mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-30 11:50:06 +00:00
[26.05] matrix-continuwuity: mark as insecure, matrix-continuwuity_latest: init at 26.9.1 (#567772)
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
{ lib, ... }:
|
||||
{ lib, pkgs, ... }:
|
||||
let
|
||||
name = "continuwuity";
|
||||
user = "alice";
|
||||
@@ -11,6 +11,7 @@ in
|
||||
continuwuity = {
|
||||
services.matrix-continuwuity = {
|
||||
enable = true;
|
||||
package = pkgs.matrix-continuwuity_latest;
|
||||
settings.global = {
|
||||
server_name = name;
|
||||
address = [ "0.0.0.0" ];
|
||||
@@ -20,61 +21,66 @@ in
|
||||
};
|
||||
networking.firewall.allowedTCPPorts = [ 6167 ];
|
||||
};
|
||||
|
||||
client =
|
||||
{ pkgs, ... }:
|
||||
{
|
||||
environment.systemPackages = [
|
||||
(pkgs.writers.writePython3Bin "do_test" { libraries = [ pkgs.python3Packages.matrix-nio ]; } ''
|
||||
(pkgs.writers.writePython3Bin "do_test" { libraries = [ pkgs.python3Packages.mautrix ]; } ''
|
||||
import asyncio
|
||||
import nio
|
||||
|
||||
from mautrix.client import Client
|
||||
from mautrix.types import EventType, RoomFilter, Filter
|
||||
|
||||
|
||||
async def main() -> None:
|
||||
# Connect to continuwuity
|
||||
client = nio.AsyncClient("http://continuwuity:6167", "${user}")
|
||||
client = Client(
|
||||
mxid="@${user}:${name}",
|
||||
base_url="http://continuwuity:6167",
|
||||
)
|
||||
|
||||
# Log in as user alice
|
||||
response = await client.login("${pass}")
|
||||
await client.login(password="${pass}")
|
||||
|
||||
# Create a new room
|
||||
response = await client.room_create(federate=False)
|
||||
print("Matrix room create response:", response)
|
||||
assert isinstance(response, nio.RoomCreateResponse)
|
||||
room_id = response.room_id
|
||||
room_id = await client.create_room()
|
||||
print("Created room:", room_id)
|
||||
|
||||
# Join the room
|
||||
response = await client.join(room_id)
|
||||
print("Matrix join response:", response)
|
||||
assert isinstance(response, nio.JoinResponse)
|
||||
await client.join_room_by_id(room_id)
|
||||
print("Joined room")
|
||||
|
||||
# Send a message to the room
|
||||
response = await client.room_send(
|
||||
room_id=room_id,
|
||||
message_type="m.room.message",
|
||||
content={
|
||||
"msgtype": "m.text",
|
||||
"body": "Hello continuwuity!"
|
||||
}
|
||||
)
|
||||
print("Matrix room send response:", response)
|
||||
assert isinstance(response, nio.RoomSendResponse)
|
||||
received = asyncio.Event()
|
||||
msg = "Hello continuwuity!"
|
||||
|
||||
# Sync responses
|
||||
response = await client.sync(timeout=30000)
|
||||
print("Matrix sync response:", response)
|
||||
assert isinstance(response, nio.SyncResponse)
|
||||
async def on_message(evt):
|
||||
if (
|
||||
evt.room_id != room_id
|
||||
or evt.sender != client.mxid
|
||||
or evt.type != EventType.ROOM_MESSAGE
|
||||
):
|
||||
return
|
||||
|
||||
# Check the message was received by continuwuity
|
||||
last_message = response.rooms.join[room_id].timeline.events[-1].body
|
||||
assert last_message == "Hello continuwuity!"
|
||||
assert evt.content.body == msg
|
||||
received.set()
|
||||
|
||||
client.add_event_handler(EventType.ROOM_MESSAGE, on_message)
|
||||
sync_task = client.start(Filter(room=RoomFilter(rooms=[room_id])))
|
||||
|
||||
await client.send_text(room_id, msg)
|
||||
|
||||
# Sync until message is received
|
||||
await asyncio.wait_for(received.wait(), timeout=30)
|
||||
|
||||
# Leave the room
|
||||
response = await client.room_leave(room_id)
|
||||
print("Matrix room leave response:", response)
|
||||
assert isinstance(response, nio.RoomLeaveResponse)
|
||||
await client.leave_room(room_id)
|
||||
print("Left room")
|
||||
|
||||
# Close the client
|
||||
await client.close()
|
||||
client.stop()
|
||||
await sync_task
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
@@ -96,6 +102,7 @@ in
|
||||
'';
|
||||
|
||||
meta.maintainers = with lib.maintainers; [
|
||||
bartoostveen
|
||||
nyabinary
|
||||
snaki
|
||||
];
|
||||
|
||||
@@ -100,5 +100,18 @@ rustPlatform.buildRustPackage (finalAttrs: {
|
||||
];
|
||||
# Not a typo, continuwuity is a drop-in replacement for conduwuit.
|
||||
mainProgram = "conduwuit";
|
||||
knownVulnerabilities = [
|
||||
''
|
||||
Continuwuity 0.5.10 can no longer be securely ran, as it contains a critical security-related bug that is currently embargoed at the time of writing.
|
||||
Continuwuity internally tracks this as SEC8, see also: https://forgejo.ellis.link/continuwuation/continuwuity/releases/tag/v26.9.1
|
||||
|
||||
The latest version of Continuwuity has been moved to `matrix-continuwuity_latest` as to not introduce breaking changes.
|
||||
It is highly advisable to upgrade to this version as fast as possible. When deploying Continuwuity using the NixOS module, you may do so using:
|
||||
|
||||
`services.matrix-continuwuity.package = pkgs.matrix-continuwuity_latest`.
|
||||
|
||||
The most notable breaking change of the 26.x release is the removal of LDAP.
|
||||
''
|
||||
];
|
||||
};
|
||||
})
|
||||
|
||||
80
pkgs/by-name/ma/matrix-continuwuity_latest/package.nix
Normal file
80
pkgs/by-name/ma/matrix-continuwuity_latest/package.nix
Normal file
@@ -0,0 +1,80 @@
|
||||
{
|
||||
lib,
|
||||
rustPlatform,
|
||||
fetchFromGitea,
|
||||
pkg-config,
|
||||
bzip2,
|
||||
zstd,
|
||||
stdenv,
|
||||
callPackage,
|
||||
nix-update-script,
|
||||
testers,
|
||||
matrix-continuwuity_latest,
|
||||
rust-jemalloc-sys-unprefixed,
|
||||
liburing,
|
||||
nixosTests,
|
||||
}:
|
||||
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "matrix-continuwuity";
|
||||
version = "26.9.1";
|
||||
|
||||
__structuredAttrs = true;
|
||||
|
||||
src = fetchFromGitea {
|
||||
domain = "forgejo.ellis.link";
|
||||
owner = "continuwuation";
|
||||
repo = "continuwuity";
|
||||
tag = "v${finalAttrs.version}";
|
||||
hash = "sha256-z9iOdSjTvv+kDJaoAyKTzrY0ge2KM90H4tM8ir52RMQ=";
|
||||
};
|
||||
|
||||
cargoHash = "sha256-dbTrgE0+OzHhD3rjQciZfRIBivvZa0YZyKpTP8XOzZI=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
pkg-config
|
||||
rustPlatform.bindgenHook
|
||||
];
|
||||
|
||||
buildInputs = [
|
||||
bzip2
|
||||
zstd
|
||||
rust-jemalloc-sys-unprefixed
|
||||
liburing
|
||||
];
|
||||
|
||||
env = {
|
||||
ZSTD_SYS_USE_PKG_CONFIG = true;
|
||||
ROCKSDB_INCLUDE_DIR = "${finalAttrs.rocksdb}/include";
|
||||
ROCKSDB_LIB_DIR = "${finalAttrs.rocksdb}/lib";
|
||||
};
|
||||
|
||||
rocksdb = callPackage ./rocksdb.nix { }; # make used rocksdb version available (e.g., for backup scripts)
|
||||
|
||||
passthru = {
|
||||
updateScript = nix-update-script { };
|
||||
tests = {
|
||||
version = testers.testVersion {
|
||||
inherit (finalAttrs) version;
|
||||
package = matrix-continuwuity_latest;
|
||||
};
|
||||
}
|
||||
// lib.optionalAttrs stdenv.hostPlatform.isLinux {
|
||||
inherit (nixosTests) matrix-continuwuity;
|
||||
};
|
||||
};
|
||||
|
||||
meta = {
|
||||
description = "Matrix homeserver written in Rust, forked from conduwuit";
|
||||
homepage = "https://continuwuity.org/";
|
||||
changelog = "https://forgejo.ellis.link/continuwuation/continuwuity/releases/tag/v${finalAttrs.version}";
|
||||
license = lib.licenses.asl20;
|
||||
maintainers = with lib.maintainers; [
|
||||
bartoostveen
|
||||
nyabinary
|
||||
snaki
|
||||
];
|
||||
# Not a typo, continuwuity is a drop-in replacement for conduwuit.
|
||||
mainProgram = "conduwuit";
|
||||
};
|
||||
})
|
||||
26
pkgs/by-name/ma/matrix-continuwuity_latest/rocksdb.nix
Normal file
26
pkgs/by-name/ma/matrix-continuwuity_latest/rocksdb.nix
Normal file
@@ -0,0 +1,26 @@
|
||||
{
|
||||
stdenv,
|
||||
fetchFromGitea,
|
||||
rocksdb,
|
||||
rust-jemalloc-sys-unprefixed,
|
||||
}:
|
||||
|
||||
(rocksdb.override {
|
||||
# rocksdb does not support prefixed jemalloc, which is required on darwin
|
||||
enableJemalloc = !stdenv.hostPlatform.isDarwin;
|
||||
jemalloc = rust-jemalloc-sys-unprefixed;
|
||||
}).overrideAttrs
|
||||
(
|
||||
final: old: {
|
||||
version = "11.1.1";
|
||||
src = fetchFromGitea {
|
||||
domain = "forgejo.ellis.link";
|
||||
owner = "continuwuation";
|
||||
repo = "rocksdb";
|
||||
rev = "3756b2b905e13216d8b56bcc783d814e7b073aff";
|
||||
hash = "sha256-rSv4fr2bf9JJwdodgeuPCuceeh7k97KVxrAOC0wyPQY=";
|
||||
};
|
||||
|
||||
patches = [ ];
|
||||
}
|
||||
)
|
||||
Reference in New Issue
Block a user