mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-30 11:50:06 +00:00
networkmanager-libreswan: init at 1.2.31
This is a IPsec IKEv1 VPN, Cisco compatible plug-in maintained by the NetworkManager maintainers. https://gitlab.gnome.org/GNOME/NetworkManager-libreswan As per https://networkmanager.dev/docs/vpn/ and https://blogs.gnome.org/mcatanzaro/2026/09/15/privilege-escalation-vulnerabilities-in-networkmanager-plugins/ this is a replacement for the insecure and unmaintained NetworkManager-vpnc but connection profiles have to be recreated and per-option parity has not been checked.
This commit is contained in:
@@ -243,6 +243,7 @@ in
|
||||
with pkgs; [
|
||||
networkmanager-fortisslvpn
|
||||
networkmanager-iodine
|
||||
networkmanager-libreswan
|
||||
networkmanager-l2tp
|
||||
networkmanager-openconnect
|
||||
networkmanager-openvpn
|
||||
|
||||
48
pkgs/by-name/ne/networkmanager-libreswan/fix-paths.patch
Normal file
48
pkgs/by-name/ne/networkmanager-libreswan/fix-paths.patch
Normal file
@@ -0,0 +1,48 @@
|
||||
diff --git a/properties/nm-libreswan-editor-plugin.c b/properties/nm-libreswan-editor-plugin.c
|
||||
index 6a178af..787e183 100644
|
||||
--- a/properties/nm-libreswan-editor-plugin.c
|
||||
+++ b/properties/nm-libreswan-editor-plugin.c
|
||||
@@ -96,7 +96,7 @@ export_to_file(NMVpnEditorPlugin *self, const char *path, NMConnection *connecti
|
||||
|
||||
openswan = nm_streq(nm_setting_vpn_get_service_type(s_vpn), NM_VPN_SERVICE_TYPE_OPENSWAN);
|
||||
|
||||
- nm_libreswan_detect_version(nm_libreswan_find_helper_bin("ipsec", NULL),
|
||||
+ nm_libreswan_detect_version("@ipsec@",
|
||||
&is_openswan,
|
||||
&version,
|
||||
NULL);
|
||||
diff --git a/src/nm-libreswan-service.c b/src/nm-libreswan-service.c
|
||||
index 0458d4e..e0add02 100644
|
||||
--- a/src/nm-libreswan-service.c
|
||||
+++ b/src/nm-libreswan-service.c
|
||||
@@ -1820,7 +1820,7 @@ connect_step(NMLibreswanPlugin *self, GError **error)
|
||||
if (!priv->openswan) {
|
||||
const char *stackman_path;
|
||||
|
||||
- stackman_path = nm_libreswan_find_helper_libexec("_stackmanager", error);
|
||||
+ stackman_path = "@libreswan@/libexec/_stackmanager";
|
||||
if (!stackman_path)
|
||||
return FALSE;
|
||||
|
||||
@@ -1977,7 +1977,7 @@ _connect_common(NMVpnServicePlugin *plugin,
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
- priv->ipsec_path = nm_libreswan_find_helper_bin("ipsec", error);
|
||||
+ priv->ipsec_path = "@ipsec@";
|
||||
if (!priv->ipsec_path)
|
||||
return FALSE;
|
||||
|
||||
@@ -1988,10 +1988,10 @@ _connect_common(NMVpnServicePlugin *plugin,
|
||||
priv->openswan ? "Openswan" : "Libreswan");
|
||||
|
||||
if (!priv->openswan) {
|
||||
- priv->pluto_path = nm_libreswan_find_helper_libexec("pluto", error);
|
||||
+ priv->pluto_path = "@libreswan@/libexec/pluto";
|
||||
if (!priv->pluto_path)
|
||||
return FALSE;
|
||||
- priv->whack_path = nm_libreswan_find_helper_libexec("whack", error);
|
||||
+ priv->whack_path = "@libreswan@/libexec/whack";
|
||||
if (!priv->whack_path)
|
||||
return FALSE;
|
||||
}
|
||||
85
pkgs/by-name/ne/networkmanager-libreswan/package.nix
Normal file
85
pkgs/by-name/ne/networkmanager-libreswan/package.nix
Normal file
@@ -0,0 +1,85 @@
|
||||
{
|
||||
dieHook,
|
||||
fetchpatch,
|
||||
fetchurl,
|
||||
glib,
|
||||
gnome,
|
||||
gtk3,
|
||||
gtk4,
|
||||
intltool,
|
||||
lib,
|
||||
libnl,
|
||||
libnma,
|
||||
libnma-gtk4,
|
||||
libreswan,
|
||||
libsecret,
|
||||
networkmanager,
|
||||
pkg-config,
|
||||
replaceVars,
|
||||
stdenv,
|
||||
withGnome ? true,
|
||||
}:
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "NetworkManager-libreswan";
|
||||
version = "1.2.31";
|
||||
|
||||
src = fetchurl {
|
||||
url = "mirror://gnome/sources/NetworkManager-libreswan/${lib.versions.majorMinor finalAttrs.version}/NetworkManager-libreswan-${finalAttrs.version}.tar.xz";
|
||||
hash = "sha256-5xq3zWruZoOqlDQusm5hQzv/3y2ml4LsptHCmdzDp28=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
(replaceVars ./fix-paths.patch {
|
||||
ipsec = lib.getExe' libreswan "ipsec";
|
||||
inherit libreswan;
|
||||
})
|
||||
];
|
||||
|
||||
nativeBuildInputs = [
|
||||
dieHook
|
||||
glib
|
||||
intltool
|
||||
pkg-config
|
||||
];
|
||||
|
||||
buildInputs = [
|
||||
libnl
|
||||
networkmanager
|
||||
]
|
||||
++ lib.optionals withGnome [
|
||||
gtk3
|
||||
gtk4
|
||||
libnma
|
||||
libnma-gtk4
|
||||
libsecret
|
||||
];
|
||||
|
||||
configureFlags = [
|
||||
"--with-gnome=${lib.boolToYesNo withGnome}"
|
||||
"--with-gtk4=${lib.boolToYesNo withGnome}"
|
||||
"--enable-absolute-paths"
|
||||
];
|
||||
|
||||
strictDeps = true;
|
||||
__structuredAttrs = true;
|
||||
|
||||
postPatch = ''
|
||||
echo "Ensuring that all helper paths lookups were replaced"
|
||||
! grep -lr nm_libreswan_find_helper --exclude 'utils.[ch]' || die "^ Found non-replaced helper lookup"
|
||||
'';
|
||||
|
||||
passthru = {
|
||||
updateScript = gnome.updateScript {
|
||||
packageName = "NetworkManager-libreswan";
|
||||
attrPath = "networkmanager-libreswan";
|
||||
};
|
||||
networkManagerPlugin = "VPN/nm-libreswan-service.name";
|
||||
};
|
||||
|
||||
meta = {
|
||||
description = "NetworkManager's libreswan plugin";
|
||||
inherit (networkmanager.meta) maintainers teams platforms;
|
||||
license = lib.licenses.gpl2Plus;
|
||||
};
|
||||
})
|
||||
Reference in New Issue
Block a user