libsecret: switch to gnutls

- libgcrypt being based on gnupg codebase has had a few "interesting" security incidents recently
- libsecret exposes `gnutls` as alternative crypto backend [1]
  - all tests still pass
  - only the implementation of `service_decode_aes_secret` is affected
    - this is not an exported symbol
  - this reduces closure size (gnutls is in the closure anyways, libgcrypt would be on-top after recent changes)
  - this reduces attack surface (gnutls is in the closure anyways, libgcrypt would be additional attack surface)
- after recent changes, libsecret is currently the largest consumer of libgcrypt

[1] a5cd57f103/meson.build (L40-58)
This commit is contained in:
Grimmauld
2026-09-16 10:30:01 +02:00
parent 7ec9d15cdf
commit 47dd164970

View File

@@ -12,7 +12,7 @@
python3Packages,
docbook-xsl-nons,
docbook_xml_dtd_42,
libgcrypt,
gnutls,
gobject-introspection,
buildPackages,
withIntrospection ?
@@ -106,7 +106,7 @@ stdenv.mkDerivation (finalAttrs: {
];
buildInputs = [
libgcrypt
gnutls
]
++ lib.optionals withTpm2Tss [ tpm2-tss ]
++ lib.optionals abrmdSupport [ tpm2-abrmd ];
@@ -128,6 +128,7 @@ stdenv.mkDerivation (finalAttrs: {
(lib.mesonBool "gtk_doc" withIntrospection)
(lib.mesonBool "tpm2" withTpm2Tss)
(lib.mesonOption "bashcompdir" "share/bash-completion/completions")
(lib.mesonOption "crypto" "gnutls")
];
doCheck = stdenv.hostPlatform.isLinux && withIntrospection;