mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 13:00:23 +00:00
throne: 1.2.4 -> 1.3.1 (#566708)
This commit is contained in:
@@ -17645,6 +17645,12 @@
|
||||
githubId = 85435692;
|
||||
name = "Maxwell Berg";
|
||||
};
|
||||
Mahdi-zarei = {
|
||||
email = "mahdi.zrei@gmail.com";
|
||||
github = "Mahdi-zarei";
|
||||
githubId = 80265960;
|
||||
name = "Mahdi";
|
||||
};
|
||||
mahe = {
|
||||
email = "matthias.mh.herrmann@gmail.com";
|
||||
github = "2chilled";
|
||||
|
||||
@@ -1,40 +0,0 @@
|
||||
diff --git a/core/server/server.go b/core/server/server.go
|
||||
index 4499a6d..4c14d1a 100644
|
||||
--- a/core/server/server.go
|
||||
+++ b/core/server/server.go
|
||||
@@ -24,6 +24,7 @@ import (
|
||||
"github.com/sagernet/sing-box/experimental/clashapi"
|
||||
"github.com/sagernet/sing/common"
|
||||
E "github.com/sagernet/sing/common/exceptions"
|
||||
+ "golang.org/x/sys/unix"
|
||||
"github.com/sagernet/sing/service"
|
||||
"github.com/xtls/xray-core/core"
|
||||
)
|
||||
@@ -462,6 +463,27 @@ func (s *server) IsPrivileged(ctx context.Context, _ *gen.EmptyReq) (*gen.IsPriv
|
||||
}, nil
|
||||
}
|
||||
|
||||
+ if runtime.GOOS == "linux" {
|
||||
+ caps := unix.CapUserHeader{
|
||||
+ Version: unix.LINUX_CAPABILITY_VERSION_3,
|
||||
+ Pid: 0, // current
|
||||
+ }
|
||||
+
|
||||
+ var data [2]unix.CapUserData
|
||||
+ err := unix.Capget(&caps, &data[0])
|
||||
+
|
||||
+ if err != nil {
|
||||
+ return &gen.IsPrivilegedResponse{
|
||||
+ HasPrivilege: To(false),
|
||||
+ }, nil
|
||||
+ }
|
||||
+
|
||||
+ // CAP_NET_ADMIN = 12
|
||||
+ return &gen.IsPrivilegedResponse{
|
||||
+ HasPrivilege: To((data[0].Effective & (1 << unix.CAP_NET_ADMIN)) != 0),
|
||||
+ }, nil
|
||||
+ }
|
||||
+
|
||||
return &gen.IsPrivilegedResponse{HasPrivilege: To(os.Geteuid() == 0)}, nil
|
||||
}
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
diff --git a/core/server/parentcheck/parentcheck.go b/core/server/parentcheck/parentcheck.go
|
||||
index 0991a7f..58fd32f 100644
|
||||
--- a/core/server/parentcheck/parentcheck.go
|
||||
+++ b/core/server/parentcheck/parentcheck.go
|
||||
@@ -11,6 +11,8 @@ import (
|
||||
)
|
||||
|
||||
func CheckParentProcess() {
|
||||
+ return
|
||||
+
|
||||
parentPath, err := getParentExePath(ParentPID)
|
||||
if err != nil {
|
||||
log.Fatalf("parent check: cannot read parent executable: %v", err)
|
||||
@@ -1,39 +0,0 @@
|
||||
diff --git a/src/sys/linux/AutoRun.cpp b/src/sys/linux/AutoRun.cpp
|
||||
index 1fafe35..a32e7fe 100644
|
||||
--- a/src/sys/linux/AutoRun.cpp
|
||||
+++ b/src/sys/linux/AutoRun.cpp
|
||||
@@ -31,18 +31,9 @@ void AutoRun_SetEnabled(bool enable) {
|
||||
QString desktopFileLocation = userAutoStartPath + appName + QLatin1String(".desktop");
|
||||
QStringList appCmdList;
|
||||
|
||||
- if (QProcessEnvironment::systemEnvironment().contains("APPIMAGE")) {
|
||||
- appCmdList << QProcessEnvironment::systemEnvironment().value("APPIMAGE");
|
||||
- } else {
|
||||
- appCmdList << QApplication::applicationFilePath();
|
||||
- }
|
||||
-
|
||||
+ appCmdList << "Throne";
|
||||
appCmdList << "-tray";
|
||||
|
||||
- if (Configs::dataManager->settingsRepo->flag_use_appdata) {
|
||||
- appCmdList << "-appdata";
|
||||
- }
|
||||
-
|
||||
if (enable) {
|
||||
if (!QDir().exists(userAutoStartPath) && !QDir().mkpath(userAutoStartPath)) {
|
||||
// qCWarning(lcUtility) << "Could not create autostart folder"
|
||||
diff --git a/src/sys/linux/UrlScheme.cpp b/src/sys/linux/UrlScheme.cpp
|
||||
index 63e4118..a9d3a42 100644
|
||||
--- a/src/sys/linux/UrlScheme.cpp
|
||||
+++ b/src/sys/linux/UrlScheme.cpp
|
||||
@@ -14,9 +14,7 @@ static const QString kDesktopId = "throne-url-handler.desktop";
|
||||
// For AppImage the launcher must point at the outer image ($APPIMAGE), not the
|
||||
// extracted binary inside the mount, which disappears after exit.
|
||||
static QString execTarget() {
|
||||
- auto env = QProcessEnvironment::systemEnvironment();
|
||||
- if (env.contains("APPIMAGE")) return env.value("APPIMAGE");
|
||||
- return QApplication::applicationFilePath();
|
||||
+ return "Throne";
|
||||
}
|
||||
|
||||
static QString desktopFilePath() {
|
||||
@@ -1,51 +0,0 @@
|
||||
diff --git a/src/global/Configs.cpp b/src/global/Configs.cpp
|
||||
index 9600a95..ee38aaa 100644
|
||||
--- a/src/global/Configs.cpp
|
||||
+++ b/src/global/Configs.cpp
|
||||
@@ -45,6 +45,12 @@ namespace Configs {
|
||||
}
|
||||
|
||||
QString FindCoreRealPath() {
|
||||
+ // find in PATH first
|
||||
+ QString path_for_nixos = QStandardPaths::findExecutable("ThroneCore");
|
||||
+ if (!path_for_nixos.isEmpty()) {
|
||||
+ return path_for_nixos;
|
||||
+ }
|
||||
+
|
||||
auto fn = QApplication::applicationDirPath() + "/ThroneCore";
|
||||
#ifdef Q_OS_WIN
|
||||
fn += ".exe";
|
||||
diff --git a/src/ui/mainWindow/mainwindow_setup.cpp b/src/ui/mainWindow/mainwindow_setup.cpp
|
||||
index 7bec187..0f04cc8 100644
|
||||
--- a/src/ui/mainWindow/mainwindow_setup.cpp
|
||||
+++ b/src/ui/mainWindow/mainwindow_setup.cpp
|
||||
@@ -207,8 +207,7 @@ MainWindow::MainWindow(QWidget *parent) : QMainWindow(parent), ui(new Ui::MainWi
|
||||
runOnNewThread([=, this] {GetDeviceDetails(); });
|
||||
|
||||
// Prepare core
|
||||
- auto core_path = QApplication::applicationDirPath() + "/";
|
||||
- core_path += "ThroneCore";
|
||||
+ auto core_path = Configs::FindCoreRealPath();
|
||||
|
||||
bool coreDebugMode = (Configs::dataManager->settingsRepo->log_level == "debug");
|
||||
|
||||
diff --git a/src/ui/mainWindow/mainwindow_system.cpp b/src/ui/mainWindow/mainwindow_system.cpp
|
||||
index f1a7504..efffd4a 100644
|
||||
--- a/src/ui/mainWindow/mainwindow_system.cpp
|
||||
+++ b/src/ui/mainWindow/mainwindow_system.cpp
|
||||
@@ -193,6 +193,15 @@ bool MainWindow::get_elevated_permissions(ExitReason reason) {
|
||||
return true;
|
||||
}
|
||||
if (Configs::IsAdmin()) return true;
|
||||
+ QMessageBox::critical(
|
||||
+ GetMessageBoxParent(),
|
||||
+ tr("Unable to elevate privileges when installed with Nix"),
|
||||
+ tr("Due to the read-only property of the Nix store, we cannot set suid for ThroneCore. If you are using NixOS, please install Throne via `programs.throne.enable` and then set the `programs.throne.tunMode.enable` option to elevate privileges."),
|
||||
+ QMessageBox::Ok
|
||||
+ );
|
||||
+ return false;
|
||||
+ // The following code isn't effective, preserve to avoid merge conflict
|
||||
+
|
||||
#ifdef Q_OS_LINUX
|
||||
if (!Linux_HavePkexec()) {
|
||||
MessageBoxWarning(software_name, "Please install \"pkexec\" first.");
|
||||
@@ -21,22 +21,24 @@
|
||||
# To get the latest revision go to the rule-set branch and get the revision of the last commit
|
||||
# Link: https://github.com/throneproj/routeprofiles/tree/rule-set
|
||||
throne-srslist-info ? {
|
||||
rev = "bf5016b114a2dee6a31aa269093de38892fb9df4";
|
||||
hash = "sha256-RfyFSCecfY1SfvO62nW72+4JLAP7qX8KmmWFGhRrC8I=";
|
||||
rev = "1aa995b5fc30c26b931a61171aea2ab49c3d1711";
|
||||
hash = "sha256-jKYUjgxpE1zwcVv+9Fdj8H1QnPZpTzmzVsMfOMOKGFw=";
|
||||
},
|
||||
}:
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "throne";
|
||||
version = "1.2.4";
|
||||
version = "1.3.1";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "throneproj";
|
||||
repo = "Throne";
|
||||
tag = finalAttrs.version;
|
||||
hash = "sha256-fDaU3xjrpjeW8MePBaj5aNGJ2GrNQ3/M3LhtBoU+I/A=";
|
||||
hash = "sha256-G1i8nFMabkg7qUbqYq/GYXsREXRcSXtDSO+RgiuulIE=";
|
||||
};
|
||||
|
||||
# NKR_ELEVATION_HINT contains spaces
|
||||
__structuredAttrs = true;
|
||||
strictDeps = true;
|
||||
|
||||
nativeBuildInputs = [
|
||||
@@ -51,21 +53,22 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
qt6Packages.qttools
|
||||
];
|
||||
|
||||
cmakeFlags = [
|
||||
# use a writable config dir
|
||||
(lib.cmakeBool "NKR_PACKAGE" true)
|
||||
# use ThroneCore from PATH first to make use of security wrappers
|
||||
(lib.cmakeBool "NKR_CORE_IN_PATH" true)
|
||||
# the Exec field of the auto-run and the scheme-handler .desktop files
|
||||
(lib.cmakeFeature "NKR_DESKTOP_EXEC" "Throne")
|
||||
# suid cannot be set on ThroneCore in the Nix store, so point users to the NixOS module instead
|
||||
(lib.cmakeFeature "NKR_ELEVATION_HINT" "On NixOS, use programs.throne with tunMode.enable.")
|
||||
];
|
||||
|
||||
env.INPUT_VERSION = finalAttrs.version;
|
||||
|
||||
# suppress errors in 3rdparty/simple-protobuf
|
||||
env.NIX_CFLAGS_COMPILE = "-Wno-error=maybe-uninitialized";
|
||||
|
||||
patches = [
|
||||
# disable suid request as it cannot be applied to ThroneCore in nix store
|
||||
# and prompt users to use NixOS module instead. And use ThroneCore from PATH
|
||||
# to make use of security wrappers
|
||||
./nixos-disable-setuid-request.patch
|
||||
|
||||
# sets the Exec field of the auto-run and the scheme-handler .desktop files to use the Throne binary from PATH
|
||||
./fix-desktop-exec.patch
|
||||
];
|
||||
|
||||
preBuild =
|
||||
let
|
||||
srslist = fetchurl {
|
||||
@@ -87,8 +90,7 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
install -Dm755 Throne -t "$out/share/throne/"
|
||||
install -Dm644 "$src/res/public/Throne.png" -t "$out/share/icons/hicolor/512x512/apps/"
|
||||
|
||||
makeQtWrapper "$out/share/throne/Throne" "$out/bin/Throne" \
|
||||
--append-flag "-appdata" # use writable config dir
|
||||
makeQtWrapper "$out/share/throne/Throne" "$out/bin/Throne"
|
||||
|
||||
ln -s ${finalAttrs.passthru.core}/bin/ThroneCore "$out/share/throne/ThroneCore"
|
||||
|
||||
@@ -110,17 +112,15 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
passthru.core = buildGoModule {
|
||||
pname = "throne-core";
|
||||
inherit (finalAttrs) version src;
|
||||
modRoot = "./core/server";
|
||||
modRoot = "./core";
|
||||
|
||||
patches = [
|
||||
# also check cap_net_admin so we don't have to set suid
|
||||
./core-also-check-capabilities.patch
|
||||
# skip cmd/schemagen, a development tool
|
||||
subPackages = [ "." ];
|
||||
|
||||
# disable a security check, which hopefully is not too bad
|
||||
./dont-check-parent.patch
|
||||
];
|
||||
# the main package has no tests, checkPhase would only rebuild all deps without -trimpath
|
||||
doCheck = false;
|
||||
|
||||
vendorHash = "sha256-qr45kA/xw3NARNUAj5OMjNE1JUeYQXkEXArsyc9K5jA=";
|
||||
vendorHash = "sha256-L189eeaYDdDKGJYT5vr412YpTgHptVfC4jpNSjNcyuk=";
|
||||
|
||||
nativeBuildInputs = [
|
||||
protobuf
|
||||
@@ -163,10 +163,13 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
"with_utls"
|
||||
"with_dhcp"
|
||||
"with_tailscale"
|
||||
"with_openvpn"
|
||||
"with_openconnect"
|
||||
"badlinkname"
|
||||
"tfogo_checklinkname"
|
||||
"tfogo_checklinkname0"
|
||||
"with_naive_outbound"
|
||||
"with_purego" # use prebuilt .so instead of prebuilt .a files for cronet-go
|
||||
"noparentcheck" # ThroneCore and its security-wrapper live under a different store path than the GUI
|
||||
];
|
||||
};
|
||||
|
||||
@@ -186,6 +189,7 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
maintainers = with lib.maintainers; [
|
||||
tomasajt
|
||||
aleksana
|
||||
Mahdi-zarei
|
||||
];
|
||||
platforms = lib.platforms.linux;
|
||||
sourceProvenance = with lib.sourceTypes; [
|
||||
|
||||
Reference in New Issue
Block a user