diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 922e0c1ed7a1..3602e064f4b3 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -17645,6 +17645,12 @@ githubId = 85435692; name = "Maxwell Berg"; }; + Mahdi-zarei = { + email = "mahdi.zrei@gmail.com"; + github = "Mahdi-zarei"; + githubId = 80265960; + name = "Mahdi"; + }; mahe = { email = "matthias.mh.herrmann@gmail.com"; github = "2chilled"; diff --git a/pkgs/by-name/th/throne/core-also-check-capabilities.patch b/pkgs/by-name/th/throne/core-also-check-capabilities.patch deleted file mode 100644 index 0f12415e5e59..000000000000 --- a/pkgs/by-name/th/throne/core-also-check-capabilities.patch +++ /dev/null @@ -1,40 +0,0 @@ -diff --git a/core/server/server.go b/core/server/server.go -index 4499a6d..4c14d1a 100644 ---- a/core/server/server.go -+++ b/core/server/server.go -@@ -24,6 +24,7 @@ import ( - "github.com/sagernet/sing-box/experimental/clashapi" - "github.com/sagernet/sing/common" - E "github.com/sagernet/sing/common/exceptions" -+ "golang.org/x/sys/unix" - "github.com/sagernet/sing/service" - "github.com/xtls/xray-core/core" - ) -@@ -462,6 +463,27 @@ func (s *server) IsPrivileged(ctx context.Context, _ *gen.EmptyReq) (*gen.IsPriv - }, nil - } - -+ if runtime.GOOS == "linux" { -+ caps := unix.CapUserHeader{ -+ Version: unix.LINUX_CAPABILITY_VERSION_3, -+ Pid: 0, // current -+ } -+ -+ var data [2]unix.CapUserData -+ err := unix.Capget(&caps, &data[0]) -+ -+ if err != nil { -+ return &gen.IsPrivilegedResponse{ -+ HasPrivilege: To(false), -+ }, nil -+ } -+ -+ // CAP_NET_ADMIN = 12 -+ return &gen.IsPrivilegedResponse{ -+ HasPrivilege: To((data[0].Effective & (1 << unix.CAP_NET_ADMIN)) != 0), -+ }, nil -+ } -+ - return &gen.IsPrivilegedResponse{HasPrivilege: To(os.Geteuid() == 0)}, nil - } - diff --git a/pkgs/by-name/th/throne/dont-check-parent.patch b/pkgs/by-name/th/throne/dont-check-parent.patch deleted file mode 100644 index cb2dce830e1e..000000000000 --- a/pkgs/by-name/th/throne/dont-check-parent.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/core/server/parentcheck/parentcheck.go b/core/server/parentcheck/parentcheck.go -index 0991a7f..58fd32f 100644 ---- a/core/server/parentcheck/parentcheck.go -+++ b/core/server/parentcheck/parentcheck.go -@@ -11,6 +11,8 @@ import ( - ) - - func CheckParentProcess() { -+ return -+ - parentPath, err := getParentExePath(ParentPID) - if err != nil { - log.Fatalf("parent check: cannot read parent executable: %v", err) diff --git a/pkgs/by-name/th/throne/fix-desktop-exec.patch b/pkgs/by-name/th/throne/fix-desktop-exec.patch deleted file mode 100644 index 683c63893a72..000000000000 --- a/pkgs/by-name/th/throne/fix-desktop-exec.patch +++ /dev/null @@ -1,39 +0,0 @@ -diff --git a/src/sys/linux/AutoRun.cpp b/src/sys/linux/AutoRun.cpp -index 1fafe35..a32e7fe 100644 ---- a/src/sys/linux/AutoRun.cpp -+++ b/src/sys/linux/AutoRun.cpp -@@ -31,18 +31,9 @@ void AutoRun_SetEnabled(bool enable) { - QString desktopFileLocation = userAutoStartPath + appName + QLatin1String(".desktop"); - QStringList appCmdList; - -- if (QProcessEnvironment::systemEnvironment().contains("APPIMAGE")) { -- appCmdList << QProcessEnvironment::systemEnvironment().value("APPIMAGE"); -- } else { -- appCmdList << QApplication::applicationFilePath(); -- } -- -+ appCmdList << "Throne"; - appCmdList << "-tray"; - -- if (Configs::dataManager->settingsRepo->flag_use_appdata) { -- appCmdList << "-appdata"; -- } -- - if (enable) { - if (!QDir().exists(userAutoStartPath) && !QDir().mkpath(userAutoStartPath)) { - // qCWarning(lcUtility) << "Could not create autostart folder" -diff --git a/src/sys/linux/UrlScheme.cpp b/src/sys/linux/UrlScheme.cpp -index 63e4118..a9d3a42 100644 ---- a/src/sys/linux/UrlScheme.cpp -+++ b/src/sys/linux/UrlScheme.cpp -@@ -14,9 +14,7 @@ static const QString kDesktopId = "throne-url-handler.desktop"; - // For AppImage the launcher must point at the outer image ($APPIMAGE), not the - // extracted binary inside the mount, which disappears after exit. - static QString execTarget() { -- auto env = QProcessEnvironment::systemEnvironment(); -- if (env.contains("APPIMAGE")) return env.value("APPIMAGE"); -- return QApplication::applicationFilePath(); -+ return "Throne"; - } - - static QString desktopFilePath() { diff --git a/pkgs/by-name/th/throne/nixos-disable-setuid-request.patch b/pkgs/by-name/th/throne/nixos-disable-setuid-request.patch deleted file mode 100644 index 510c5961b3af..000000000000 --- a/pkgs/by-name/th/throne/nixos-disable-setuid-request.patch +++ /dev/null @@ -1,51 +0,0 @@ -diff --git a/src/global/Configs.cpp b/src/global/Configs.cpp -index 9600a95..ee38aaa 100644 ---- a/src/global/Configs.cpp -+++ b/src/global/Configs.cpp -@@ -45,6 +45,12 @@ namespace Configs { - } - - QString FindCoreRealPath() { -+ // find in PATH first -+ QString path_for_nixos = QStandardPaths::findExecutable("ThroneCore"); -+ if (!path_for_nixos.isEmpty()) { -+ return path_for_nixos; -+ } -+ - auto fn = QApplication::applicationDirPath() + "/ThroneCore"; - #ifdef Q_OS_WIN - fn += ".exe"; -diff --git a/src/ui/mainWindow/mainwindow_setup.cpp b/src/ui/mainWindow/mainwindow_setup.cpp -index 7bec187..0f04cc8 100644 ---- a/src/ui/mainWindow/mainwindow_setup.cpp -+++ b/src/ui/mainWindow/mainwindow_setup.cpp -@@ -207,8 +207,7 @@ MainWindow::MainWindow(QWidget *parent) : QMainWindow(parent), ui(new Ui::MainWi - runOnNewThread([=, this] {GetDeviceDetails(); }); - - // Prepare core -- auto core_path = QApplication::applicationDirPath() + "/"; -- core_path += "ThroneCore"; -+ auto core_path = Configs::FindCoreRealPath(); - - bool coreDebugMode = (Configs::dataManager->settingsRepo->log_level == "debug"); - -diff --git a/src/ui/mainWindow/mainwindow_system.cpp b/src/ui/mainWindow/mainwindow_system.cpp -index f1a7504..efffd4a 100644 ---- a/src/ui/mainWindow/mainwindow_system.cpp -+++ b/src/ui/mainWindow/mainwindow_system.cpp -@@ -193,6 +193,15 @@ bool MainWindow::get_elevated_permissions(ExitReason reason) { - return true; - } - if (Configs::IsAdmin()) return true; -+ QMessageBox::critical( -+ GetMessageBoxParent(), -+ tr("Unable to elevate privileges when installed with Nix"), -+ tr("Due to the read-only property of the Nix store, we cannot set suid for ThroneCore. If you are using NixOS, please install Throne via `programs.throne.enable` and then set the `programs.throne.tunMode.enable` option to elevate privileges."), -+ QMessageBox::Ok -+ ); -+ return false; -+ // The following code isn't effective, preserve to avoid merge conflict -+ - #ifdef Q_OS_LINUX - if (!Linux_HavePkexec()) { - MessageBoxWarning(software_name, "Please install \"pkexec\" first."); diff --git a/pkgs/by-name/th/throne/package.nix b/pkgs/by-name/th/throne/package.nix index 606c128c567f..93d66872fbc0 100644 --- a/pkgs/by-name/th/throne/package.nix +++ b/pkgs/by-name/th/throne/package.nix @@ -21,22 +21,24 @@ # To get the latest revision go to the rule-set branch and get the revision of the last commit # Link: https://github.com/throneproj/routeprofiles/tree/rule-set throne-srslist-info ? { - rev = "bf5016b114a2dee6a31aa269093de38892fb9df4"; - hash = "sha256-RfyFSCecfY1SfvO62nW72+4JLAP7qX8KmmWFGhRrC8I="; + rev = "1aa995b5fc30c26b931a61171aea2ab49c3d1711"; + hash = "sha256-jKYUjgxpE1zwcVv+9Fdj8H1QnPZpTzmzVsMfOMOKGFw="; }, }: stdenv.mkDerivation (finalAttrs: { pname = "throne"; - version = "1.2.4"; + version = "1.3.1"; src = fetchFromGitHub { owner = "throneproj"; repo = "Throne"; tag = finalAttrs.version; - hash = "sha256-fDaU3xjrpjeW8MePBaj5aNGJ2GrNQ3/M3LhtBoU+I/A="; + hash = "sha256-G1i8nFMabkg7qUbqYq/GYXsREXRcSXtDSO+RgiuulIE="; }; + # NKR_ELEVATION_HINT contains spaces + __structuredAttrs = true; strictDeps = true; nativeBuildInputs = [ @@ -51,21 +53,22 @@ stdenv.mkDerivation (finalAttrs: { qt6Packages.qttools ]; + cmakeFlags = [ + # use a writable config dir + (lib.cmakeBool "NKR_PACKAGE" true) + # use ThroneCore from PATH first to make use of security wrappers + (lib.cmakeBool "NKR_CORE_IN_PATH" true) + # the Exec field of the auto-run and the scheme-handler .desktop files + (lib.cmakeFeature "NKR_DESKTOP_EXEC" "Throne") + # suid cannot be set on ThroneCore in the Nix store, so point users to the NixOS module instead + (lib.cmakeFeature "NKR_ELEVATION_HINT" "On NixOS, use programs.throne with tunMode.enable.") + ]; + env.INPUT_VERSION = finalAttrs.version; # suppress errors in 3rdparty/simple-protobuf env.NIX_CFLAGS_COMPILE = "-Wno-error=maybe-uninitialized"; - patches = [ - # disable suid request as it cannot be applied to ThroneCore in nix store - # and prompt users to use NixOS module instead. And use ThroneCore from PATH - # to make use of security wrappers - ./nixos-disable-setuid-request.patch - - # sets the Exec field of the auto-run and the scheme-handler .desktop files to use the Throne binary from PATH - ./fix-desktop-exec.patch - ]; - preBuild = let srslist = fetchurl { @@ -87,8 +90,7 @@ stdenv.mkDerivation (finalAttrs: { install -Dm755 Throne -t "$out/share/throne/" install -Dm644 "$src/res/public/Throne.png" -t "$out/share/icons/hicolor/512x512/apps/" - makeQtWrapper "$out/share/throne/Throne" "$out/bin/Throne" \ - --append-flag "-appdata" # use writable config dir + makeQtWrapper "$out/share/throne/Throne" "$out/bin/Throne" ln -s ${finalAttrs.passthru.core}/bin/ThroneCore "$out/share/throne/ThroneCore" @@ -110,17 +112,15 @@ stdenv.mkDerivation (finalAttrs: { passthru.core = buildGoModule { pname = "throne-core"; inherit (finalAttrs) version src; - modRoot = "./core/server"; + modRoot = "./core"; - patches = [ - # also check cap_net_admin so we don't have to set suid - ./core-also-check-capabilities.patch + # skip cmd/schemagen, a development tool + subPackages = [ "." ]; - # disable a security check, which hopefully is not too bad - ./dont-check-parent.patch - ]; + # the main package has no tests, checkPhase would only rebuild all deps without -trimpath + doCheck = false; - vendorHash = "sha256-qr45kA/xw3NARNUAj5OMjNE1JUeYQXkEXArsyc9K5jA="; + vendorHash = "sha256-L189eeaYDdDKGJYT5vr412YpTgHptVfC4jpNSjNcyuk="; nativeBuildInputs = [ protobuf @@ -163,10 +163,13 @@ stdenv.mkDerivation (finalAttrs: { "with_utls" "with_dhcp" "with_tailscale" + "with_openvpn" + "with_openconnect" "badlinkname" - "tfogo_checklinkname" + "tfogo_checklinkname0" "with_naive_outbound" "with_purego" # use prebuilt .so instead of prebuilt .a files for cronet-go + "noparentcheck" # ThroneCore and its security-wrapper live under a different store path than the GUI ]; }; @@ -186,6 +189,7 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ tomasajt aleksana + Mahdi-zarei ]; platforms = lib.platforms.linux; sourceProvenance = with lib.sourceTypes; [