From 263f66ee2a17b22241aabed0c555347d0a643533 Mon Sep 17 00:00:00 2001 From: Wanja Hentze Date: Fri, 8 Jul 2022 18:44:38 +0200 Subject: [PATCH 1/5] vim: 8.2.4816 -> 8.2.5172 Fixes the following CVEs: https://nvd.nist.gov/vuln/detail/CVE-2022-1927 https://nvd.nist.gov/vuln/detail/CVE-2022-2207 https://nvd.nist.gov/vuln/detail/CVE-2022-2210 https://nvd.nist.gov/vuln/detail/CVE-2022-2175 https://nvd.nist.gov/vuln/detail/CVE-2022-1616 https://nvd.nist.gov/vuln/detail/CVE-2022-1619 https://nvd.nist.gov/vuln/detail/CVE-2022-1621 https://nvd.nist.gov/vuln/detail/CVE-2022-1629 https://nvd.nist.gov/vuln/detail/CVE-2022-1720 https://nvd.nist.gov/vuln/detail/CVE-2022-1733 https://nvd.nist.gov/vuln/detail/CVE-2022-1735 https://nvd.nist.gov/vuln/detail/CVE-2022-1769 https://nvd.nist.gov/vuln/detail/CVE-2022-1785 https://nvd.nist.gov/vuln/detail/CVE-2022-1796 https://nvd.nist.gov/vuln/detail/CVE-2022-1851 https://nvd.nist.gov/vuln/detail/CVE-2022-1886 https://nvd.nist.gov/vuln/detail/CVE-2022-1898 https://nvd.nist.gov/vuln/detail/CVE-2022-1942 https://nvd.nist.gov/vuln/detail/CVE-2022-2124 https://nvd.nist.gov/vuln/detail/CVE-2022-2125 https://nvd.nist.gov/vuln/detail/CVE-2022-2126 https://nvd.nist.gov/vuln/detail/CVE-2022-2129 https://nvd.nist.gov/vuln/detail/CVE-2022-2182 https://nvd.nist.gov/vuln/detail/CVE-2022-2183 https://nvd.nist.gov/vuln/detail/CVE-2022-2206 https://nvd.nist.gov/vuln/detail/CVE-2022-1620 https://nvd.nist.gov/vuln/detail/CVE-2022-1674 https://nvd.nist.gov/vuln/detail/CVE-2022-1771 https://nvd.nist.gov/vuln/detail/CVE-2022-2208 Changes: https://github.com/vim/vim/compare/v8.2.4816...v8.2.5172 --- pkgs/applications/editors/vim/common.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/editors/vim/common.nix b/pkgs/applications/editors/vim/common.nix index 8c5058658495..a47dd56ea076 100644 --- a/pkgs/applications/editors/vim/common.nix +++ b/pkgs/applications/editors/vim/common.nix @@ -1,12 +1,12 @@ { lib, fetchFromGitHub }: rec { - version = "8.2.4816"; + version = "8.2.5172"; src = fetchFromGitHub { owner = "vim"; repo = "vim"; rev = "v${version}"; - sha256 = "1lgqr3ki50hwkz4vhdyaryirrs99qq4kgkhmpx7ygvn6aj2wapg5"; + sha256 = "sha256-ycp9K7IpXBFLE9DV9/iQ+N1H7EMD/tP/KGv2VOXoDvE="; }; enableParallelBuilding = true; From 636862dd5c5e7a39845228ab326f94bd0994307b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sebasti=C3=A1n=20Mancilla?= Date: Sat, 9 Jul 2022 23:55:57 -0400 Subject: [PATCH 2/5] libui: fix typo when installing libs on darwin (cherry picked from commit c39770ecc5468a54aeaafb941ca0a055788fc6aa) --- pkgs/development/libraries/libui/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/libraries/libui/default.nix b/pkgs/development/libraries/libui/default.nix index 14fb004187d8..a798977b1f41 100644 --- a/pkgs/development/libraries/libui/default.nix +++ b/pkgs/development/libraries/libui/default.nix @@ -30,7 +30,7 @@ stdenv.mkDerivation rec { ln -s $out/lib/libui.so.0 $out/lib/libui.so '' + lib.optionalString stdenv.isDarwin '' mv ./out/libui.A.dylib $out/lib/ - ln -s $out/lib/lubui.A.dylib $out/lib/libui.dylib + ln -s $out/lib/libui.A.dylib $out/lib/libui.dylib '' + '' cp $src/ui.h $out/include cp $src/ui_${backend}.h $out/include From a132219e189953ec0396e7ad090ee39edabde62f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sebasti=C3=A1n=20Mancilla?= Date: Sat, 9 Jul 2022 23:56:43 -0400 Subject: [PATCH 3/5] untrunc-anthwlock: mark as unbroken on darwin Fixed by c39770ecc54 (libui: fix typo when installing libs on darwin, 2022-07-09). (cherry picked from commit cf88ead89d554904e2b29aef73df98d9bd336523) --- pkgs/tools/video/untrunc-anthwlock/default.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/pkgs/tools/video/untrunc-anthwlock/default.nix b/pkgs/tools/video/untrunc-anthwlock/default.nix index 83b56e2f056a..4b950fd0f220 100644 --- a/pkgs/tools/video/untrunc-anthwlock/default.nix +++ b/pkgs/tools/video/untrunc-anthwlock/default.nix @@ -27,7 +27,6 @@ stdenv.mkDerivation { enableParallelBuilding = true; meta = with lib; { - broken = stdenv.isDarwin; description = "Restore a truncated mp4/mov (improved version of ponchio/untrunc)"; homepage = "https://github.com/anthwlock/untrunc"; license = licenses.gpl2; From da92159e33937d7705d78e80f02b566a25f60868 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sebasti=C3=A1n=20Mancilla?= Date: Sat, 9 Jul 2022 23:57:14 -0400 Subject: [PATCH 4/5] untrunc-anthwlock: refactor build Use buildPhase to make clear that we need two invocations of 'make' with different targets. Also set IS_RELEASE to 1 to ensure an optimized build is created instead of a debug build (see Makefile). (cherry picked from commit 3239a0535787625e036af8f59a45a5fe689ff4ca) --- pkgs/tools/video/untrunc-anthwlock/default.nix | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/pkgs/tools/video/untrunc-anthwlock/default.nix b/pkgs/tools/video/untrunc-anthwlock/default.nix index 4b950fd0f220..c127bfe8740e 100644 --- a/pkgs/tools/video/untrunc-anthwlock/default.nix +++ b/pkgs/tools/video/untrunc-anthwlock/default.nix @@ -11,11 +11,13 @@ stdenv.mkDerivation { sha256 = "14i2lq68q990hnm2kkfamlsi67bcml85zl8yjsyxc5h8ncc2f3dp"; }; - buildInputs = [ ffmpeg libui ]; - postBuild = '' - make untrunc-gui + buildPhase = '' + runHook preBuild + make IS_RELEASE=1 untrunc + make IS_RELEASE=1 untrunc-gui + runHook postBuild ''; installPhase = '' From 563e7d183dffdd1cbb0f9b4b68b9f6834d37e6fd Mon Sep 17 00:00:00 2001 From: Jiajie Chen Date: Mon, 4 Jul 2022 14:53:28 +0800 Subject: [PATCH 5/5] hdf5_1_10: 1.10.6 -> 1.10.9 pythonPackages.tables is updated, the version pin is removed. The bin-mv.patch is applied upstream. (cherry picked from commit b3aee32add2396c1521b83b5c6c92e4c53108bcc) --- pkgs/tools/misc/hdf5/1.10.nix | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/pkgs/tools/misc/hdf5/1.10.nix b/pkgs/tools/misc/hdf5/1.10.nix index 74d8fce599a8..fbfac18414c8 100644 --- a/pkgs/tools/misc/hdf5/1.10.nix +++ b/pkgs/tools/misc/hdf5/1.10.nix @@ -12,12 +12,11 @@ let inherit (lib) optional optionals; in stdenv.mkDerivation rec { - # pinned to 1.10.6 for pythonPackages.tables v3.6.1. tables has test errors for hdf5 > 1.10.6. https://github.com/PyTables/PyTables/issues/845 - version = "1.10.6"; + version = "1.10.9"; pname = "hdf5"; src = fetchurl { url = "https://support.hdfgroup.org/ftp/HDF5/releases/hdf5-${lib.versions.majorMinor version}/${pname}-${version}/src/${pname}-${version}.tar.bz2"; - sha256 = "1gf38x51128hn00744358w27xgzjk0ff4wra4yxh2lk804ck1mh9"; + sha256 = "sha256-AMS+cJbzb9yvpPl04SbGwUEkKOOOvHsYHZB0WeeB8ZE="; }; outputs = [ "out" "dev" ]; @@ -31,9 +30,7 @@ stdenv.mkDerivation rec { configureFlags = optional enableShared "--enable-shared" ++ optional javaSupport "--enable-java"; - patches = [ - ./bin-mv.patch - ]; + patches = [ ]; postInstall = '' find "$out" -type f -exec remove-references-to -t ${stdenv.cc} '{}' +