From 47dd164970b7958dcd9cf4472fed27e0024a2ef8 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Wed, 16 Sep 2026 10:30:01 +0200 Subject: [PATCH] libsecret: switch to gnutls - libgcrypt being based on gnupg codebase has had a few "interesting" security incidents recently - libsecret exposes `gnutls` as alternative crypto backend [1] - all tests still pass - only the implementation of `service_decode_aes_secret` is affected - this is not an exported symbol - this reduces closure size (gnutls is in the closure anyways, libgcrypt would be on-top after recent changes) - this reduces attack surface (gnutls is in the closure anyways, libgcrypt would be additional attack surface) - after recent changes, libsecret is currently the largest consumer of libgcrypt [1] https://gitlab.gnome.org/GNOME/libsecret/-/blob/a5cd57f103038c06b64d5f6ebfd0e627bb40af4e/meson.build#L40-58 --- pkgs/by-name/li/libsecret/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libsecret/package.nix b/pkgs/by-name/li/libsecret/package.nix index 92ab2fa2f8c1..0926483b7cd7 100644 --- a/pkgs/by-name/li/libsecret/package.nix +++ b/pkgs/by-name/li/libsecret/package.nix @@ -12,7 +12,7 @@ python3Packages, docbook-xsl-nons, docbook_xml_dtd_42, - libgcrypt, + gnutls, gobject-introspection, buildPackages, withIntrospection ? @@ -106,7 +106,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ - libgcrypt + gnutls ] ++ lib.optionals withTpm2Tss [ tpm2-tss ] ++ lib.optionals abrmdSupport [ tpm2-abrmd ]; @@ -128,6 +128,7 @@ stdenv.mkDerivation (finalAttrs: { (lib.mesonBool "gtk_doc" withIntrospection) (lib.mesonBool "tpm2" withTpm2Tss) (lib.mesonOption "bashcompdir" "share/bash-completion/completions") + (lib.mesonOption "crypto" "gnutls") ]; doCheck = stdenv.hostPlatform.isLinux && withIntrospection;