[26.05] matrix-continuwuity: mark as insecure, matrix-continuwuity_latest: init at 26.9.1 (#567772)

This commit is contained in:
Diogo Correia
2026-09-28 10:08:08 +00:00
committed by GitHub
4 changed files with 159 additions and 33 deletions

View File

@@ -1,4 +1,4 @@
{ lib, ... }:
{ lib, pkgs, ... }:
let
name = "continuwuity";
user = "alice";
@@ -11,6 +11,7 @@ in
continuwuity = {
services.matrix-continuwuity = {
enable = true;
package = pkgs.matrix-continuwuity_latest;
settings.global = {
server_name = name;
address = [ "0.0.0.0" ];
@@ -20,61 +21,66 @@ in
};
networking.firewall.allowedTCPPorts = [ 6167 ];
};
client =
{ pkgs, ... }:
{
environment.systemPackages = [
(pkgs.writers.writePython3Bin "do_test" { libraries = [ pkgs.python3Packages.matrix-nio ]; } ''
(pkgs.writers.writePython3Bin "do_test" { libraries = [ pkgs.python3Packages.mautrix ]; } ''
import asyncio
import nio
from mautrix.client import Client
from mautrix.types import EventType, RoomFilter, Filter
async def main() -> None:
# Connect to continuwuity
client = nio.AsyncClient("http://continuwuity:6167", "${user}")
client = Client(
mxid="@${user}:${name}",
base_url="http://continuwuity:6167",
)
# Log in as user alice
response = await client.login("${pass}")
await client.login(password="${pass}")
# Create a new room
response = await client.room_create(federate=False)
print("Matrix room create response:", response)
assert isinstance(response, nio.RoomCreateResponse)
room_id = response.room_id
room_id = await client.create_room()
print("Created room:", room_id)
# Join the room
response = await client.join(room_id)
print("Matrix join response:", response)
assert isinstance(response, nio.JoinResponse)
await client.join_room_by_id(room_id)
print("Joined room")
# Send a message to the room
response = await client.room_send(
room_id=room_id,
message_type="m.room.message",
content={
"msgtype": "m.text",
"body": "Hello continuwuity!"
}
)
print("Matrix room send response:", response)
assert isinstance(response, nio.RoomSendResponse)
received = asyncio.Event()
msg = "Hello continuwuity!"
# Sync responses
response = await client.sync(timeout=30000)
print("Matrix sync response:", response)
assert isinstance(response, nio.SyncResponse)
async def on_message(evt):
if (
evt.room_id != room_id
or evt.sender != client.mxid
or evt.type != EventType.ROOM_MESSAGE
):
return
# Check the message was received by continuwuity
last_message = response.rooms.join[room_id].timeline.events[-1].body
assert last_message == "Hello continuwuity!"
assert evt.content.body == msg
received.set()
client.add_event_handler(EventType.ROOM_MESSAGE, on_message)
sync_task = client.start(Filter(room=RoomFilter(rooms=[room_id])))
await client.send_text(room_id, msg)
# Sync until message is received
await asyncio.wait_for(received.wait(), timeout=30)
# Leave the room
response = await client.room_leave(room_id)
print("Matrix room leave response:", response)
assert isinstance(response, nio.RoomLeaveResponse)
await client.leave_room(room_id)
print("Left room")
# Close the client
await client.close()
client.stop()
await sync_task
if __name__ == "__main__":
@@ -96,6 +102,7 @@ in
'';
meta.maintainers = with lib.maintainers; [
bartoostveen
nyabinary
snaki
];

View File

@@ -100,5 +100,18 @@ rustPlatform.buildRustPackage (finalAttrs: {
];
# Not a typo, continuwuity is a drop-in replacement for conduwuit.
mainProgram = "conduwuit";
knownVulnerabilities = [
''
Continuwuity 0.5.10 can no longer be securely ran, as it contains a critical security-related bug that is currently embargoed at the time of writing.
Continuwuity internally tracks this as SEC8, see also: https://forgejo.ellis.link/continuwuation/continuwuity/releases/tag/v26.9.1
The latest version of Continuwuity has been moved to `matrix-continuwuity_latest` as to not introduce breaking changes.
It is highly advisable to upgrade to this version as fast as possible. When deploying Continuwuity using the NixOS module, you may do so using:
`services.matrix-continuwuity.package = pkgs.matrix-continuwuity_latest`.
The most notable breaking change of the 26.x release is the removal of LDAP.
''
];
};
})

View File

@@ -0,0 +1,80 @@
{
lib,
rustPlatform,
fetchFromGitea,
pkg-config,
bzip2,
zstd,
stdenv,
callPackage,
nix-update-script,
testers,
matrix-continuwuity_latest,
rust-jemalloc-sys-unprefixed,
liburing,
nixosTests,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "matrix-continuwuity";
version = "26.9.1";
__structuredAttrs = true;
src = fetchFromGitea {
domain = "forgejo.ellis.link";
owner = "continuwuation";
repo = "continuwuity";
tag = "v${finalAttrs.version}";
hash = "sha256-z9iOdSjTvv+kDJaoAyKTzrY0ge2KM90H4tM8ir52RMQ=";
};
cargoHash = "sha256-dbTrgE0+OzHhD3rjQciZfRIBivvZa0YZyKpTP8XOzZI=";
nativeBuildInputs = [
pkg-config
rustPlatform.bindgenHook
];
buildInputs = [
bzip2
zstd
rust-jemalloc-sys-unprefixed
liburing
];
env = {
ZSTD_SYS_USE_PKG_CONFIG = true;
ROCKSDB_INCLUDE_DIR = "${finalAttrs.rocksdb}/include";
ROCKSDB_LIB_DIR = "${finalAttrs.rocksdb}/lib";
};
rocksdb = callPackage ./rocksdb.nix { }; # make used rocksdb version available (e.g., for backup scripts)
passthru = {
updateScript = nix-update-script { };
tests = {
version = testers.testVersion {
inherit (finalAttrs) version;
package = matrix-continuwuity_latest;
};
}
// lib.optionalAttrs stdenv.hostPlatform.isLinux {
inherit (nixosTests) matrix-continuwuity;
};
};
meta = {
description = "Matrix homeserver written in Rust, forked from conduwuit";
homepage = "https://continuwuity.org/";
changelog = "https://forgejo.ellis.link/continuwuation/continuwuity/releases/tag/v${finalAttrs.version}";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [
bartoostveen
nyabinary
snaki
];
# Not a typo, continuwuity is a drop-in replacement for conduwuit.
mainProgram = "conduwuit";
};
})

View File

@@ -0,0 +1,26 @@
{
stdenv,
fetchFromGitea,
rocksdb,
rust-jemalloc-sys-unprefixed,
}:
(rocksdb.override {
# rocksdb does not support prefixed jemalloc, which is required on darwin
enableJemalloc = !stdenv.hostPlatform.isDarwin;
jemalloc = rust-jemalloc-sys-unprefixed;
}).overrideAttrs
(
final: old: {
version = "11.1.1";
src = fetchFromGitea {
domain = "forgejo.ellis.link";
owner = "continuwuation";
repo = "rocksdb";
rev = "3756b2b905e13216d8b56bcc783d814e7b073aff";
hash = "sha256-rSv4fr2bf9JJwdodgeuPCuceeh7k97KVxrAOC0wyPQY=";
};
patches = [ ];
}
)