"--disable-autoipd"
];

installFlags = [
"avahi_runtime_dir=${placeholder "out"}/run"
"sysconfdir=${placeholder "out"}/etc"
];

preBuild = lib.optionalString stdenv.hostPlatform.isDarwin ''
sed -i '20 i\
#define __APPLE_USE_RFC_2292' \
avahi-core/socket.c
'';

postInstall = lib.optionalString withLibdnssdCompat ''
ln -s avahi-compat-libdns_sd/dns_sd.h "$dev/include/dns_sd.h"
'';

meta = {
description = "mDNS/DNS-SD implementation";
homepage = "http://avahi.org";
license = lib.licenses.lgpl2Plus;
platforms = lib.platforms.unix;
};
}
14 changes: 2 additions & 12 deletions pkgs/conmon/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -19,20 +19,9 @@ stdenv.mkDerivation (finalAttrs: {
owner = "containers";
repo = "conmon";
tag = "v${finalAttrs.version}";
hash = "sha256-YkPgpT+0cE7FCP/dcqnTy6oonPbXKiutFCGX5Lj1JB8=";
leaveDotGit = true;
postFetch = ''
cd $out
git rev-parse HEAD > COMMIT
rm -rf .git
'';
hash = "sha256-NIbH/fiz/m2W7aGt2On7E6zkWFa5IKzrPROuCAYwNFk=";
};

preConfigure = ''
substituteInPlace Makefile \
--replace-fail "(GIT_COMMIT)" "(shell cat COMMIT)"
'';

nativeBuildInputs = [ pkg-config ];
buildInputs = [
glib
Expand All @@ -47,6 +36,7 @@ stdenv.mkDerivation (finalAttrs: {
# manpage requires building the vendored go-md2man
makeFlags = [
"bin/conmon"
"GIT_COMMIT=${finalAttrs.src.rev}"
];

installPhase = ''
Expand Down
1 change: 1 addition & 0 deletions pkgs/freerdp/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -163,6 +163,7 @@ stdenv.mkDerivation (finalAttrs: {
WITH_MANPAGES = withManPages;
WITH_PCSC = pcsclite != null;
WITH_PULSE = libpulseaudio != null;
WITH_CLIENT_SDL3 = false; # requires sdl3-ttf which is not yet available
WITH_SERVER = buildServer;
WITH_WEBVIEW = false; # avoid introducing webkit2gtk-4.0
WITH_VAAPI = false; # false is recommended by upstream
Expand Down
2 changes: 1 addition & 1 deletion pkgs/gtk/4.x.nix
Original file line number Diff line number Diff line change
Expand Up @@ -198,7 +198,7 @@ stdenv.mkDerivation (finalAttrs: {
};

mesonFeatures = {
tracker = trackerSupport;
tracker = trackerSupport && tinysparql != null;
vulkan = vulkanSupport;
print-cups = cupsSupport;
${
Expand Down
10 changes: 9 additions & 1 deletion pkgs/harfbuzz/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,11 @@
withGraphite2 ? true,
withIcu ? false,
icu,
gobject-introspection,
withIntrospection ?
lib.meta.availableOn stdenv.hostPlatform gobject-introspection
&& stdenv.hostPlatform.emulatorAvailable buildPackages,
buildPackages,
testers,

# for passthru.tests
Expand Down Expand Up @@ -46,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: {
coretext = false;
graphite = withGraphite2;
icu = withIcu;
introspection = false;
introspection = withIntrospection;
docs = false;
gpu = false;
gpu_demo = false;
Expand All @@ -63,6 +68,9 @@ stdenv.mkDerivation (finalAttrs: {
pkg-config
python3
glib
]
++ lib.optionals withIntrospection [
gobject-introspection
];

buildInputs = [
Expand Down
37 changes: 37 additions & 0 deletions pkgs/libdaemon/default.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
{
lib,
stdenv,
fetchurl,
}:

stdenv.mkDerivation (finalAttrs: {
pname = "libdaemon";
version = "0.14";

src = fetchurl {
url = "https://0pointer.de/lennart/projects/libdaemon/libdaemon-${finalAttrs.version}.tar.gz";
sha256 = "0d5qlq5ab95wh1xc87rqrh1vx6i8lddka1w3f1zcqvcqdxgyn8zx";
};

outputs = [
"out"
"dev"
"doc"
];

patches = [ ./fix-includes.patch ];

configureFlags = [
"--disable-lynx"
]
++ lib.optionals (stdenv.hostPlatform != stdenv.buildPlatform) [
"ac_cv_func_setpgrp_void=${lib.boolToYesNo (!stdenv.hostPlatform.isBSD)}"
];

meta = {
description = "Lightweight C library that eases the writing of UNIX daemons";
homepage = "http://0pointer.de/lennart/projects/libdaemon/";
license = lib.licenses.lgpl2Plus;
platforms = lib.platforms.unix;
};
})
13 changes: 13 additions & 0 deletions pkgs/libdaemon/fix-includes.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
--- libdaemon-0.14.orig/examples/testd.c
+++ libdaemon-0.14/examples/testd.c
@@ -21,9 +21,9 @@
#include <signal.h>
#include <errno.h>
#include <string.h>
+#include <unistd.h>
#include <sys/types.h>
#include <sys/time.h>
-#include <sys/unistd.h>
#include <sys/select.h>

#include <libdaemon/dfork.h>
Loading
Loading