From be14653947b6d8289c4f7da47db66fac5187e863 Mon Sep 17 00:00:00 2001 From: yueyinqiu Date: Sun, 27 Sep 2026 23:15:28 +0800 Subject: [PATCH] qq: 3.2.32 -> 3.2.34 Tencent now requires a time-limited signature on the official download URLs, so replace fetchurl with a custom fixed-output fetcher that signs and downloads at build time. update.sh signs URLs before prefetching. See https://github.com/flathub/com.qq.QQ/issues/274 for context. Co-authored-by: chillcicada <116548943+chillcicada@users.noreply.github.com> Co-authored-by: ryan4yin <22363274+ryan4yin@users.noreply.github.com> Assisted-by: opencode (deepseek-v4-pro) --- pkgs/by-name/qq/qq/package.nix | 37 +++++++++++++++++++++++++++++++--- pkgs/by-name/qq/qq/sources.nix | 28 ++++++++++--------------- pkgs/by-name/qq/qq/update.sh | 34 ++++++++++++++++--------------- 3 files changed, 63 insertions(+), 36 deletions(-) diff --git a/pkgs/by-name/qq/qq/package.nix b/pkgs/by-name/qq/qq/package.nix index d70762d0a2cc..a711590a247c 100644 --- a/pkgs/by-name/qq/qq/package.nix +++ b/pkgs/by-name/qq/qq/package.nix @@ -3,7 +3,9 @@ libuuid, cups, dpkg, - fetchurl, + cacert, + curl, + jq, glib, libssh2, gtk3, @@ -19,6 +21,7 @@ nss, libxdamage, systemd, + runCommandLocal, stdenv, undmg, at-spi2-core, @@ -31,12 +34,40 @@ }: let - sources = import ./sources.nix { inherit fetchurl; }; + fetchqq = + { + url, + hash, + }: + runCommandLocal (baseNameOf url) + { + outputHash = hash; + outputHashMode = "flat"; + nativeBuildInputs = [ + curl + jq + cacert + ]; + } + '' + # https://github.com/flathub/com.qq.QQ/issues/274#issuecomment-5512982615 + signedUrl=$( + curl -fsS --retry 3 -X POST "https://im.qq.com/http2rpc/gotrpc/noauth/trpc.qqntv2.urlsign.UrlSign/GetSign" \ + -H "Content-Type: application/json" \ + -H 'x-oidb: {"uint32_command":"0x9b8e","uint32_service_type":1}' \ + -d "{\"url\":\"${url}\"}" | jq -er '.data.url' + ) + curl -fL --retry 3 -o "$out" "$signedUrl" + ''; + sources = import ./sources.nix { }; source = sources.${stdenv.hostPlatform.system} or (throw "Unsupported system: ${stdenv.hostPlatform.system}"); pname = "qq"; - inherit (source) version src; + version = source.version; + src = fetchqq { + inherit (source) url hash; + }; passthru = { # nixpkgs-update: no auto update updateScript = ./update.sh; diff --git a/pkgs/by-name/qq/qq/sources.nix b/pkgs/by-name/qq/qq/sources.nix index 9aa201a84614..8810c0ea00ef 100644 --- a/pkgs/by-name/qq/qq/sources.nix +++ b/pkgs/by-name/qq/qq/sources.nix @@ -1,26 +1,20 @@ # Generated by ./update.sh - do not update manually! -# Last updated: 2026-08-15 -{ fetchurl }: +# Last updated: 2026-09-27 +{ }: { aarch64-darwin = { - version = "7.0.0-2026-08-12"; - src = fetchurl { - url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.33/release/126b7ce6/QQ_7.0.0_260812_01.dmg"; - hash = "sha256-sZXCbfNir1iVTImKsd2YR4Sium9Xpinm+5s+zDv55lw="; - }; + version = "7.0.2-2026-09-24"; + url = "https://qqdl.gtimg.cn/qqfile/QQNTV2/9.9.36/release/837fcb63/QQ_7.0.2_260924_01.dmg"; + hash = "sha256-0nC3jwshBTJjcHZTKog9yGWYUbbaqSRRmDmFq58yFvA="; }; aarch64-linux = { - version = "3.2.32-2026-08-12"; - src = fetchurl { - url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.33/release/3f89efc5/QQ_3.2.32_260812_arm64_01.deb"; - hash = "sha256-h5bM/WaswCXvGNs3GFUy1AvIxYkh4X2m0owpWsvPj5I="; - }; + version = "3.2.34-2026-09-24"; + url = "https://qqdl.gtimg.cn/qqfile/QQNTV2/9.9.36/release/9ee04bef/QQ_3.2.34_260924_arm64_01.deb"; + hash = "sha256-GBuJXLVzVI45blS7BUjMqS/9wbGksBj6RVG7BiOF/co="; }; x86_64-linux = { - version = "3.2.32-2026-08-12"; - src = fetchurl { - url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.33/release/3f89efc5/QQ_3.2.32_260812_amd64_01.deb"; - hash = "sha256-0IXdiTlyJQYeufGUMI9ogSmBjtRFd36XpKChbhPXsOg="; - }; + version = "3.2.34-2026-09-24"; + url = "https://qqdl.gtimg.cn/qqfile/QQNTV2/9.9.36/release/9ee04bef/QQ_3.2.34_260924_amd64_01.deb"; + hash = "sha256-Q2xl4d0oQi4SiiHL3bX+Ti5sB51/J/7CVB4BTTjMM24="; }; } diff --git a/pkgs/by-name/qq/qq/update.sh b/pkgs/by-name/qq/qq/update.sh index af58939b7598..1f831dc2ffeb 100755 --- a/pkgs/by-name/qq/qq/update.sh +++ b/pkgs/by-name/qq/qq/update.sh @@ -5,6 +5,14 @@ set -euo pipefail cd $(readlink -e $(dirname "${BASH_SOURCE[0]}")) +sign_url() { + # https://github.com/flathub/com.qq.QQ/issues/274#issuecomment-5512982615 + curl -fsS -X POST "https://im.qq.com/http2rpc/gotrpc/noauth/trpc.qqntv2.urlsign.UrlSign/GetSign" \ + -H "Content-Type: application/json" \ + -H 'x-oidb: {"uint32_command":"0x9b8e","uint32_service_type":1}' \ + -d "{\"url\":\"$1\"}" | jq -er '.data.url' +} + # darwin darwin_payload=$(curl https://cdn-go.cn/qq-web/im.qq.com_new/latest/rainbow/macOSConfig.js | grep -oP "var params= \K\{.*\}(?=;)") @@ -12,7 +20,7 @@ darwin_version=$(jq -r .version <<< "$darwin_payload" | awk -F\ '{print $1}')-$ darwin_url=$(jq -r .downloadUrl <<< "$darwin_payload") -darwin_hash=$(nix-prefetch-url $darwin_url) +darwin_hash=$(nix-prefetch-url "$(sign_url "$darwin_url")") # use friendlier hashes darwin_hash=$(nix --extra-experimental-features nix-command hash convert --to sri --hash-algo sha256 "$darwin_hash") @@ -25,8 +33,8 @@ linux_version=$(jq -r .version <<< "$linux_payload")-$(jq -r .updateDate <<< "$l linux_aarch64_url=$(jq -r .armDownloadUrl.deb <<< "$linux_payload") linux_x86_64_url=$(jq -r .x64DownloadUrl.deb <<< "$linux_payload") -linux_aarch64_hash=$(nix-prefetch-url $linux_aarch64_url) -linux_x86_64_hash=$(nix-prefetch-url $linux_x86_64_url) +linux_aarch64_hash=$(nix-prefetch-url "$(sign_url "$linux_aarch64_url")") +linux_x86_64_hash=$(nix-prefetch-url "$(sign_url "$linux_x86_64_url")") # use friendlier hashes linux_aarch64_hash=$(nix --extra-experimental-features nix-command hash convert --to sri --hash-algo sha256 "$linux_aarch64_hash") @@ -35,28 +43,22 @@ linux_x86_64_hash=$(nix --extra-experimental-features nix-command hash convert - cat >sources.nix <