diff --git a/pkgs/development/libraries/openldap/default.nix b/pkgs/development/libraries/openldap/default.nix index fdf3298a6fad..db25363593a8 100644 --- a/pkgs/development/libraries/openldap/default.nix +++ b/pkgs/development/libraries/openldap/default.nix @@ -2,11 +2,11 @@ stdenv.mkDerivation rec { pname = "openldap"; - version = "2.4.56"; + version = "2.4.57"; src = fetchurl { url = "https://www.openldap.org/software/download/OpenLDAP/openldap-release/${pname}-${version}.tgz"; - sha256 = "1q0m26kbab96r73y0dll0c36411kvfillal0i75kngy9cc1hwli5"; + sha256 = "sha256-x7pH4ebstbQ289Qygd9Xq+/6mSYhQa7IImKLwiD2tFo="; }; # TODO: separate "out" and "bin" diff --git a/pkgs/development/libraries/qt-5/modules/qtwebengine.nix b/pkgs/development/libraries/qt-5/modules/qtwebengine.nix index b98b711c0f5d..582044a27e56 100644 --- a/pkgs/development/libraries/qt-5/modules/qtwebengine.nix +++ b/pkgs/development/libraries/qt-5/modules/qtwebengine.nix @@ -218,6 +218,8 @@ qtModule { description = "A web engine based on the Chromium web browser"; maintainers = with maintainers; [ matthewbauer ]; platforms = platforms.unix; + # This build takes a long time; particularly on slow architectures + timeout = 24 * 3600; }; } diff --git a/pkgs/development/libraries/science/math/openblas/default.nix b/pkgs/development/libraries/science/math/openblas/default.nix index 89d88bdf564a..28299971b81a 100644 --- a/pkgs/development/libraries/science/math/openblas/default.nix +++ b/pkgs/development/libraries/science/math/openblas/default.nix @@ -15,8 +15,8 @@ # Select a specific optimization target (other than the default) # See https://github.com/xianyi/OpenBLAS/blob/develop/TargetList.txt , target ? null -, enableStatic ? false -, enableShared ? true +, enableStatic ? stdenv.hostPlatform.isStatic +, enableShared ? !stdenv.hostPlatform.isStatic }: with stdenv.lib; @@ -71,6 +71,13 @@ let NO_AVX512 = true; USE_OPENMP = !stdenv.hostPlatform.isMusl; }; + + powerpc64le-linux = { + BINARY = 64; + TARGET = setTarget "POWER5"; + DYNAMIC_ARCH = true; + USE_OPENMP = !stdenv.hostPlatform.isMusl; + }; }; in @@ -99,12 +106,12 @@ let in stdenv.mkDerivation rec { pname = "openblas"; - version = "0.3.10"; + version = "0.3.13"; src = fetchFromGitHub { owner = "xianyi"; repo = "OpenBLAS"; rev = "v${version}"; - sha256 = "174id98ga82bhz2v7sy9yj6pqy0h0088p3mkdikip69p9rh3d17b"; + sha256 = "14jxh0v3jfbw4mfjx4mcz4dd51lyq7pqvh9k8dg94539ypzjr2lj"; }; inherit blas64; @@ -134,12 +141,6 @@ stdenv.mkDerivation rec { buildPackages.stdenv.cc ]; - # Disable an optimisation which seems to cause issues, pending an - # upstream fix: https://github.com/xianyi/OpenBLAS/issues/2496 - patches = stdenv.lib.optionals stdenv.hostPlatform.isAarch64 [ - ./0001-Disable-optimised-aarch64-dgemm_beta-pending-fix.patch - ]; - makeFlags = mkMakeFlagsFromConfig (config // { FC = "${stdenv.cc.targetPrefix}gfortran"; CC = "${stdenv.cc.targetPrefix}${if stdenv.cc.isClang then "clang" else "cc"}"; diff --git a/pkgs/development/python-modules/lxml/default.nix b/pkgs/development/python-modules/lxml/default.nix index aa009e0a3e73..b58376031039 100644 --- a/pkgs/development/python-modules/lxml/default.nix +++ b/pkgs/development/python-modules/lxml/default.nix @@ -7,13 +7,13 @@ buildPythonPackage rec { pname = "lxml"; - version = "4.5.2"; + version = "4.6.2"; src = fetchFromGitHub { owner = pname; repo = pname; rev = "${pname}-${version}"; - sha256 = "1d0cpwdjxfzwjzmnz066ibzicyj2vhx15qxmm775l8hxqi65xps4"; + sha256 = "1zidx62sxh2r4fmjfjzd4f6i4yxgzkpd20nafbyr0i0wnw9da3fd"; }; # setuptoolsBuildPhase needs dependencies to be passed through nativeBuildInputs diff --git a/pkgs/development/python-modules/pillow/7.2.0-CVE-2020-35653.patch b/pkgs/development/python-modules/pillow/7.2.0-CVE-2020-35653.patch new file mode 100644 index 000000000000..1a8b67c10cdd --- /dev/null +++ b/pkgs/development/python-modules/pillow/7.2.0-CVE-2020-35653.patch @@ -0,0 +1,75 @@ +Modified version of https://github.com/python-pillow/Pillow/commit/3757b8c7485f9d804f4a96772384543b4fe59121 +--- a/Tests/test_image.py ++++ b/Tests/test_image.py +@@ -775,26 +775,29 @@ + with pytest.warns(DeprecationWarning): + assert test_module.PILLOW_VERSION > "7.0.0" + +- def test_overrun(self): +- """ For overrun completeness, test as: +- valgrind pytest -qq Tests/test_image.py::TestImage::test_overrun | grep decode.c +- """ +- for file in [ ++ @pytest.mark.parametrize("path", [ + "fli_overrun.bin", + "sgi_overrun.bin", + "sgi_overrun_expandrow.bin", + "sgi_overrun_expandrow2.bin", + "pcx_overrun.bin", + "pcx_overrun2.bin", ++ "ossfuzz-4836216264589312.pcx", + "01r_00.pcx", +- ]: +- with Image.open(os.path.join("Tests/images", file)) as im: +- try: +- im.load() +- assert False +- except OSError as e: +- assert str(e) == "buffer overrun when reading image file" ++ ]) ++ def test_overrun(self, path): ++ """For overrun completeness, test as: ++ valgrind pytest -qq Tests/test_image.py::TestImage::test_overrun | grep decode.c ++ """ ++ with Image.open(os.path.join("Tests/images", path)) as im: ++ try: ++ im.load() ++ assert False ++ except OSError as e: ++ assert (str(e) == "buffer overrun when reading image file" or ++ "image file is truncated" in str(e)) + ++ def test_fli_overrun2(self): + with Image.open("Tests/images/fli_overrun2.bin") as im: + try: + im.seek(1) +--- a/src/PIL/PcxImagePlugin.py ++++ b/src/PIL/PcxImagePlugin.py +@@ -66,13 +66,13 @@ + version = i8(s[1]) + bits = i8(s[3]) + planes = i8(s[65]) +- stride = i16(s, 66) ++ ignored_stride = i16(s, 66) + logger.debug( + "PCX version %s, bits %s, planes %s, stride %s", + version, + bits, + planes, +- stride, ++ ignored_stride, + ) + + self.info["dpi"] = i16(s, 12), i16(s, 14) +@@ -110,6 +110,11 @@ + self.mode = mode + self._size = bbox[2] - bbox[0], bbox[3] - bbox[1] + ++ # don't trust the passed in stride. Calculate for ourselves. ++ # CVE-2020-35655 ++ stride = (self._size[0] * bits + 7) // 8 ++ stride += stride % 2 ++ + bbox = (0, 0) + self.size + logger.debug("size: %sx%s", *self.size) + diff --git a/pkgs/development/python-modules/pillow/default.nix b/pkgs/development/python-modules/pillow/default.nix index ab971e4201b5..0ef73143b651 100644 --- a/pkgs/development/python-modules/pillow/default.nix +++ b/pkgs/development/python-modules/pillow/default.nix @@ -1,4 +1,4 @@ -{ stdenv, buildPythonPackage, fetchPypi, isPyPy +{ stdenv, buildPythonPackage, fetchPypi, fetchpatch, fetchurl, isPyPy , olefile , freetype, libjpeg, zlib, libtiff, libwebp, tcl, lcms2, tk, libX11 , openjpeg, libimagequant @@ -17,11 +17,80 @@ buildPythonPackage rec { sha256 = "97f9e7953a77d5a70f49b9a48da7776dc51e9b738151b22dacf101641594a626"; }; + patches = [ + ./7.2.0-CVE-2020-35653.patch + (fetchpatch { + name = "CVE-2020-35654.prerequisite-1.patch"; + url = "https://github.com/python-pillow/Pillow/commit/21533e4deba80290bbc46f1a9e660196f75be45f.patch"; + sha256 = "19i7svxqlcz02ffcx1n1r6brf4m2iqm3k0zq3wd8k1pj2zw9gkhi"; + }) + (fetchpatch { + name = "CVE-2020-35654.prerequisite-2.patch"; + url = "https://github.com/python-pillow/Pillow/commit/26bf1c352489c9e847ff770cd752e97fda5b82cb.patch"; + sha256 = "0h4ch8in2ljz3qgah7k8nwzby1kg02p0fbkg8zzvmmkms051v0im"; + }) + (fetchpatch { + name = "CVE-2020-35654.part-1.patch"; + url = "https://github.com/python-pillow/Pillow/commit/eb8c1206d6b170d4e798a00db7432e023853da5c.patch"; + sha256 = "0cw1hp9irzhgh52s9g5mb6j6cry5gz2n5al4sy1sl5k998h76qaq"; + }) + (fetchpatch { + name = "CVE-2020-35654.part-2.patch"; + url = "https://github.com/python-pillow/Pillow/commit/45a62e91b1f72e79989a7919af97b062dc8dfaf4.patch"; + sha256 = "1kk4jrbz1h74pa5racxc1skp0rgwb00b8ybfyb7v7wmc34f1lm8f"; + }) + (fetchpatch { + name = "CVE-2020-35655.part-1.patch"; + url = "https://github.com/python-pillow/Pillow/commit/7e95c63fa7f503f185d3d9eb16b9cee1e54d1e46.patch"; + sha256 = "15zjkiwcmnv70vy1cfwrvzkfjmgclw4fzvina4rjd8xqap9na5fr"; + }) + (fetchpatch { + name = "CVE-2020-35655.part-2.patch"; + url = "https://github.com/python-pillow/Pillow/commit/9a2c9f722f78773e608d44710873437baf3f17d1.patch"; + sha256 = "15dhzd3i8xwx2iaff2qp6z3h0b2yrzcmqi6x7ngld96805gf7v2q"; + }) + ]; + + # patching mechanism doesn't work with binary files, but the commits contain + # example images needed for the accompanying tests, so invent our own mechanism + # to put these in place + injectMissingBinFiles = stdenv.lib.concatMapStrings ({commit, sha256, path}: let + src = fetchurl { + inherit sha256; + url = "https://github.com/python-pillow/Pillow/raw/${commit}/${path}"; + }; + dest = path; + in '' + cp ${src} ${dest} + '' + ) [ + { # needed by CVE-2020-35653.patch + commit = "2f409261eb1228e166868f8f0b5da5cda52e55bf"; + sha256 = "1gf7zn0qv0i8qvr22sm9azchwizb9aa4xxipy6x5lh7kgb974g0f"; + path = "Tests/images/ossfuzz-4836216264589312.pcx"; + } + { # needed by CVE-2020-35654.part-1.patch + commit = "eb8c1206d6b170d4e798a00db7432e023853da5c"; + sha256 = "0v7jg2xdqzyq3rq6jq0ipsy335sw557symv5jrcz9rdfgkbafh92"; + path = "Tests/images/crash-2020-10-test.tif"; + } + { # needed by CVE-2020-35655.part-1.patch + commit = "7e95c63fa7f503f185d3d9eb16b9cee1e54d1e46"; + sha256 = "0jkzwnv11c1h3hy0ri6kqvcjj800armzrvwc9724ivnm2id8qi8z"; + path = "Tests/images/crash-6b7f2244da6d0ae297ee0754a424213444e92778.sgi"; + } + { # needed by CVE-2020-35655.part-1.patch + commit = "7e95c63fa7f503f185d3d9eb16b9cee1e54d1e46"; + sha256 = "0is0r49pbaxy8mgp5fdlx9hm7zdp64ij38hzgnjj9pzxxdrcw3qk"; + path = "Tests/images/ossfuzz-5730089102868480.sgi"; + } + ]; + # Disable imagefont tests, because they don't work well with infinality: # https://github.com/python-pillow/Pillow/issues/1259 postPatch = '' rm Tests/test_imagefont.py - ''; + '' + injectMissingBinFiles; # Disable darwin tests which require executables: `iconutil` and `screencapture` disabledTests = stdenv.lib.optionals stdenv.isDarwin [ "test_save" "test_grab" "test_grabclipboard" ]; diff --git a/pkgs/servers/sql/postgresql/default.nix b/pkgs/servers/sql/postgresql/default.nix index cb11afee3e69..0c575544ceda 100644 --- a/pkgs/servers/sql/postgresql/default.nix +++ b/pkgs/servers/sql/postgresql/default.nix @@ -183,41 +183,41 @@ let in self: { postgresql_9_5 = self.callPackage generic { - version = "9.5.24"; + version = "9.5.25"; psqlSchema = "9.5"; - sha256 = "0an2k4m1da96897hyxlff8p4p63wg4dffwsfg57aib7mp4yzsp06"; + sha256 = "00yny0sskxrqk4ji2phgv3iqxd1aiy6rh660k73s4s1pn9gcaa3n"; this = self.postgresql_9_5; inherit self; }; postgresql_9_6 = self.callPackage generic { - version = "9.6.20"; + version = "9.6.21"; psqlSchema = "9.6"; - sha256 = "1dkv916y7vrfbygrfbfvs6y3fxaysnh32i5j88nvcnnl16jcn21x"; + sha256 = "0d0ngpadf1i7c0i2psaxcbmiwx8334ibcsn283n9fp4853pyl3wk"; this = self.postgresql_9_6; inherit self; }; postgresql_10 = self.callPackage generic { - version = "10.15"; + version = "10.16"; psqlSchema = "10.0"; # should be 10, but changing it is invasive - sha256 = "0zhzj9skag1pgqas2rnd217vj41ilaalqna17j47gyngpvhbqmjr"; + sha256 = "1cvv8qw0gkkczqhiwx6ns7w88dwkvdz4cvb2d4ff14363f5p2p53"; this = self.postgresql_10; inherit self; }; postgresql_11 = self.callPackage generic { - version = "11.10"; + version = "11.11"; psqlSchema = "11.1"; # should be 11, but changing it is invasive - sha256 = "16bqp6ds37kbwqx7mk5gg3y6gv59wq6xz33iqwxldzk20vwd5rhk"; + sha256 = "0v0qk298nxmpzpgsxcsxma328hdkyzd7fwjs0zsn6zavl5zpnq20"; this = self.postgresql_11; inherit self; }; postgresql_12 = self.callPackage generic { - version = "12.5"; + version = "12.6"; psqlSchema = "12"; - sha256 = "15gzg778da23sbfmy7sqg443f9ny480301lm7i3vay4m3ls2a3dx"; + sha256 = "028asz92mi3706zabfs8w9z03mzyx62d1l71qy9zdwfabj6xjzfz"; this = self.postgresql_12; inherit self; };