From 397c37609a499e68aac0997f5e239978919cb77b Mon Sep 17 00:00:00 2001 From: Joachim Breitner Date: Thu, 7 Jan 2021 20:04:54 +0100 Subject: [PATCH 01/11] openblas: 0.3.10 -> 0.3.13 this backports the effect of the following commits from `master` to 20.09: * f52263ced09 treewide: Start to break up static overlay * d1d536cc07f openblas: 0.3.10 -> 0.3.12 * f715602febc Revert "openblas: 0.3.10 -> 0.3.12" * 840c20169e9 Merge pull request #101715 from r-ryantm/auto-update/openblas * e1a59dddd08 openblas: 0.3.10 -> 0.3.12 * 4e291519102 Revert "Merge pull request #101780 from glittershark/bump-openblas" * 3b4cd4f4dac openblas: 0.3.10 -> 0.3.12 * 692d219a931 Merge staging-next into staging * 7902256cfd1 openblas: enable multiple outputs * 92d7b38e89a openblas: enable on ppc64le * 01378600776 openblas: 0.3.12 -> 0.3.13 The motivation is to unbreak building `python36Packages.scipy` (see issue 92458) --- .../science/math/openblas/default.nix | 24 +++++++++++-------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/pkgs/development/libraries/science/math/openblas/default.nix b/pkgs/development/libraries/science/math/openblas/default.nix index 89d88bdf564a..5573b0eaae75 100644 --- a/pkgs/development/libraries/science/math/openblas/default.nix +++ b/pkgs/development/libraries/science/math/openblas/default.nix @@ -15,8 +15,8 @@ # Select a specific optimization target (other than the default) # See https://github.com/xianyi/OpenBLAS/blob/develop/TargetList.txt , target ? null -, enableStatic ? false -, enableShared ? true +, enableStatic ? stdenv.hostPlatform.isStatic +, enableShared ? !stdenv.hostPlatform.isStatic }: with stdenv.lib; @@ -71,6 +71,13 @@ let NO_AVX512 = true; USE_OPENMP = !stdenv.hostPlatform.isMusl; }; + + powerpc64le-linux = { + BINARY = 64; + TARGET = setTarget "POWER5"; + DYNAMIC_ARCH = true; + USE_OPENMP = !stdenv.hostPlatform.isMusl; + }; }; in @@ -99,12 +106,15 @@ let in stdenv.mkDerivation rec { pname = "openblas"; - version = "0.3.10"; + version = "0.3.13"; + + outputs = [ "out" "dev" ]; + src = fetchFromGitHub { owner = "xianyi"; repo = "OpenBLAS"; rev = "v${version}"; - sha256 = "174id98ga82bhz2v7sy9yj6pqy0h0088p3mkdikip69p9rh3d17b"; + sha256 = "14jxh0v3jfbw4mfjx4mcz4dd51lyq7pqvh9k8dg94539ypzjr2lj"; }; inherit blas64; @@ -134,12 +144,6 @@ stdenv.mkDerivation rec { buildPackages.stdenv.cc ]; - # Disable an optimisation which seems to cause issues, pending an - # upstream fix: https://github.com/xianyi/OpenBLAS/issues/2496 - patches = stdenv.lib.optionals stdenv.hostPlatform.isAarch64 [ - ./0001-Disable-optimised-aarch64-dgemm_beta-pending-fix.patch - ]; - makeFlags = mkMakeFlagsFromConfig (config // { FC = "${stdenv.cc.targetPrefix}gfortran"; CC = "${stdenv.cc.targetPrefix}${if stdenv.cc.isClang then "clang" else "cc"}"; From 5806b6e0c0f1ac798b06aa90016307ffad783917 Mon Sep 17 00:00:00 2001 From: "R. RyanTM" Date: Wed, 20 Jan 2021 14:30:23 +0000 Subject: [PATCH 02/11] openldap: 2.4.56 -> 2.4.57 (cherry picked from commit b833f741e189a495bd27668f17a35b48781069cc) --- pkgs/development/libraries/openldap/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/openldap/default.nix b/pkgs/development/libraries/openldap/default.nix index fdf3298a6fad..db25363593a8 100644 --- a/pkgs/development/libraries/openldap/default.nix +++ b/pkgs/development/libraries/openldap/default.nix @@ -2,11 +2,11 @@ stdenv.mkDerivation rec { pname = "openldap"; - version = "2.4.56"; + version = "2.4.57"; src = fetchurl { url = "https://www.openldap.org/software/download/OpenLDAP/openldap-release/${pname}-${version}.tgz"; - sha256 = "1q0m26kbab96r73y0dll0c36411kvfillal0i75kngy9cc1hwli5"; + sha256 = "sha256-x7pH4ebstbQ289Qygd9Xq+/6mSYhQa7IImKLwiD2tFo="; }; # TODO: separate "out" and "bin" From a3713143cc79e038634780745a2edb598f51fe0a Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Mon, 8 Feb 2021 20:00:47 +0000 Subject: [PATCH 03/11] pythonPackages.pillow: add patches for CVE-2020-35653, CVE-2020-35654, CVE-2020-35655 (#111673) patch for CVE-2020-35653 needed some modification, hence included in-tree. --- .../pillow/7.2.0-CVE-2020-35653.patch | 75 +++++++++++++++++++ .../python-modules/pillow/default.nix | 73 +++++++++++++++++- 2 files changed, 146 insertions(+), 2 deletions(-) create mode 100644 pkgs/development/python-modules/pillow/7.2.0-CVE-2020-35653.patch diff --git a/pkgs/development/python-modules/pillow/7.2.0-CVE-2020-35653.patch b/pkgs/development/python-modules/pillow/7.2.0-CVE-2020-35653.patch new file mode 100644 index 000000000000..1a8b67c10cdd --- /dev/null +++ b/pkgs/development/python-modules/pillow/7.2.0-CVE-2020-35653.patch @@ -0,0 +1,75 @@ +Modified version of https://github.com/python-pillow/Pillow/commit/3757b8c7485f9d804f4a96772384543b4fe59121 +--- a/Tests/test_image.py ++++ b/Tests/test_image.py +@@ -775,26 +775,29 @@ + with pytest.warns(DeprecationWarning): + assert test_module.PILLOW_VERSION > "7.0.0" + +- def test_overrun(self): +- """ For overrun completeness, test as: +- valgrind pytest -qq Tests/test_image.py::TestImage::test_overrun | grep decode.c +- """ +- for file in [ ++ @pytest.mark.parametrize("path", [ + "fli_overrun.bin", + "sgi_overrun.bin", + "sgi_overrun_expandrow.bin", + "sgi_overrun_expandrow2.bin", + "pcx_overrun.bin", + "pcx_overrun2.bin", ++ "ossfuzz-4836216264589312.pcx", + "01r_00.pcx", +- ]: +- with Image.open(os.path.join("Tests/images", file)) as im: +- try: +- im.load() +- assert False +- except OSError as e: +- assert str(e) == "buffer overrun when reading image file" ++ ]) ++ def test_overrun(self, path): ++ """For overrun completeness, test as: ++ valgrind pytest -qq Tests/test_image.py::TestImage::test_overrun | grep decode.c ++ """ ++ with Image.open(os.path.join("Tests/images", path)) as im: ++ try: ++ im.load() ++ assert False ++ except OSError as e: ++ assert (str(e) == "buffer overrun when reading image file" or ++ "image file is truncated" in str(e)) + ++ def test_fli_overrun2(self): + with Image.open("Tests/images/fli_overrun2.bin") as im: + try: + im.seek(1) +--- a/src/PIL/PcxImagePlugin.py ++++ b/src/PIL/PcxImagePlugin.py +@@ -66,13 +66,13 @@ + version = i8(s[1]) + bits = i8(s[3]) + planes = i8(s[65]) +- stride = i16(s, 66) ++ ignored_stride = i16(s, 66) + logger.debug( + "PCX version %s, bits %s, planes %s, stride %s", + version, + bits, + planes, +- stride, ++ ignored_stride, + ) + + self.info["dpi"] = i16(s, 12), i16(s, 14) +@@ -110,6 +110,11 @@ + self.mode = mode + self._size = bbox[2] - bbox[0], bbox[3] - bbox[1] + ++ # don't trust the passed in stride. Calculate for ourselves. ++ # CVE-2020-35655 ++ stride = (self._size[0] * bits + 7) // 8 ++ stride += stride % 2 ++ + bbox = (0, 0) + self.size + logger.debug("size: %sx%s", *self.size) + diff --git a/pkgs/development/python-modules/pillow/default.nix b/pkgs/development/python-modules/pillow/default.nix index ab971e4201b5..0ef73143b651 100644 --- a/pkgs/development/python-modules/pillow/default.nix +++ b/pkgs/development/python-modules/pillow/default.nix @@ -1,4 +1,4 @@ -{ stdenv, buildPythonPackage, fetchPypi, isPyPy +{ stdenv, buildPythonPackage, fetchPypi, fetchpatch, fetchurl, isPyPy , olefile , freetype, libjpeg, zlib, libtiff, libwebp, tcl, lcms2, tk, libX11 , openjpeg, libimagequant @@ -17,11 +17,80 @@ buildPythonPackage rec { sha256 = "97f9e7953a77d5a70f49b9a48da7776dc51e9b738151b22dacf101641594a626"; }; + patches = [ + ./7.2.0-CVE-2020-35653.patch + (fetchpatch { + name = "CVE-2020-35654.prerequisite-1.patch"; + url = "https://github.com/python-pillow/Pillow/commit/21533e4deba80290bbc46f1a9e660196f75be45f.patch"; + sha256 = "19i7svxqlcz02ffcx1n1r6brf4m2iqm3k0zq3wd8k1pj2zw9gkhi"; + }) + (fetchpatch { + name = "CVE-2020-35654.prerequisite-2.patch"; + url = "https://github.com/python-pillow/Pillow/commit/26bf1c352489c9e847ff770cd752e97fda5b82cb.patch"; + sha256 = "0h4ch8in2ljz3qgah7k8nwzby1kg02p0fbkg8zzvmmkms051v0im"; + }) + (fetchpatch { + name = "CVE-2020-35654.part-1.patch"; + url = "https://github.com/python-pillow/Pillow/commit/eb8c1206d6b170d4e798a00db7432e023853da5c.patch"; + sha256 = "0cw1hp9irzhgh52s9g5mb6j6cry5gz2n5al4sy1sl5k998h76qaq"; + }) + (fetchpatch { + name = "CVE-2020-35654.part-2.patch"; + url = "https://github.com/python-pillow/Pillow/commit/45a62e91b1f72e79989a7919af97b062dc8dfaf4.patch"; + sha256 = "1kk4jrbz1h74pa5racxc1skp0rgwb00b8ybfyb7v7wmc34f1lm8f"; + }) + (fetchpatch { + name = "CVE-2020-35655.part-1.patch"; + url = "https://github.com/python-pillow/Pillow/commit/7e95c63fa7f503f185d3d9eb16b9cee1e54d1e46.patch"; + sha256 = "15zjkiwcmnv70vy1cfwrvzkfjmgclw4fzvina4rjd8xqap9na5fr"; + }) + (fetchpatch { + name = "CVE-2020-35655.part-2.patch"; + url = "https://github.com/python-pillow/Pillow/commit/9a2c9f722f78773e608d44710873437baf3f17d1.patch"; + sha256 = "15dhzd3i8xwx2iaff2qp6z3h0b2yrzcmqi6x7ngld96805gf7v2q"; + }) + ]; + + # patching mechanism doesn't work with binary files, but the commits contain + # example images needed for the accompanying tests, so invent our own mechanism + # to put these in place + injectMissingBinFiles = stdenv.lib.concatMapStrings ({commit, sha256, path}: let + src = fetchurl { + inherit sha256; + url = "https://github.com/python-pillow/Pillow/raw/${commit}/${path}"; + }; + dest = path; + in '' + cp ${src} ${dest} + '' + ) [ + { # needed by CVE-2020-35653.patch + commit = "2f409261eb1228e166868f8f0b5da5cda52e55bf"; + sha256 = "1gf7zn0qv0i8qvr22sm9azchwizb9aa4xxipy6x5lh7kgb974g0f"; + path = "Tests/images/ossfuzz-4836216264589312.pcx"; + } + { # needed by CVE-2020-35654.part-1.patch + commit = "eb8c1206d6b170d4e798a00db7432e023853da5c"; + sha256 = "0v7jg2xdqzyq3rq6jq0ipsy335sw557symv5jrcz9rdfgkbafh92"; + path = "Tests/images/crash-2020-10-test.tif"; + } + { # needed by CVE-2020-35655.part-1.patch + commit = "7e95c63fa7f503f185d3d9eb16b9cee1e54d1e46"; + sha256 = "0jkzwnv11c1h3hy0ri6kqvcjj800armzrvwc9724ivnm2id8qi8z"; + path = "Tests/images/crash-6b7f2244da6d0ae297ee0754a424213444e92778.sgi"; + } + { # needed by CVE-2020-35655.part-1.patch + commit = "7e95c63fa7f503f185d3d9eb16b9cee1e54d1e46"; + sha256 = "0is0r49pbaxy8mgp5fdlx9hm7zdp64ij38hzgnjj9pzxxdrcw3qk"; + path = "Tests/images/ossfuzz-5730089102868480.sgi"; + } + ]; + # Disable imagefont tests, because they don't work well with infinality: # https://github.com/python-pillow/Pillow/issues/1259 postPatch = '' rm Tests/test_imagefont.py - ''; + '' + injectMissingBinFiles; # Disable darwin tests which require executables: `iconutil` and `screencapture` disabledTests = stdenv.lib.optionals stdenv.isDarwin [ "test_save" "test_grab" "test_grabclipboard" ]; From f1c480e707dbe881ce606a6392061a93ef249ac4 Mon Sep 17 00:00:00 2001 From: Robert Hensing Date: Tue, 9 Feb 2021 18:32:54 +0100 Subject: [PATCH 04/11] Revert "openblas: enable multiple outputs" This reverts commit 7902256cfd1aeec4867e9f3f2fe30b05f6c151b1. --- pkgs/development/libraries/science/math/openblas/default.nix | 3 --- 1 file changed, 3 deletions(-) diff --git a/pkgs/development/libraries/science/math/openblas/default.nix b/pkgs/development/libraries/science/math/openblas/default.nix index 5573b0eaae75..28299971b81a 100644 --- a/pkgs/development/libraries/science/math/openblas/default.nix +++ b/pkgs/development/libraries/science/math/openblas/default.nix @@ -107,9 +107,6 @@ in stdenv.mkDerivation rec { pname = "openblas"; version = "0.3.13"; - - outputs = [ "out" "dev" ]; - src = fetchFromGitHub { owner = "xianyi"; repo = "OpenBLAS"; From dfe3fb89538a7e82f88c23f8c42ad05ba715b8ae Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Thu, 11 Feb 2021 04:20:00 +0000 Subject: [PATCH 05/11] postgresql_9_5: 9.5.24 -> 9.5.25 Release notes: https://www.postgresql.org/docs/9.5/release-9-5-25.html (cherry picked from commit f226fa4fda9518c1c24ab34283fa71a0d3d882c4) --- pkgs/servers/sql/postgresql/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/sql/postgresql/default.nix b/pkgs/servers/sql/postgresql/default.nix index cb11afee3e69..2a58b1215aef 100644 --- a/pkgs/servers/sql/postgresql/default.nix +++ b/pkgs/servers/sql/postgresql/default.nix @@ -183,9 +183,9 @@ let in self: { postgresql_9_5 = self.callPackage generic { - version = "9.5.24"; + version = "9.5.25"; psqlSchema = "9.5"; - sha256 = "0an2k4m1da96897hyxlff8p4p63wg4dffwsfg57aib7mp4yzsp06"; + sha256 = "00yny0sskxrqk4ji2phgv3iqxd1aiy6rh660k73s4s1pn9gcaa3n"; this = self.postgresql_9_5; inherit self; }; From 096c9a81a05d6ab15e422b953403e417b151c3d9 Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Thu, 11 Feb 2021 04:20:00 +0000 Subject: [PATCH 06/11] postgresql_9_6: 9.6.20 -> 9.6.21 Release notes: https://www.postgresql.org/docs/9.6/release-9-6-21.html (cherry picked from commit 65ef71689fcf0e4fde21ef32b40273bda7db2039) --- pkgs/servers/sql/postgresql/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/sql/postgresql/default.nix b/pkgs/servers/sql/postgresql/default.nix index 2a58b1215aef..b4d93a71a004 100644 --- a/pkgs/servers/sql/postgresql/default.nix +++ b/pkgs/servers/sql/postgresql/default.nix @@ -191,9 +191,9 @@ in self: { }; postgresql_9_6 = self.callPackage generic { - version = "9.6.20"; + version = "9.6.21"; psqlSchema = "9.6"; - sha256 = "1dkv916y7vrfbygrfbfvs6y3fxaysnh32i5j88nvcnnl16jcn21x"; + sha256 = "0d0ngpadf1i7c0i2psaxcbmiwx8334ibcsn283n9fp4853pyl3wk"; this = self.postgresql_9_6; inherit self; }; From b56b5ff5525a555f9e0acde9ed9450408384b8b2 Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Thu, 11 Feb 2021 04:20:00 +0000 Subject: [PATCH 07/11] postgresql_10: 10.15 -> 10.16 Release notes: https://www.postgresql.org/docs/10/release-10-16.html (cherry picked from commit 1fb790d9fa3f0c7fe45b8318c54db35de80034c5) --- pkgs/servers/sql/postgresql/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/sql/postgresql/default.nix b/pkgs/servers/sql/postgresql/default.nix index b4d93a71a004..d52c980a995c 100644 --- a/pkgs/servers/sql/postgresql/default.nix +++ b/pkgs/servers/sql/postgresql/default.nix @@ -199,9 +199,9 @@ in self: { }; postgresql_10 = self.callPackage generic { - version = "10.15"; + version = "10.16"; psqlSchema = "10.0"; # should be 10, but changing it is invasive - sha256 = "0zhzj9skag1pgqas2rnd217vj41ilaalqna17j47gyngpvhbqmjr"; + sha256 = "1cvv8qw0gkkczqhiwx6ns7w88dwkvdz4cvb2d4ff14363f5p2p53"; this = self.postgresql_10; inherit self; }; From 66c5ad3cd8c31a9eb5c7945fc1c56feab7297d80 Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Thu, 11 Feb 2021 04:20:00 +0000 Subject: [PATCH 08/11] postgresql_11: 11.10 -> 11.11 Release notes: https://www.postgresql.org/docs/11/release-11-11.html (cherry picked from commit 9d5aa602e0ce4481c07a3d99e0a630827c76fca2) --- pkgs/servers/sql/postgresql/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/sql/postgresql/default.nix b/pkgs/servers/sql/postgresql/default.nix index d52c980a995c..54d698120deb 100644 --- a/pkgs/servers/sql/postgresql/default.nix +++ b/pkgs/servers/sql/postgresql/default.nix @@ -207,9 +207,9 @@ in self: { }; postgresql_11 = self.callPackage generic { - version = "11.10"; + version = "11.11"; psqlSchema = "11.1"; # should be 11, but changing it is invasive - sha256 = "16bqp6ds37kbwqx7mk5gg3y6gv59wq6xz33iqwxldzk20vwd5rhk"; + sha256 = "0v0qk298nxmpzpgsxcsxma328hdkyzd7fwjs0zsn6zavl5zpnq20"; this = self.postgresql_11; inherit self; }; From d439b237cc1c8100bd3eea31f5faa7745577a045 Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Thu, 11 Feb 2021 04:20:00 +0000 Subject: [PATCH 09/11] postgresql_12: 12.5 -> 12.6 Release notes: https://www.postgresql.org/docs/12/release-12-6.html (cherry picked from commit 444a5b5a05949a1b917e475607434e4956582b7a) --- pkgs/servers/sql/postgresql/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/sql/postgresql/default.nix b/pkgs/servers/sql/postgresql/default.nix index 54d698120deb..0c575544ceda 100644 --- a/pkgs/servers/sql/postgresql/default.nix +++ b/pkgs/servers/sql/postgresql/default.nix @@ -215,9 +215,9 @@ in self: { }; postgresql_12 = self.callPackage generic { - version = "12.5"; + version = "12.6"; psqlSchema = "12"; - sha256 = "15gzg778da23sbfmy7sqg443f9ny480301lm7i3vay4m3ls2a3dx"; + sha256 = "028asz92mi3706zabfs8w9z03mzyx62d1l71qy9zdwfabj6xjzfz"; this = self.postgresql_12; inherit self; }; From 0473d24b28fddbaeae912ed917100197b3db236b Mon Sep 17 00:00:00 2001 From: sternenseemann <0rpkxez4ksa01gb3typccl0i@systemli.org> Date: Sat, 13 Feb 2021 13:47:23 +0100 Subject: [PATCH 10/11] pythonPackages.lxml: 4.5.2 -> 4.6.2 (#107408) (cherry picked from commit b14d8bae274a876f1ce1fc4ce47644c936622031) --- pkgs/development/python-modules/lxml/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/lxml/default.nix b/pkgs/development/python-modules/lxml/default.nix index aa009e0a3e73..b58376031039 100644 --- a/pkgs/development/python-modules/lxml/default.nix +++ b/pkgs/development/python-modules/lxml/default.nix @@ -7,13 +7,13 @@ buildPythonPackage rec { pname = "lxml"; - version = "4.5.2"; + version = "4.6.2"; src = fetchFromGitHub { owner = pname; repo = pname; rev = "${pname}-${version}"; - sha256 = "1d0cpwdjxfzwjzmnz066ibzicyj2vhx15qxmm775l8hxqi65xps4"; + sha256 = "1zidx62sxh2r4fmjfjzd4f6i4yxgzkpd20nafbyr0i0wnw9da3fd"; }; # setuptoolsBuildPhase needs dependencies to be passed through nativeBuildInputs From 86001ec4ceccb687c5895384320316b12d88a9fe Mon Sep 17 00:00:00 2001 From: Robert Hensing Date: Tue, 16 Feb 2021 10:17:55 +0100 Subject: [PATCH 11/11] qtwebengine: Increase build timeout to 24h The default 10h timeout caused the cancellation of builds on aarch64-linux builders. Perhaps counterintuitively, this wastes resources because it requires a restart, but never completes. https://hydra.nixos.org/build/136917190 (cherry picked from commit 46a4d53063c7794933f581688e4229a0420af5c7) --- pkgs/development/libraries/qt-5/modules/qtwebengine.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/qt-5/modules/qtwebengine.nix b/pkgs/development/libraries/qt-5/modules/qtwebengine.nix index b98b711c0f5d..582044a27e56 100644 --- a/pkgs/development/libraries/qt-5/modules/qtwebengine.nix +++ b/pkgs/development/libraries/qt-5/modules/qtwebengine.nix @@ -218,6 +218,8 @@ qtModule { description = "A web engine based on the Chromium web browser"; maintainers = with maintainers; [ matthewbauer ]; platforms = platforms.unix; + # This build takes a long time; particularly on slow architectures + timeout = 24 * 3600; }; }