From 487689b35d0388e71464e7e384d60d321ca1ac16 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 16 Jun 2022 23:36:28 +0200 Subject: [PATCH 1/9] nixos/prometheus-postfix-exporter: fixes for systemd integration * Allow the service to read from the journal w/systemd.enable * Ensure that the service is started after postfix.service (cherry picked from commit 1f9375b92e8236b4881f080e3b43d8db8db2dc68) --- .../services/monitoring/prometheus/exporters/postfix.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nixos/modules/services/monitoring/prometheus/exporters/postfix.nix b/nixos/modules/services/monitoring/prometheus/exporters/postfix.nix index 4d3c1fa267e5..53509b7a385b 100644 --- a/nixos/modules/services/monitoring/prometheus/exporters/postfix.nix +++ b/nixos/modules/services/monitoring/prometheus/exporters/postfix.nix @@ -74,11 +74,13 @@ in }; }; serviceOpts = { + after = mkIf cfg.systemd.enable [ cfg.systemd.unit ]; serviceConfig = { DynamicUser = false; # By default, each prometheus exporter only gets AF_INET & AF_INET6, # but AF_UNIX is needed to read from the `showq`-socket. RestrictAddressFamilies = [ "AF_UNIX" ]; + SupplementaryGroups = mkIf cfg.systemd.enable [ "systemd-journal" ]; ExecStart = '' ${pkgs.prometheus-postfix-exporter}/bin/postfix_exporter \ --web.listen-address ${cfg.listenAddress}:${toString cfg.port} \ From e67b541a3a62551e901f15731f4b69da73a7b8aa Mon Sep 17 00:00:00 2001 From: Andrew Kvalheim Date: Thu, 30 Jun 2022 07:27:38 -0700 Subject: [PATCH 2/9] signal-desktop: revert "Allow overriding the spell checker language (#44456)" This reverts commit 9ef1406a9918f3414d081563ba34084c5e187a58. Signal Desktop removed this functionality when changing spell checkers: - signalapp/Signal-Desktop@6a517e4ef94cd76bd31d94ea3aad7af8e1da0360 - signalapp/Signal-Desktop@4a8f5db0a49f67426237731245bebdcc75c2a5c0 (cherry picked from commit cb7ddc7f34db03b4fc479df592c85b7176c85db2) --- .../signal-desktop/default.nix | 18 +----------------- 1 file changed, 1 insertion(+), 17 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix b/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix index 4bf0aa078883..4674af74a8cc 100644 --- a/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix +++ b/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix @@ -5,24 +5,9 @@ , cups, expat, libuuid, at-spi2-core, libappindicator-gtk3, mesa # Runtime dependencies: , systemd, libnotify, libdbusmenu, libpulseaudio, xdg-utils -# Unfortunately this also overwrites the UI language (not just the spell -# checking language!): -, hunspellDicts, spellcheckerLanguage ? null # E.g. "de_DE" -# For a full list of available languages: -# $ cat pkgs/development/libraries/hunspell/dictionaries.nix | grep "dictFileName =" | awk '{ print $3 }' }: -let - customLanguageWrapperArgs = (with lib; - let - # E.g. "de_DE" -> "de-de" (spellcheckerLanguage -> hunspellDict) - spellLangComponents = splitString "_" spellcheckerLanguage; - hunspellDict = elemAt spellLangComponents 0 + "-" + toLower (elemAt spellLangComponents 1); - in lib.optionalString (spellcheckerLanguage != null) '' - --set HUNSPELL_DICTIONARIES "${hunspellDicts.${hunspellDict}}/share/hunspell" \ - --set LC_MESSAGES "${spellcheckerLanguage}"''); - -in stdenv.mkDerivation rec { +stdenv.mkDerivation rec { pname = "signal-desktop"; version = "5.47.0"; # Please backport all updates to the stable channel. # All releases have a limited lifetime and "expire" 90 days after the release. @@ -122,7 +107,6 @@ in stdenv.mkDerivation rec { preFixup = '' gappsWrapperArgs+=( --prefix LD_LIBRARY_PATH : "${lib.makeLibraryPath [ stdenv.cc.cc ] }" - ${customLanguageWrapperArgs} --add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--enable-features=UseOzonePlatform --ozone-platform=wayland}}" --suffix PATH : ${lib.makeBinPath [ xdg-utils ]} ) From 66eb568b21703b3948865afd22bb17da65891e32 Mon Sep 17 00:00:00 2001 From: kilianar Date: Fri, 1 Jul 2022 11:03:38 +0200 Subject: [PATCH 3/9] signal-desktop: 5.47.0 -> 5.48.0 https://github.com/signalapp/Signal-Desktop/releases/tag/v5.48.0 (cherry picked from commit 1fc2aa773b8a3054929a8f7527440b9eeaa6e2c8) --- .../networking/instant-messengers/signal-desktop/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix b/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix index cf30841ac9e7..bb2157c7a0f6 100644 --- a/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix +++ b/pkgs/applications/networking/instant-messengers/signal-desktop/default.nix @@ -24,7 +24,7 @@ let in stdenv.mkDerivation rec { pname = "signal-desktop"; - version = "5.47.0"; # Please backport all updates to the stable channel. + version = "5.48.0"; # Please backport all updates to the stable channel. # All releases have a limited lifetime and "expire" 90 days after the release. # When releases "expire" the application becomes unusable until an update is # applied. The expiration date for the current release can be extracted with: @@ -34,7 +34,7 @@ in stdenv.mkDerivation rec { src = fetchurl { url = "https://updates.signal.org/desktop/apt/pool/main/s/signal-desktop/signal-desktop_${version}_amd64.deb"; - sha256 = "sha256-aQpylo4/pbHP2an1w6DEhRmU3uvntN/tnYhvaWtNGGg="; + sha256 = "sha256-SJ3wO3lDEDyKuNuT8sadLfd3AcxB+DR2J5yKlkBUv24="; }; nativeBuildInputs = [ From 0a242ce1f8a6b03d0ac9cad5708d85ccdf8b7c0a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=EF=BD=88=EF=BD=89=EF=BD=8C=EF=BD=8A=EF=BD=95=EF=BD=93?= =?UTF-8?q?=EF=BD=94=EF=BD=89?= Date: Sun, 3 Jul 2022 02:47:00 -0700 Subject: [PATCH 4/9] sigi: 3.4.0 -> 3.4.2 (cherry picked from commit b4cbc03186a339351bf78eae7a36905ce3ee8252) --- pkgs/applications/misc/sigi/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/misc/sigi/default.nix b/pkgs/applications/misc/sigi/default.nix index 827c1b71ff2d..28aaf9dd72c8 100644 --- a/pkgs/applications/misc/sigi/default.nix +++ b/pkgs/applications/misc/sigi/default.nix @@ -2,14 +2,14 @@ rustPlatform.buildRustPackage rec { pname = "sigi"; - version = "3.4.0"; + version = "3.4.2"; src = fetchCrate { inherit pname version; - sha256 = "sha256-wqdgrFeB3YuMo/r4ndqRZCz+M1WuUvX2pHHkyNMdnvo="; + sha256 = "sha256-YlTawz09i7k5QxaybKSo4IhECs6UdDSNV+ylIJgKPt4="; }; - cargoSha256 = "sha256-103zhlskzhEj6oUam7YDRWiSPTaV2PPJhzP7QeMBtDQ="; + cargoSha256 = "sha256-L4eIGxQTM+sZWXWZDGtSwsCT54CWLbyPQ9b+Jf6s94U="; nativeBuildInputs = [ installShellFiles ]; # In case anything goes wrong. From d95d417ffd1af24292988da9b26119ca9570f340 Mon Sep 17 00:00:00 2001 From: WilliButz Date: Mon, 4 Jul 2022 11:49:31 +0200 Subject: [PATCH 5/9] atlassian-jira: 8.22.2 -> 8.22.4 includes fix for CVE-2022-26135 https://confluence.atlassian.com/jira/jira-server-security-advisory-29nd-june-2022-1142430667.html https://confluence.atlassian.com/jirasoftware/issues-resolved-in-8-22-4-1141486890.html (cherry picked from commit 50dff7c678cf9f17ae27f6465a21ff366eb18f08) --- pkgs/servers/atlassian/jira.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/atlassian/jira.nix b/pkgs/servers/atlassian/jira.nix index e9d38a41c029..6434a756bcd8 100644 --- a/pkgs/servers/atlassian/jira.nix +++ b/pkgs/servers/atlassian/jira.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation rec { pname = "atlassian-jira"; - version = "8.22.2"; + version = "8.22.4"; src = fetchurl { url = "https://product-downloads.atlassian.com/software/jira/downloads/atlassian-jira-software-${version}.tar.gz"; - sha256 = "sha256-j9JUIK4GOdY9rMLPZcWbjWUh/s2ZkoVEQBNAIqHhdYI="; + sha256 = "sha256-Zog0m8tsx8mDLU1rsW5zhhHgyRmi4JGWuy9DV8yp9nY="; }; buildPhase = '' From 3f04afbe92500f98fb9db366043a23ab638da132 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 4 Jul 2022 03:30:41 +0000 Subject: [PATCH 6/9] gnome.gnome-remote-desktop: 42.2 -> 42.3 (cherry picked from commit 19c31e6b87086271790f8619acc3ac24d5d81352) --- pkgs/desktops/gnome/core/gnome-remote-desktop/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/desktops/gnome/core/gnome-remote-desktop/default.nix b/pkgs/desktops/gnome/core/gnome-remote-desktop/default.nix index 111aa6bfefa5..a72012ca57fd 100644 --- a/pkgs/desktops/gnome/core/gnome-remote-desktop/default.nix +++ b/pkgs/desktops/gnome/core/gnome-remote-desktop/default.nix @@ -28,11 +28,11 @@ stdenv.mkDerivation rec { pname = "gnome-remote-desktop"; - version = "42.2"; + version = "42.3"; src = fetchurl { url = "mirror://gnome/sources/${pname}/${lib.versions.major version}/${pname}-${version}.tar.xz"; - hash = "sha256-wcy82MpwN+9ttz9r8rXdOKM2t9gKKpyY32/4g4eP+dU="; + hash = "sha256-opatWPizvawOLg2H2xKpOV5ydwqWDnh/vMG+PwBotkI="; }; nativeBuildInputs = [ From b5546b96c1bf34e82d6b157f1f1ca40ea3651c7b Mon Sep 17 00:00:00 2001 From: 06kellyjac Date: Mon, 4 Jul 2022 13:44:46 +0100 Subject: [PATCH 7/9] kdigger: 1.2.0 -> 1.2.1 (cherry picked from commit 383ee3c194359482710e25cf07ab071cf5ad10cd) --- pkgs/tools/security/kdigger/default.nix | 18 +++++------------- 1 file changed, 5 insertions(+), 13 deletions(-) diff --git a/pkgs/tools/security/kdigger/default.nix b/pkgs/tools/security/kdigger/default.nix index 5067d4003274..b552499b10ec 100644 --- a/pkgs/tools/security/kdigger/default.nix +++ b/pkgs/tools/security/kdigger/default.nix @@ -3,18 +3,17 @@ , buildGoModule , fetchFromGitHub , installShellFiles -, fetchpatch }: buildGoModule rec { pname = "kdigger"; - version = "1.2.0"; + version = "1.2.1"; src = fetchFromGitHub { owner = "quarkslab"; repo = pname; rev = "v${version}"; - sha256 = "sha256-j4HIwfRIUpV25DmbQ+9go8aJMEYaFDPxrdr/zGWBeVU="; + sha256 = "sha256-xNOfxJJa0KbrxP1YRDEhnJEmKmpWzXchJWZ/2StR2O0="; # populate values that require us to use git. By doing this in postFetch we # can delete .git afterwards and maintain better reproducibility of the src. leaveDotGit = true; @@ -26,17 +25,11 @@ buildGoModule rec { }; vendorSha256 = "sha256-3vn3MsE/4lBw89wgYgzm0RuJJ5RQTkgS6O74PpfFcUk="; - patches = [ - (fetchpatch { - name = "simplify-ldflags.patch"; - url = "https://github.com/quarkslab/kdigger/pull/2.patch"; - sha256 = "sha256-d/NdoAdnheVgdqr2EF2rNn3gJvbjRZtOKFw2DqWR8TY="; - }) - ]; - nativeBuildInputs = [ installShellFiles ]; + # static to be easily copied into containers since it's an in-pod pen-testing tool CGO_ENABLED = 0; + ldflags = [ "-s" "-w" @@ -76,7 +69,6 @@ buildGoModule rec { ''; license = licenses.asl20; maintainers = with maintainers; [ jk ]; - # aarch64-linux support progress - https://github.com/quarkslab/kdigger/issues/3 - platforms = [ "x86_64-linux" ]; + platforms = [ "x86_64-linux" "aarch64-linux" "x86_64-darwin" ]; }; } From b9cac54ba756ceac0d071d137150760f6a4eb5ef Mon Sep 17 00:00:00 2001 From: Nicolas Benes Date: Sun, 3 Jul 2022 21:13:34 +0200 Subject: [PATCH 8/9] tor-browser-bundle-bin: 11.0.14 -> 11.0.15 (cherry picked from commit b6805190a2b5d65e93aba36d87404c4dd5cb4cbc) --- .../networking/browsers/tor-browser-bundle-bin/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/browsers/tor-browser-bundle-bin/default.nix b/pkgs/applications/networking/browsers/tor-browser-bundle-bin/default.nix index 30c9d8435786..53b3e03422d7 100644 --- a/pkgs/applications/networking/browsers/tor-browser-bundle-bin/default.nix +++ b/pkgs/applications/networking/browsers/tor-browser-bundle-bin/default.nix @@ -87,7 +87,7 @@ let fteLibPath = makeLibraryPath [ stdenv.cc.cc gmp ]; # Upstream source - version = "11.0.14"; + version = "11.0.15"; lang = "en-US"; @@ -98,7 +98,7 @@ let "https://tor.eff.org/dist/torbrowser/${version}/tor-browser-linux64-${version}_${lang}.tar.xz" "https://tor.calyxinstitute.org/dist/torbrowser/${version}/tor-browser-linux64-${version}_${lang}.tar.xz" ]; - sha256 = "19lsxdxbdismjrv2kmvm10cmr1x5klc2khlmrybycdw2vx7r41mn"; + sha256 = "1gv44bi3gfg5z46fvs9wy46fgvfshad5kbxl43x3x4r70ps1nc3l"; }; i686-linux = fetchurl { @@ -107,7 +107,7 @@ let "https://tor.eff.org/dist/torbrowser/${version}/tor-browser-linux32-${version}_${lang}.tar.xz" "https://tor.calyxinstitute.org/dist/torbrowser/${version}/tor-browser-linux32-${version}_${lang}.tar.xz" ]; - sha256 = "0hkj4vn5jk3z32mdgzzwmhj5xa4mv5p1nnwqhlsbc3g5b5q8bc7q"; + sha256 = "109291wwcy63k8hs23kx8vffpj4zvywdpy8srwaq367l0ffvfqn2"; }; }; in From 38561390bdd399388df51712e04edb0d4f9783f3 Mon Sep 17 00:00:00 2001 From: Tobias Stenzel Date: Fri, 29 Apr 2022 23:57:57 +0200 Subject: [PATCH 9/9] nixos/gitlab: fix gitlab-registry-cert path condition `ConditionPathExists` belongs in the [Unit] section, not [Service]. The unit now properly checks if the cert file already exists before activating so certs will not be overwritten anymore. (cherry picked from commit 0c4f8e78b522711ca72724248393d7f5d57f6b57) --- nixos/modules/services/misc/gitlab.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/services/misc/gitlab.nix b/nixos/modules/services/misc/gitlab.nix index 0b8bd08a22bc..ee59cea38dfd 100644 --- a/nixos/modules/services/misc/gitlab.nix +++ b/nixos/modules/services/misc/gitlab.nix @@ -1063,7 +1063,7 @@ in { chown ${cfg.user}:${cfg.group} ${cfg.registry.certFile} ''; - serviceConfig = { + unitConfig = { ConditionPathExists = "!${cfg.registry.certFile}"; }; };