mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-30 03:39:59 +00:00
Merge release-24.05 into staging-next-24.05
This commit is contained in:
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -242,7 +242,8 @@ buildStdenv.mkDerivation {
|
||||
hash = "sha256-5PzVNJvPNX8irCqj1H38SFDydNJZuBHx167e1TQehaI=";
|
||||
})
|
||||
]
|
||||
++ lib.optional (lib.versionAtLeast version "111") ./env_var_for_system_dir-ff111.patch
|
||||
++ lib.optionals (lib.versionAtLeast version "111" && lib.versionOlder version "133") [ ./env_var_for_system_dir-ff111.patch ]
|
||||
++ lib.optionals (lib.versionAtLeast version "133") [ ./env_var_for_system_dir-ff133.patch ]
|
||||
++ lib.optional (lib.versionAtLeast version "96" && lib.versionOlder version "121") ./no-buildconfig-ffx96.patch
|
||||
++ lib.optional (lib.versionAtLeast version "121") ./no-buildconfig-ffx121.patch
|
||||
++ lib.optionals (lib.versionAtLeast version "120" && lib.versionOlder version "120.0.1") [
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
diff --git a/toolkit/xre/nsXREDirProvider.cpp b/toolkit/xre/nsXREDirProvider.cpp
|
||||
index 6db876975187..5882c5d7f1d6 100644
|
||||
--- a/toolkit/xre/nsXREDirProvider.cpp
|
||||
+++ b/toolkit/xre/nsXREDirProvider.cpp
|
||||
@@ -11,6 +11,7 @@
|
||||
|
||||
#include "jsapi.h"
|
||||
#include "xpcpublic.h"
|
||||
+#include "prenv.h"
|
||||
#include "prprf.h"
|
||||
|
||||
#include "nsIAppStartup.h"
|
||||
@@ -297,7 +297,8 @@ static nsresult GetSystemParentDirectory(nsIFile** aFile) {
|
||||
"/usr/lib/mozilla"_ns
|
||||
# endif
|
||||
;
|
||||
- rv = NS_NewNativeLocalFile(dirname, getter_AddRefs(localDir));
|
||||
+ const char* pathVar = PR_GetEnv("MOZ_SYSTEM_DIR");
|
||||
+ rv = NS_NewNativeLocalFile((pathVar && *pathVar) ? nsDependentCString(pathVar) : reinterpret_cast<const nsCString&>(dirname), getter_AddRefs(localDir));
|
||||
# endif
|
||||
|
||||
if (NS_SUCCEEDED(rv)) {
|
||||
@@ -3,10 +3,10 @@
|
||||
{
|
||||
firefox = buildMozillaMach rec {
|
||||
pname = "firefox";
|
||||
version = "131.0.3";
|
||||
version = "132.0";
|
||||
src = fetchurl {
|
||||
url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz";
|
||||
sha512 = "3aa96db839f7a45e34c43b5e7e3333e1100ca11545ad26a8e42987fbc72df5ae7ebebe7dfc8c4e856d2bb4676c0516914a07c001f6047799f314146a3329c0ce";
|
||||
sha512 = "254ffba16d6e6c61cffaa8131f81a9a78880e5723b7ee78ac36251a27d82e6ff088238ae289d07469ba3a51b5b5969a08ecd1fc02dcb4d93325a08fac1cfc916";
|
||||
};
|
||||
|
||||
extraPatches = [
|
||||
@@ -33,11 +33,11 @@
|
||||
|
||||
firefox-beta = buildMozillaMach rec {
|
||||
pname = "firefox-beta";
|
||||
version = "132.0b9";
|
||||
version = "133.0b1";
|
||||
applicationName = "Mozilla Firefox Beta";
|
||||
src = fetchurl {
|
||||
url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz";
|
||||
sha512 = "0c491e2a601d6989c10cdd757c83453e07454113dac8e4de154df04386fc0797ee5146dcdc8ca904692a6cb87246b54a4f5e93057afd20f23701abd3f61a6985";
|
||||
sha512 = "c4a85a72b2891c5b6c6e200cd7ef13abe0f5ad090f8ef1d8243a489791f3542b2cd390c141118c4745c4ca677d1e9bf1e564e4a45e066d27ed53e6bd92844727";
|
||||
};
|
||||
|
||||
meta = {
|
||||
@@ -62,13 +62,13 @@
|
||||
|
||||
firefox-devedition = buildMozillaMach rec {
|
||||
pname = "firefox-devedition";
|
||||
version = "132.0b9";
|
||||
version = "133.0b1";
|
||||
applicationName = "Mozilla Firefox Developer Edition";
|
||||
requireSigning = false;
|
||||
branding = "browser/branding/aurora";
|
||||
src = fetchurl {
|
||||
url = "mirror://mozilla/devedition/releases/${version}/source/firefox-${version}.source.tar.xz";
|
||||
sha512 = "3393bb677c6e735860ef49c837ffab10720c6eb47d6cfb6c7960267e3676c69c8293b5f7e49de3f91b6eb88fa4780300db2b2653dde1ae38d546f473bca7e34b";
|
||||
sha512 = "dced4aba71b07b68ee31c283945e7d62a7032f08f5cf71aa261fc7ba32f58277acbe9fdbdd28777d7f4b824e411815b069cab0ce791438088c9ad19c3d2de62e";
|
||||
};
|
||||
|
||||
meta = {
|
||||
@@ -94,10 +94,10 @@
|
||||
|
||||
firefox-esr-128 = buildMozillaMach rec {
|
||||
pname = "firefox";
|
||||
version = "128.3.1esr";
|
||||
version = "128.4.0esr";
|
||||
src = fetchurl {
|
||||
url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz";
|
||||
sha512 = "c5c1a2e951e0dbb1259a0f77a26b8678bfa4a4c7e909f8fcd5c6d0f807625926824ed235e114d9bab5e289232efaaf4c6691764db64860161ebc9bece9200f0c";
|
||||
sha512 = "e720b1f993926d73f5a5727648f753176ac2fd093fb0b71393946bbc5919ce5fc7b88b82960bd1aa427b5663c7f659828dc6702485fc0c1e7a6961571c67faa3";
|
||||
};
|
||||
|
||||
meta = {
|
||||
|
||||
@@ -10,15 +10,15 @@ let
|
||||
if stdenv.hostPlatform.isLinux then
|
||||
{
|
||||
stable = "0.0.72";
|
||||
ptb = "0.0.112";
|
||||
canary = "0.0.508";
|
||||
development = "0.0.32";
|
||||
ptb = "0.0.113";
|
||||
canary = "0.0.509";
|
||||
development = "0.0.33";
|
||||
}
|
||||
else
|
||||
{
|
||||
stable = "0.0.323";
|
||||
ptb = "0.0.142";
|
||||
canary = "0.0.617";
|
||||
ptb = "0.0.143";
|
||||
canary = "0.0.618";
|
||||
development = "0.0.55";
|
||||
};
|
||||
version = versions.${branch};
|
||||
@@ -30,15 +30,15 @@ let
|
||||
};
|
||||
ptb = fetchurl {
|
||||
url = "https://ptb.dl2.discordapp.net/apps/linux/${version}/discord-ptb-${version}.tar.gz";
|
||||
hash = "sha256-wJIVKrP+F6IKeE7rT8vAmWRTtvWj9h3vKJDsPu8x2kQ=";
|
||||
hash = "sha256-1Rhn6pH6KvuhGNTymBK01tA78it7JXekG48XvRZQOiA=";
|
||||
};
|
||||
canary = fetchurl {
|
||||
url = "https://canary.dl2.discordapp.net/apps/linux/${version}/discord-canary-${version}.tar.gz";
|
||||
hash = "sha256-zvjIVXZtYl9GdDCvKyuU+9+rNhRX4fGLpw9jPKEpFCs=";
|
||||
hash = "sha256-jLAeix6IQ6rqOM8NKNryEeswB5VSzc1lIEI7X7Nrc68=";
|
||||
};
|
||||
development = fetchurl {
|
||||
url = "https://development.dl2.discordapp.net/apps/linux/${version}/discord-development-${version}.tar.gz";
|
||||
hash = "sha256-Ec2kdoVA5NImT4afXi4GZ9GQF8NjT+h7qM7K3w3qrjU=";
|
||||
hash = "sha256-A87sVmaYRjRi0Q9IrXuQBr+yC+FtGgZA2L/9V4WuYbU=";
|
||||
};
|
||||
};
|
||||
x86_64-darwin = {
|
||||
@@ -48,11 +48,11 @@ let
|
||||
};
|
||||
ptb = fetchurl {
|
||||
url = "https://ptb.dl2.discordapp.net/apps/osx/${version}/DiscordPTB.dmg";
|
||||
hash = "sha256-69ioQKRoQ1RTO39BdVppOuwQb/6ylnSy1luMAX5TCeQ=";
|
||||
hash = "sha256-ZbHz0OR7p873U7YpwsHxa3Uuf3uPsmVOQF9exARQzdI=";
|
||||
};
|
||||
canary = fetchurl {
|
||||
url = "https://canary.dl2.discordapp.net/apps/osx/${version}/DiscordCanary.dmg";
|
||||
hash = "sha256-L/nnwHNPni93axBvXS4MH/NuoQbl7Ugva2sozVg6GEk=";
|
||||
hash = "sha256-UsJRw7gforZ1OAA6GNtXuTe/y95mIr7R6MRa+qe44tk=";
|
||||
};
|
||||
development = fetchurl {
|
||||
url = "https://development.dl2.discordapp.net/apps/osx/${version}/DiscordDevelopment.dmg";
|
||||
|
||||
@@ -1,665 +1,665 @@
|
||||
{
|
||||
version = "128.3.2esr";
|
||||
version = "128.4.0esr";
|
||||
sources = [
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/af/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/af/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "af";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "68e754e3280b0e47e2160d2538dbe959edde3b987a62f05c42bee02e554fbeeb";
|
||||
sha256 = "f4b5c0c67baf17bcd36c395f4e2a103680899f4b5b5134c0772725a5cc2edcfb";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ar/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ar/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ar";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "06eb5688aeab9fd9c544c45079a5a711bef6bf0710d0abfc508e33d072827ee0";
|
||||
sha256 = "b7097cb173e15e8a1ebd8d07d9695de046c950d8d363af06ab9a131597300208";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ast/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ast/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ast";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "434d20e1d20acb0aefbce5d15fb3d015eee1dc474a5b5afae90b7575308c27b6";
|
||||
sha256 = "98567596e05ff39ecfaefc77b03589dd77874e292943f665f4c31463eff0113a";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/be/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/be/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "be";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "a4def49f05a1a479c3ac0f1267d4ab65de84d7acbcc79e1c52e55e814bad8342";
|
||||
sha256 = "9672515b79fa7db20b77b032c21b5a43816aa405b6d712cdea1b779a701b9e49";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/bg/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/bg/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "bg";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "d6d4770f6707dc8a246eafaa0c3a360fb49117eb2adbb12e99a02b4de2cf1805";
|
||||
sha256 = "929517a24e94364187bfe6f4f4df25c61cdcab4a06302981a7de17c094b50eab";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/br/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/br/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "br";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "e2352aacca362ce56571b1f50009304355e5c2575e0aea3e84f81d386f7e5553";
|
||||
sha256 = "23779556660e301737025a15c13554a149fa4d1414b882bad7f3d943a2189d66";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ca/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ca/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ca";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "67c31bb9599c181bbaf250c2479188d7fc2e208322aa51737aed83ed9f91299a";
|
||||
sha256 = "2e375548e9b79bf4d0227bcaae413f898c42c12e6fe45c3a8cdd3dfd66ef63c9";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/cak/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/cak/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "cak";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "b7b44e214374a526264522345e5907b76d080603b0fc6b2c4bae9621b78279a5";
|
||||
sha256 = "7247868660c51b6a3fbe916e2203b12116ae4daf54099088d059c5f40c7ae28b";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/cs/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/cs/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "cs";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "72149f69323530b8e369fb2689a8baad097f23fe3a6039bfe56b24c0a3290744";
|
||||
sha256 = "65918f24eab7e390e0b4ce74a2b8651702f05d3517f5ef94ecd99b5459250c8e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/cy/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/cy/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "cy";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "207ee0a8bd84e9e8b1c759a1c9987207f701d0da2dd6c036d759475896a0f2c0";
|
||||
sha256 = "b5b042bdcb95d1229d2d832a7e137999119321a8312c0bc672ce35d330d0b8e3";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/da/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/da/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "da";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "b69247826491468475cae337ed62c0314ce8ca4de33ed3d8630114fddcaec41a";
|
||||
sha256 = "1da0e908f24e3efe0e4dd43a10bb4ce620059bf6ceee3fa5f9d2a5d8d32ff31e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/de/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/de/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "de";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "a0ef4564aa205006fd448ddd8d03f398a1fd525c156bbcbcba297a6a2c932cb7";
|
||||
sha256 = "4a8751d1268ce303fcba4dcdb1cf93252338908a302f3532d2adb6276fe6eac8";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/dsb/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/dsb/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "dsb";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "58eb03368703f0fdd760f04102fd3f1dddf525147fb7e5e4f1919e080935d6ea";
|
||||
sha256 = "bc9b9d26d827794f61b046788e9f965e9275b4ce15017c3115fec2c1eda5de3f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/el/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/el/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "el";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "1a1c48242ab368a8039edb04093c64cc41aa1885cbe67567340f324ce429dbe8";
|
||||
sha256 = "a2a44db9099395350baad249ad252d8002cc990613b82d77b84e6f49ca60f54f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/en-CA/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/en-CA/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "en-CA";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "f13a13039d3006320a71a01a6ffdcfebdfa446abd0aadc6858b4296dbbd01106";
|
||||
sha256 = "a85f302f53ab25362dd9f60f926c7909cdb3df90587b2b930defe8b71e039adb";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/en-GB/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/en-GB/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "en-GB";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "10d698906140a7b104484a3e90875b1f0fc2d1d7abe3bfcc2c82ab793a8c7992";
|
||||
sha256 = "76781c1c4e617995d79c22bf3b5aa0f0cf706ad2cb0ac59ab0ae736db2aa89f2";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/en-US/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/en-US/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "en-US";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "72c185256191a6f1f8b4e497b65dde1fedd919a2251261ccad6da06c62dd627b";
|
||||
sha256 = "e6aae02f5f9e01768b850b2df18404f19ac4f0f0e9aa176683d0152d8731876f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/es-AR/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/es-AR/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "es-AR";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "211d5fbe5d72d5365c74153817fc95eb376d7eb2f1fba9aea1522491fe718afc";
|
||||
sha256 = "7fb83af57053b258b63dec7327a814feee2550a7aef6db38ce55f1dda53eb40c";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/es-ES/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/es-ES/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "es-ES";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "6fcf5a499accf6882dae1c1f1a69da600a8b8ba28a902a6c7a3b4d8de51d17e1";
|
||||
sha256 = "fe16a9eddc488c8318ada85130bc7720b4aff243e6ee02c702c1e167d6831358";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/es-MX/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/es-MX/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "es-MX";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "aeba0e0b1637ce57d8ef11e73efbc39e5843c03d1efaf2e9519e60a03d6f50de";
|
||||
sha256 = "80d23de928a1f23f9b53c593a2c39f8ec316c0b8c2614e66b77864917445b9d1";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/et/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/et/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "et";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "04b7e75de0df9fb9ca09ea2910a618d9c6ed60d9b71c2505ec8850b183ee98a3";
|
||||
sha256 = "066cdae27bdfcf37c8f06bee52c1b2c6dd08a87ac9046d16272958508b2164d6";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/eu/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/eu/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "eu";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "5499fac8f11acc67b1590ca43dad0c136e9c0a00134ff14469265845154b791d";
|
||||
sha256 = "a86df82e8c15ff6f30ee30227bf3ae85c9d0c8df8264b63542f5a64fda9b2a00";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/fi/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/fi/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "fi";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "3254378b2ee27f7462129428176a92277315c0089915c0f3a80dfa435bd2205e";
|
||||
sha256 = "ad266dd4c903c53c48e62c62288e210c5b98ef653ef03196b9a261ce1f6e8415";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/fr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/fr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "fr";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "56861692b1c421d7f5a90657397b86e678cb6c162853362e69aaa7db4f28925f";
|
||||
sha256 = "54e6aaa6fc5b976f62930ec44a8069cda5edb0780fa342673daa0421e2eb9f6f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/fy-NL/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/fy-NL/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "fy-NL";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "63dca4a0a7c71b4d717f92213d8b7524b1eca29ad50e4540edaac148badf0586";
|
||||
sha256 = "2c0e5b5f3ada77823a3812ed342dca95171b05f151bf43beac62c7ca4d37fcca";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ga-IE/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ga-IE/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ga-IE";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "70ded506c128d9e7962dcf8621b772840834f44d59ab1a6a8c8c543175242858";
|
||||
sha256 = "29a77f6d2ebf8b1aec6942a212f0a524c5d4faa804e344cd31eae1fd2e4c2e9f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/gd/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/gd/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "gd";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "e65b6d02421f5b37d19c6b65cba400d12f64418b80410ffebafdc83b11758eeb";
|
||||
sha256 = "f0b3cc12e081308572eea9a122ebf53a33f042fdaa77962dd2b11c52ce964ebc";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/gl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/gl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "gl";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "a92eb0bfd1efba1f5b5efe794b915050d3a67c116e78b84b0abce563553efbd1";
|
||||
sha256 = "10c148f76d49a2bb17fd990fedfd6940ddcadde772f0026255263e6381690743";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/he/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/he/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "he";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "5fe6d0a4b259ddb0e85d192659e205610a11c5f1d32498dc84ff4956ce0ecc52";
|
||||
sha256 = "00d5e80ad49c9839fea580648b02636ad3a284eefee89fceaceff1cfcfca2761";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/hr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/hr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hr";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "05d9d2a86ae030b7c036292ebbdccd5095efb26c32bb9ceb618f1e049514aa94";
|
||||
sha256 = "b02ed6adeb246c263436f3d4f23b40ec830487b88f30585cdfe58e4ead140c9e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/hsb/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/hsb/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hsb";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "e9a807e8ac2ee94d2ff214e92e1b69cba5f00c3b9c6cbc0244fea2e9ac2386aa";
|
||||
sha256 = "c2c3ff348f1ee9af50c9ca068cd3970f151a679621b94f3aafef817966f50fa5";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/hu/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/hu/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hu";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "0347ccb486557e961ef46979f4a221b8fed55307379d9eb3e77afafc4d07d736";
|
||||
sha256 = "093059f5e6e7f9b8fd653719ed21bd7988ffe180890c9bc8a1e086ce8ec61aa3";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/hy-AM/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/hy-AM/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hy-AM";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "636762093f4697a778696bd56864aa8eaae04e48c7f4a4129b116247cd78b998";
|
||||
sha256 = "a632e051dc232c36aec69531eb64d98483899f9128042c90ad0b238b498b3415";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/id/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/id/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "id";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "291f1bddffcc0dc308a7532455e232d6e587bc8e0a803b4f6dd85f6f80346135";
|
||||
sha256 = "d44ca9526e7444ac56ee0edb8a29c709093a463e193cd9752b7cb00c51fbea17";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/is/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/is/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "is";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "01ace7af5465472c958e3e3ff1784c6b3978a46f3b008fe1a0a556e825d8b327";
|
||||
sha256 = "6bc92c2f7eb0d7577687fe8f987798edf694944214c6fa53b02b7d2c13858f2f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/it/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/it/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "it";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "1ba69fa4e8baaf106a3006dd651c92be6b3ba19701ca8c553fd0c3fc7e34425f";
|
||||
sha256 = "9751063446cce37f9d166d5d3685b9dc4c75e2dcb870acc536b99aaad809ecf9";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ja/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ja/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ja";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "98c79c493f9c23a698bf2a6627975cf918bead4e2e7ae9bdf8b132e8e5e205ec";
|
||||
sha256 = "7606009ff008abc3919d93ef61c7ae2a23f8ed78b878f22bda83be211ece04a9";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ka/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ka/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ka";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "e4e9a739ead52440b1bf0b9dc535d530c812b4d2a91bf6828cbc635f8273a8d1";
|
||||
sha256 = "72fe8b5150caeedbda2084ac6b09cc9793c840fd0964c8326c6ce030b62448b5";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/kab/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/kab/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "kab";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "e36858baf702c8402fa72ac4f1805852dd5d371766e47482f1bc7cb1a73c59fb";
|
||||
sha256 = "be4a52751123bc92470f03200a5875964ff6105e31d9e4ae0f1aa6d52223dab1";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/kk/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/kk/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "kk";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "53e88b687cc6db2abeb3e1f90f861df946c06c6026f4a5cc05a598b3f98ea2ab";
|
||||
sha256 = "159c2554fe613cb4abc157debe9b301c028f9b982b5ae8c4f2117a135cd4954e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ko/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ko/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ko";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "6a18161a3977fe91e5c878dbf28f9de76c919f753dc1e29211168ecd0bb76ea4";
|
||||
sha256 = "d8f8096f503c12429c94c42c119e21957a6cf3924d14f0030da9e46ae3b9326e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/lt/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/lt/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "lt";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "6cf21bbaf1fee99a86f036e49c56a6c789795375db7b7c2b2d66c9cf4db2009d";
|
||||
sha256 = "1d0ab203ef07760d3808aa92acfa734219f0fcfc2ba23f1a0d7ca8011e0a58f4";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/lv/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/lv/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "lv";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "ee6207c449bfaf50acbb8d666a87439080ddc6c151324064c6114ddbacfc03bc";
|
||||
sha256 = "89e2eb6f61846e69e67f9e10360b2a3e88f0b21a75996f1167f6c169b6870c9f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ms/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ms/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ms";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "6f73ddde1f47f484819c14e80e9f91be095b6229a69b7ea584b670acfe88af74";
|
||||
sha256 = "f4b11168bbaaaf519f16b8d637a635a405729f68d34b8844224a5782ea6b5afb";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/nb-NO/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/nb-NO/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "nb-NO";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "64f324a7d0c3cfce88383ca8cb844e29df33f9b740bc6d02c718e8e436a555bf";
|
||||
sha256 = "ca8661ecbf45808aac86b4d40acf129d04d71551f8cce206dc913ac63946c80b";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/nl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/nl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "nl";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "d7a982d8ba02c6ddad2c1891ae09f5cff5aa80b19e6d2fc26848f8df593fd1a4";
|
||||
sha256 = "2b852d095844fc93f8e326adfc18572461046db0f40abb3bfa16cbf80ddfccdb";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/nn-NO/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/nn-NO/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "nn-NO";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "0d572d3d4f79958083603e2238b3cfe1a5c7d333a1de5a55f0c320ae8415b4fe";
|
||||
sha256 = "387aa2d3bd17236082257f049bbc1bd0ceb8bebfcfa073197fc7f906f1cc13c1";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/pa-IN/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/pa-IN/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pa-IN";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "ded2cd04fec68d5639c5ebf93a9f50ebd7855cd316b8135c4be36d15dc03d6e5";
|
||||
sha256 = "baff051c11778958a6c52e4127760987d323bf0b100fb6c205f0ec3f8925ba86";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/pl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/pl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pl";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "a7b4c48be5aaa11b836069862bf471d19f7297575b579411938cd9a1b5f19886";
|
||||
sha256 = "08bd02a1e671c88f7ae9689b6cfca9b138c3923071e8278e529790deaee4272b";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/pt-BR/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/pt-BR/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pt-BR";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "32a1c309b143c5b2c9d9993c65f3f475ddc279c683d5c6434c1fa92176908e49";
|
||||
sha256 = "7b55c074e0342876e5cfe2c069724e673742069fce307576021407edf9ae87c0";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/pt-PT/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/pt-PT/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pt-PT";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "9f3b43fef1200627869eeef5d0814a7831ef6be2b9893cef94f6060ac579f4f9";
|
||||
sha256 = "8f81ab9e58d69f751aed4dfe16a23b667196a520115e2d0cc930295a8fa8189f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/rm/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/rm/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "rm";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "900a77024280148075888fc3dfadeaa7944b7fbe96cbcf359e3cc4cd421ef71d";
|
||||
sha256 = "0c07d0faea7d8795ad2389960bd5b8c47e2000fdfea14b93ff8f6c7e6c3db730";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ro/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ro/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ro";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "7d556f80f1fa9b60f93ec0a9bfdcc02cb063569515ff5e285aec2b8d6ef3b0f6";
|
||||
sha256 = "7beeb1f9c6a3159c351596caae91609a7247de3eef2df775703fd8ac71d1f858";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/ru/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/ru/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ru";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "bbbf234d7b1e8c7cdd71f582f1c4cf1b14ae2e9e695e9edfd56e7358ffcf9daa";
|
||||
sha256 = "c52a4a86626b025dd5b421f9033cd9ca8b13b7278946fc061b60706364541147";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/sk/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/sk/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sk";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "665f506a18615247a57c7b936d3b4f0fef7240967c2e64e206ca44fe8842f65f";
|
||||
sha256 = "3b5e3d688b6168b42cb8142c095749e6339618fb56f77fbf43bb4abf1ee49e7e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/sl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/sl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sl";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "6cb65f62b5759336d08cf4735cd4eb4a4dfa3664786e06988dc5db3fa74267b9";
|
||||
sha256 = "b8301c1136e9145a1b45c9eaabaee5daec9eac84a883978cac91b4eecfb1a13d";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/sq/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/sq/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sq";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "578d0542d3e0b4615653832d4474d5253ab7f11aafecc4a4bfb370ff14d09c85";
|
||||
sha256 = "21ce583b646bdb0451f6cf2b0178ab7d56b80fce5bdba38cb3b65598cd91e3e3";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/sr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/sr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sr";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "69f922567c45c44c2902255c6abc58312f625d2be421cbf986a488addc96af92";
|
||||
sha256 = "95b476e61cc72787642c9ceec7d26b652cc5d1ec8f756e62a89e4d45022f3d66";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/sv-SE/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/sv-SE/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sv-SE";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "338f53c983182a93febd49671b73e519da023e6d9653d16dcb1e96d62589d095";
|
||||
sha256 = "36f24520dfaea9a3090812b326ca29434f93fdad055793f6aeff85aad6f47599";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/th/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/th/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "th";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "89498e7b762e95e27d5a5cb7b33cfdcb04057f7c25bbec594f02b5ba11049cd3";
|
||||
sha256 = "c63e0b7c645a0dc60fdf74c98f3e429fd2ce7f0e460e3eaaad51bbb8a3c753e8";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/tr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/tr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "tr";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "e08daa81402551cada7b056d40ddcd77f19d19584552349895cb6d206fc3e3b2";
|
||||
sha256 = "8713083de4a756194e48038923d5584722ec49368a33a2b08157a51963ff658b";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/uk/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/uk/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "uk";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "d008cdb485bfa80654acbda091761f31cea620b5fda06cea86df9920f807da90";
|
||||
sha256 = "fd83a6354ccdedb72a41a74755a637ca8fc3f44424306abcab5f8af7efefecef";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/uz/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/uz/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "uz";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "6d73e85cc68bc9dbe519a46e217f2c62d4b002757cac6f3eee73142642259575";
|
||||
sha256 = "fa5bb891a80deca794b190e52c8496e43ea0b610f85451c31eb5d6851a1181a0";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/vi/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/vi/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "vi";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "6f7b1aa7b314f9f7a23bea9f7e5dcf654891f14eadf543603e057a62e56eb1c3";
|
||||
sha256 = "f6b09e305770da8cd27702c0024e5b237b3e7c0a7d237324188e569eaaafdba9";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/zh-CN/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/zh-CN/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "zh-CN";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "4b63f9cc7e02e1048273de888df5238c4e308a5b62caa97b9177ac9daddfaef1";
|
||||
sha256 = "0f4d8444c65d57294ab5a2eb110386d90164da2f40959b6ccbd2f959515c1f7e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-x86_64/zh-TW/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-x86_64/zh-TW/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "zh-TW";
|
||||
arch = "linux-x86_64";
|
||||
sha256 = "c3697d78a62dd49b6c9c264809fa3a208edee853fd6f2371a90a3180d88e3ec8";
|
||||
sha256 = "d87055f5fbd0970c3123d3b3dc5d3e5ac30a056af4ba0b5030e14a995691f543";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/af/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/af/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "af";
|
||||
arch = "linux-i686";
|
||||
sha256 = "d396f5bd5a22cf7e7edff3ea71cc05922c4b0326859f7460f363eb31df09ddcd";
|
||||
sha256 = "40b8316fb40a81f674a1ab8b070f36a0250006d815ebaef338b429ec2c477a9c";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ar/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ar/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ar";
|
||||
arch = "linux-i686";
|
||||
sha256 = "c095953766c3aa7f1308a8931017b202ef63783562404344efbab9a9367f38b6";
|
||||
sha256 = "ba6316f8d639b21b29c0400dcd5004c55250dde52eefb290c406b52764fae625";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ast/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ast/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ast";
|
||||
arch = "linux-i686";
|
||||
sha256 = "1039b107a3adcadc4d1e329416792fe668c0588a4a1e1283caed89789b2c49e8";
|
||||
sha256 = "0a3be4e77102a994a61280615cefdee894611c94c0902bb446c5bc7dd19e0780";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/be/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/be/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "be";
|
||||
arch = "linux-i686";
|
||||
sha256 = "43a3da378465f4e3b7a6adcd55dfbb9a100392d06dd96e49a3d50ae756a3ca02";
|
||||
sha256 = "12299b04da9ba5dbf0ac3d6ee6d11a0e0f7dda07c90f6b5f874b29702acd6f7d";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/bg/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/bg/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "bg";
|
||||
arch = "linux-i686";
|
||||
sha256 = "03be328293a1039ea0c4d05fc8ea091c073d95c4b72dfb4f348f5982647ac5db";
|
||||
sha256 = "f668f2dae9b4f3071af1a3a0e87d019ed3ad044f20f45153e62603a2e90edeb3";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/br/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/br/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "br";
|
||||
arch = "linux-i686";
|
||||
sha256 = "11e5309a82b6ae36906d2285aefca39db32247501cf60a582bfe69a879646a9e";
|
||||
sha256 = "aab0c30d08a1687389c53b14170839828b7ee5c85be1e77b30db72135119804a";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ca/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ca/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ca";
|
||||
arch = "linux-i686";
|
||||
sha256 = "9a17b59732a651b3247f7af810bd633f07e608ba66c1e7d00b341baac9f0ec69";
|
||||
sha256 = "bbfbb488667237a4cde6e73948df78f2a8ebf4fd78e40227c2000eb15155ef9a";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/cak/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/cak/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "cak";
|
||||
arch = "linux-i686";
|
||||
sha256 = "2796ae01d6fa7b48d22837d0c6f10ba6bf00ffbd35794bb1f38e3a136c8cccb2";
|
||||
sha256 = "64c28f5a4b123ce00884c90fbf246e34bce6453ce30e3bfea6b2574496d46052";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/cs/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/cs/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "cs";
|
||||
arch = "linux-i686";
|
||||
sha256 = "f2e65539e93222d4a7e552b7f670be776853b65aeb2f7fb144d68072b3bdd50d";
|
||||
sha256 = "e86a6704f92a5a0b8bdffca1ea066310818690e0dec2a5ddd2029504f677258c";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/cy/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/cy/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "cy";
|
||||
arch = "linux-i686";
|
||||
sha256 = "a59825b1692b9dffeb39bf30ea8b5f36cc30445dcd5ea184cc8487fc01fdff75";
|
||||
sha256 = "2dc05b825b3f1d58eea7042fd502da562999391d1e889f267916a2bef0fe008e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/da/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/da/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "da";
|
||||
arch = "linux-i686";
|
||||
sha256 = "d0c8b043c86e83ccc86a728743489a48cb0cc4e46d6976bd3595752a306c0774";
|
||||
sha256 = "5cbccb42d58dd622e1f7d165523597f1be5d527dc532400919e5b0e84e9cd95b";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/de/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/de/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "de";
|
||||
arch = "linux-i686";
|
||||
sha256 = "917ce52fc4d81ebbe5276240b41565fbce6bdfc53ffa7753db97e7e640a2f90a";
|
||||
sha256 = "25c6cefa9eae00bb8983d071a8bb7c2175d69386b96236c8c75389901919392e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/dsb/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/dsb/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "dsb";
|
||||
arch = "linux-i686";
|
||||
sha256 = "2c6ffd2c7e140d7710e5d702008f85892761e834e81ee1dd80f561e1aa56ddf6";
|
||||
sha256 = "ff2a8ad07dbf6ea8c0860c984b438c94f01fd37861b16805a0f50e8bc9401cf7";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/el/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/el/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "el";
|
||||
arch = "linux-i686";
|
||||
sha256 = "9213a7c441951f9a07766ccff191da85cab2a24fd7fbce1f19bae077387e5c08";
|
||||
sha256 = "ee6eeb93e95a960b2e6b43566896d2c3ce9eb24ed477c9600148ccc533809bed";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/en-CA/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/en-CA/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "en-CA";
|
||||
arch = "linux-i686";
|
||||
sha256 = "77895c740967e60406ca466afbcf294be052a6ee81d5c4b2cd531750d23fa661";
|
||||
sha256 = "6c6f11aa8f46bb49e07105c8a4a7391663cdfda166285b326ff35c1a40a38abd";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/en-GB/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/en-GB/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "en-GB";
|
||||
arch = "linux-i686";
|
||||
sha256 = "4c547974c874a4ce973b02a890fd12ac917d89c8ebf0a9d332262092ef8b9be9";
|
||||
sha256 = "6fc49aed294f7bdce470834596ba3ba7f65c938105d0d747daa425cdc182401f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/en-US/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/en-US/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "en-US";
|
||||
arch = "linux-i686";
|
||||
sha256 = "161b7ea35c5d4c1ecdb8cf0229fbcf3ea152c09c22543e0762eece4b7d6bb6eb";
|
||||
sha256 = "c4edd030485a935fdba3ec4faac0aa8a78de047af8e0d5e47ca95bc879a17621";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/es-AR/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/es-AR/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "es-AR";
|
||||
arch = "linux-i686";
|
||||
sha256 = "bb83137654be3e90cd5c0836342f00b85b065663f5318f562b09bcd2714084e9";
|
||||
sha256 = "f0c29400917af1bce184b994f65892115c69ed492c16e7180b83905f29bd03d7";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/es-ES/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/es-ES/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "es-ES";
|
||||
arch = "linux-i686";
|
||||
sha256 = "4744ecee5a3e72560aa25efd25c793b8786764aa7d9f8ac33cf1a33ccbe28a76";
|
||||
sha256 = "1dd664e361a4163ec516f4526e5f60c565645cd892d61ea3c72a5ca8f0454f1a";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/es-MX/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/es-MX/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "es-MX";
|
||||
arch = "linux-i686";
|
||||
sha256 = "6a63c009191b205ced9f8147cfe36a801e9a02d5d74a9a57f66960c78a9b3671";
|
||||
sha256 = "819e064ab10fa975d8a483f1f1b648f7ccd41d8e1cda59d6cdf26db34a74f457";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/et/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/et/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "et";
|
||||
arch = "linux-i686";
|
||||
sha256 = "aa2cc826ecbe7397b21a7c5b603026105a5db5ae3d8046ca806749b2133e38b5";
|
||||
sha256 = "5f07c0e0b9dca3ce883dc3382141f7c38e1b042bc5609b4ae85d7d792231f58b";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/eu/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/eu/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "eu";
|
||||
arch = "linux-i686";
|
||||
sha256 = "28762f614cc70ebbd3d4863a671257cbbccb5d60258d7d07f7d1e42ca3c1b2ee";
|
||||
sha256 = "b9ac89ba8815d30a527f27f3d01dec0548be1cedf9449acba17b7948d44b92d1";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/fi/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/fi/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "fi";
|
||||
arch = "linux-i686";
|
||||
sha256 = "f5b844a279088b43538b4e3f96cfa1c8614710398022d3cf0d4c3c4fbacea456";
|
||||
sha256 = "313dd6d2f2bbf36395b826f7e04c69fae434c7fc9a2ad886d4af536b0b2ac098";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/fr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/fr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "fr";
|
||||
arch = "linux-i686";
|
||||
sha256 = "4e75cc4efc0bef081cf6e0b74ac7dd74f450dd87a1a0bfbabdc8cdcc383be3c9";
|
||||
sha256 = "8883f2c417ecc6336155d5f05c9de82409d035894726936923bb96f4d70b37f1";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/fy-NL/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/fy-NL/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "fy-NL";
|
||||
arch = "linux-i686";
|
||||
sha256 = "11ec4e4be64feac976e21dadcca77145dc4fea225c0d00c9dceaa509ec61cabc";
|
||||
sha256 = "ae4875e8dac4729546770a24dba35b904a0f34342dc2f56c3dca5870b8f3fabc";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ga-IE/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ga-IE/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ga-IE";
|
||||
arch = "linux-i686";
|
||||
sha256 = "b4eaace12a57f7b24f56f476fbaa9e9606f25d1f82b34e67cb1a0e10d191e3d6";
|
||||
sha256 = "72bf9ee607ab87f9d6975eecaf3e2104cf98a32ace843178aa156bd167db9359";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/gd/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/gd/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "gd";
|
||||
arch = "linux-i686";
|
||||
sha256 = "1f669d83cc4caf91bfdd61b9e63e282f90f0d7cbb96c1100c0f904d003f9e076";
|
||||
sha256 = "9364706897f6505d4b6c8eaa315fd9c9ee85880ee58924c8d118fcd5ef551193";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/gl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/gl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "gl";
|
||||
arch = "linux-i686";
|
||||
sha256 = "5eb51acfb2955bc0038e299d77ed8491648b4d7293d31d8a01648b67dc1e575e";
|
||||
sha256 = "5de972bf2fc002fba0d1e5afc4e6b2f83bb6c740c7f6ef4958734fc18984f94c";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/he/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/he/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "he";
|
||||
arch = "linux-i686";
|
||||
sha256 = "87f4fb6eaf8f32e9b041a8d5e5da6072b1106492a9da75a4cac4255ccb818121";
|
||||
sha256 = "a4414c6642a7aeb4e754ae75f583dc0582e98b0e4555130590b2abf68b29cf13";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/hr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/hr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hr";
|
||||
arch = "linux-i686";
|
||||
sha256 = "d93a01b31369d687865d1bafca101b349c697bc7e7b48ff470831849b0444814";
|
||||
sha256 = "d2312db3e884a4575ab3c2d0e3fedbfc85f6ace385895451c15a27f06a746a06";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/hsb/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/hsb/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hsb";
|
||||
arch = "linux-i686";
|
||||
sha256 = "78d421c94906c39d64013679d786579ae60a574adebdb4b4729a2861e392b5ad";
|
||||
sha256 = "972a1f9391fd1b32bd9eec5341483d01b1b91ed04e8febe05a9dfea9dea42300";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/hu/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/hu/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hu";
|
||||
arch = "linux-i686";
|
||||
sha256 = "cb6a581fb55422aedb80ad1cf2b67dc07a82f0e3817612454bd0894522a77051";
|
||||
sha256 = "5ad67c2c7b215be82dcd223519b8750a68dc2a8947e6f1f2e2af1808126a2fe8";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/hy-AM/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/hy-AM/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "hy-AM";
|
||||
arch = "linux-i686";
|
||||
sha256 = "b7f29b312f7c26fd5f876d864006eea66977e14e5ff6c761d25b00dedb520272";
|
||||
sha256 = "58460cfd499f75be278fc810834188247ddf26e4909c4685d6571822d4199497";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/id/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/id/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "id";
|
||||
arch = "linux-i686";
|
||||
sha256 = "b8942767658f68d76c071a3d4c22bde09e09886a036f3b1e5fb46af18ca76434";
|
||||
sha256 = "2c9b914b683af7434d0af1a44b1fcca0cd80ba87815aec9d0013f86a012b98a9";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/is/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/is/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "is";
|
||||
arch = "linux-i686";
|
||||
sha256 = "7023c95b4036be5a1f6d8924e746b92aef9e76e8e82726a221473bd540dc3bf7";
|
||||
sha256 = "8d0e365474bcffb29adefc95346aa39653106347130ac2168d625b251a6cc3c3";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/it/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/it/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "it";
|
||||
arch = "linux-i686";
|
||||
sha256 = "cd594a8bf3e316e9598007ede696e785013f5a11bd68b14ce742d97abb7cef8d";
|
||||
sha256 = "cb49c2dde4e8190cfe59639456940f3e96474f9cb19c72e9952107ed3806e8d0";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ja/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ja/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ja";
|
||||
arch = "linux-i686";
|
||||
sha256 = "c17eca728cf0a861f25fb9cb419ed2c20f979c19c15582b6a17a99544881d723";
|
||||
sha256 = "e28ee17dfd116b8bdd0aca4e988df23b9ffd8a56ddd62166a4eceaa3c3224e7a";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ka/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ka/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ka";
|
||||
arch = "linux-i686";
|
||||
sha256 = "495c8d23f24dd7660e9d4836d4cb18ca48c7f3b0edb255cf18daa627ad78d6ee";
|
||||
sha256 = "14a457fa40ee1f684663ecfc2bfdf7c812efa6822496fa68afebb15e789b9660";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/kab/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/kab/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "kab";
|
||||
arch = "linux-i686";
|
||||
sha256 = "6fd780bbecad88ab558c76938599a54677e93689d0d451e96beddc886569e3a6";
|
||||
sha256 = "32d538f85c9f77907126c7f67376b45186f583542ab3ca0df15d9feeb6c99950";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/kk/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/kk/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "kk";
|
||||
arch = "linux-i686";
|
||||
sha256 = "92d2e2e9e80f75285aabb3ac62edc6db028b15b752a6cbcbb3795566cbeb744f";
|
||||
sha256 = "16ddc3622e4c2d456aa98328f55a6bf93e0c0462b0ca72382be6f3e0edc6811f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ko/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ko/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ko";
|
||||
arch = "linux-i686";
|
||||
sha256 = "4ea9a6c97b458928a66341d86ed0fd274b27b1e3a2259971b8bf795ab36656c7";
|
||||
sha256 = "874447583a9c7685c48cfcfdd663d8234540e088ad6336b3281837a355ba5df3";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/lt/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/lt/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "lt";
|
||||
arch = "linux-i686";
|
||||
sha256 = "5037fd5bff06a053331b2ad6312f35af1dd881b2b017fb92ac4c433bf7c10a20";
|
||||
sha256 = "dd57c0e4c96e9ddde9e49f8db763246a4f65c451be62d4f74989993d72edff11";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/lv/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/lv/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "lv";
|
||||
arch = "linux-i686";
|
||||
sha256 = "0498e5ae2815fcb979230f3166cfeed89d02bddc9c7ed73646600fca2eb44aec";
|
||||
sha256 = "e1b0fdb30d1d4129fd3e9cb1a72040f6a0cbc906e7a8f09b70bc06a742062afa";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ms/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ms/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ms";
|
||||
arch = "linux-i686";
|
||||
sha256 = "bfbb9fa1a5c1d4aa4c9c73c7e02628c1f01c314fc252370fc6a96896a666db57";
|
||||
sha256 = "4ef54e071c9ca46a39aec1a965cd7a0a2509ceff6643279b0655bcdacebc9adf";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/nb-NO/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/nb-NO/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "nb-NO";
|
||||
arch = "linux-i686";
|
||||
sha256 = "da6ce60429e87f38ff66ce975f4a63e1f2e6f8b2a7ba4f895a32760c09fa02da";
|
||||
sha256 = "92d48bf7e3bab1f3e56affeedf7942616b99c7702254f2e88ceacdd0bfe4ce27";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/nl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/nl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "nl";
|
||||
arch = "linux-i686";
|
||||
sha256 = "514646876e7654bc5a7141d919cce98eff22e07180a37d6765f87629fc48724b";
|
||||
sha256 = "08060766e951a2c45304dc16a0ab3eb25b8b5b6e0dbcf9ec3b6bf42813287e5d";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/nn-NO/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/nn-NO/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "nn-NO";
|
||||
arch = "linux-i686";
|
||||
sha256 = "dda61d6545277b5d8f53100712796e2ebbf3c8b759c4bee0f5c467bf8419d9ed";
|
||||
sha256 = "8722da03e9accc9d746ea4bbee2e54a402bb727e3e7dec89f707a3a893542aa9";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/pa-IN/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/pa-IN/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pa-IN";
|
||||
arch = "linux-i686";
|
||||
sha256 = "02b524802db090431e2c1888b1fee5148d22ae7ae7a6d4a22c18afda11bf5c84";
|
||||
sha256 = "afa7ff5f443879b6423c5d68b320aa4783fce66a400000b87d5ab8141538ea65";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/pl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/pl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pl";
|
||||
arch = "linux-i686";
|
||||
sha256 = "43991a49c7e68753599b4b7b6e5b0d23f199d57b85824ccc56b9b4bfa2c4f7e5";
|
||||
sha256 = "c464f3af685089e44b95b6d328465f84b8b9052e05d8cf6650eba704500789d1";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/pt-BR/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/pt-BR/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pt-BR";
|
||||
arch = "linux-i686";
|
||||
sha256 = "d9af07aadc66ce20772407de1a458756545775b95b70c8c56c71a6b3ca48cd94";
|
||||
sha256 = "fb0067b077d68e8d5b11b70a72ac7fccbaf8b0a235b1a0f4b32b7ed0d21a94cd";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/pt-PT/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/pt-PT/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "pt-PT";
|
||||
arch = "linux-i686";
|
||||
sha256 = "523bcc1b478dcc9e54a1f4c6743fc546ea0b18956d907149641d34598ffccc6e";
|
||||
sha256 = "446e8b19db276e988f1d25f057e4343f467d82f6a1ca33fe96e19f51c6d9a2e3";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/rm/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/rm/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "rm";
|
||||
arch = "linux-i686";
|
||||
sha256 = "5a6fef50c1acfb0cd2e91d9e03aad4afd688436dcca5280bdb49ba144e97a439";
|
||||
sha256 = "7ea76c1352591cc5c2e612c150ad51b57d0fa18f75b667ac24551ede81f0c3fb";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ro/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ro/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ro";
|
||||
arch = "linux-i686";
|
||||
sha256 = "298aeaa7ae0afaa6531a566e2e8ce072adcc62f7646cf33bfbd3acc450335881";
|
||||
sha256 = "8cbce1993c005a231e47a034affe17f1bcdfdba8d6a157320c997353ab63efeb";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/ru/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/ru/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "ru";
|
||||
arch = "linux-i686";
|
||||
sha256 = "c017f418996a8cc7fb7bd2c4062df1ba1dcf4c2b8df7d23a44fe7e0aebd00b2c";
|
||||
sha256 = "79f4ca2a069d07ab2888061e53c360b992e95fa74129924abaf74e00158f73c9";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/sk/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/sk/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sk";
|
||||
arch = "linux-i686";
|
||||
sha256 = "84079eedbd6c2a5cf4733f256a583b302209dc84a30d2305b859bd10efa87c1f";
|
||||
sha256 = "57a42e9106f6c51b0f1fe4f6c573d9efa1e5ac5f39e0573902243a1518164de7";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/sl/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/sl/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sl";
|
||||
arch = "linux-i686";
|
||||
sha256 = "99651a3c3c28cfc1d664066bf0c197951622e55b21ba4be8f157606d63c2dafb";
|
||||
sha256 = "6a3ed3e7c8371cb367fda41db743a2dadf54ddd7095239c1a9ab1dd37cbbdc17";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/sq/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/sq/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sq";
|
||||
arch = "linux-i686";
|
||||
sha256 = "47953845a4f03c67148bb183a629a349f3e90bb4c425fc148b1b2cab9f0631e2";
|
||||
sha256 = "47c1e95035dcb5aae2ec736766019a5395299748d68ef1c8171f080dab50c48f";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/sr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/sr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sr";
|
||||
arch = "linux-i686";
|
||||
sha256 = "266e2d380f3607a3da4e68b9567d936a47552bd49173d1a44ecce572cc7338ee";
|
||||
sha256 = "29eb0d3cbaec91f01af604328ee441822f1292cff73118dc62d9ff5c76c860ff";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/sv-SE/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/sv-SE/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "sv-SE";
|
||||
arch = "linux-i686";
|
||||
sha256 = "0e97466c633f662293b53e7e61b15034d1f88718232e8cfeb32797d4110dd3af";
|
||||
sha256 = "f8b063eaae59e4401424e3e5b0a063bfbc18aabe9de850bdde21f60dfb680f6e";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/th/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/th/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "th";
|
||||
arch = "linux-i686";
|
||||
sha256 = "18bb3e26ed34c2896a2b5e57d2f740e3870354785e762b7aa827a17b9b8d5708";
|
||||
sha256 = "60121b78803375589bbfc8b0a4e5a7027d066fde61766c43245761c50fce88a8";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/tr/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/tr/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "tr";
|
||||
arch = "linux-i686";
|
||||
sha256 = "6c1d1f511ee94247f02e4b26d7125ef7e4cd839a508c1be7018127378e80915f";
|
||||
sha256 = "eb20b61417b001a8d9a307d2fd83f5f5811d2fed4298fcfb5cf2b51426eea5a2";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/uk/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/uk/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "uk";
|
||||
arch = "linux-i686";
|
||||
sha256 = "5b36b7f5efe32bf58d14d74d773cb4cdf092fe3e89e1f2facf63183699967d48";
|
||||
sha256 = "77a58bc92ea8f6f8b0d7c2a6875c557a4dff5e364e45409631a5ba81c28f903c";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/uz/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/uz/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "uz";
|
||||
arch = "linux-i686";
|
||||
sha256 = "ade3f2442dcc5b6dcce7a8114209bc7bdd3730f7e1ffd9b63b71a452fd9f657a";
|
||||
sha256 = "eec9257fa45715942dcef7caf5e60bd257c07bd6156fffaf28df11d362ead079";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/vi/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/vi/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "vi";
|
||||
arch = "linux-i686";
|
||||
sha256 = "9224b6c394daeddb695b7ccc30c21e5cbf6356db2bd1f7a6746a292a9f077b6b";
|
||||
sha256 = "d115628a1e082a740caa3170eb7ef1f446c7c7df30589e51b22684dab8c6b00c";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/zh-CN/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/zh-CN/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "zh-CN";
|
||||
arch = "linux-i686";
|
||||
sha256 = "fe17248658dd5ebcbe3f5d3dd82fa3c20f6b2a82b49e037369d8d8fa9a331083";
|
||||
sha256 = "14bfcc00a480027136a71367183ca874ed6baa14cb81027f90b3dcc126b5a0f8";
|
||||
}
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.3.2esr/linux-i686/zh-TW/thunderbird-128.3.2esr.tar.bz2";
|
||||
{ url = "http://archive.mozilla.org/pub/thunderbird/releases/128.4.0esr/linux-i686/zh-TW/thunderbird-128.4.0esr.tar.bz2";
|
||||
locale = "zh-TW";
|
||||
arch = "linux-i686";
|
||||
sha256 = "057c904f9c5e37a9b43d8410f422bf5838f18c63135add2b3f3270e2c900ea09";
|
||||
sha256 = "2e413d73f33586ed87eb8a736ef12b62593158bc67a3f57bec3e04b77513717a";
|
||||
}
|
||||
];
|
||||
}
|
||||
|
||||
@@ -27,6 +27,7 @@ let
|
||||
broken = stdenv.buildPlatform.is32bit; # since Firefox 60, build on 32-bit platforms fails with "out of memory".
|
||||
# not in `badPlatforms` because cross-compilation on 64-bit machine might work.
|
||||
license = licenses.mpl20;
|
||||
knownVulnerabilities = lib.optionals (lib.versionOlder version "116") [ "Thunderbird 115 support ended in Octoboer 2024." ];
|
||||
};
|
||||
}).override {
|
||||
geolocationSupport = false;
|
||||
@@ -61,8 +62,8 @@ in rec {
|
||||
};
|
||||
|
||||
thunderbird-128 = common {
|
||||
version = "128.3.1esr";
|
||||
sha512 = "9fef04a0c498eb16688c141cb7d45e803ecc75ea6fc6117ff8ad1e6b049716f49b435f3e5a1baa703fa937e25483137e22256e58572eeacf317de264b961ba6a";
|
||||
version = "128.4.0esr";
|
||||
sha512 = "ad031b3a9b738598358cead23cf8438435016222cd9a474c31892dc1b3db43d2d5d3a10c9639df770dc76eb3c0bc9db8be8beab84828d54ee50fc1e03f0da0a5";
|
||||
|
||||
updateScript = callPackage ./update.nix {
|
||||
attrPath = "thunderbirdPackages.thunderbird-128";
|
||||
|
||||
@@ -102,7 +102,7 @@ lib.warnIf (useHardenedMalloc != null)
|
||||
++ lib.optionals mediaSupport [ ffmpeg ]
|
||||
);
|
||||
|
||||
version = "14.0";
|
||||
version = "14.0.1";
|
||||
|
||||
sources = {
|
||||
x86_64-linux = fetchurl {
|
||||
@@ -112,7 +112,7 @@ lib.warnIf (useHardenedMalloc != null)
|
||||
"https://tor.eff.org/dist/torbrowser/${version}/tor-browser-linux-x86_64-${version}.tar.xz"
|
||||
"https://tor.calyxinstitute.org/dist/torbrowser/${version}/tor-browser-linux-x86_64-${version}.tar.xz"
|
||||
];
|
||||
hash = "sha256-RNsTj8/HP10ElIjutYCqp50gN7W7Kz+DA94rkkU/VaI=";
|
||||
hash = "sha256-DQbKMaXgEXNKHPonQF7RZ1TtEqCRnvD81ahyVUkknY8=";
|
||||
};
|
||||
|
||||
i686-linux = fetchurl {
|
||||
@@ -122,7 +122,7 @@ lib.warnIf (useHardenedMalloc != null)
|
||||
"https://tor.eff.org/dist/torbrowser/${version}/tor-browser-linux-i686-${version}.tar.xz"
|
||||
"https://tor.calyxinstitute.org/dist/torbrowser/${version}/tor-browser-linux-i686-${version}.tar.xz"
|
||||
];
|
||||
hash = "sha256-rHInikR2UvsB8A0cC7gqj09CWajJtR9ZhS3WFrv2z94=";
|
||||
hash = "sha256-khY/B4c0DjqRd0s9PblEhL0jJONVU5mQCAqZ60M+CjE=";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -5,6 +5,6 @@
|
||||
# Example: nix-shell ./maintainers/scripts/update.nix --argstr package cacert
|
||||
|
||||
import ./generic.nix {
|
||||
version = "3.105";
|
||||
hash = "sha256-Nfd7u0sdGqUCznnUxEJQFs+QuRSb+b7rZrcvKryimOQ=";
|
||||
version = "3.106";
|
||||
hash = "sha256-j8B5RgEdBbtqPmIUniNF8ToGPIrPJ8gVTMplcv72fD0=";
|
||||
}
|
||||
|
||||
@@ -23,7 +23,11 @@ rec {
|
||||
"x86_64-darwin"
|
||||
"x86_64-linux"
|
||||
"x86_64-windows"
|
||||
]
|
||||
],
|
||||
|
||||
# Extra attributes to be merged into the resulting derivation's
|
||||
# meta attribute.
|
||||
meta ? {}
|
||||
}:
|
||||
|
||||
{ lib
|
||||
@@ -152,7 +156,7 @@ rec {
|
||||
license = licenses.asl20;
|
||||
maintainers = with maintainers; [ lorenzleutgeb liff ];
|
||||
mainProgram = "gradle";
|
||||
};
|
||||
} // meta;
|
||||
});
|
||||
|
||||
# NOTE: Default JDKs that are hardcoded below must be LTS versions
|
||||
@@ -178,5 +182,11 @@ rec {
|
||||
nativeVersion = "0.22-milestone-20";
|
||||
hash = "sha256-PiQCKFON6fGHcqV06ZoLqVnoPW7zUQFDgazZYxeBOJo=";
|
||||
defaultJava = jdk11;
|
||||
meta.knownVulnerabilities = [
|
||||
"CVE-2021-29429: '[...]files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle[...]'"
|
||||
"CVE-2021-29427: '[...]there is a vulnerability which can lead to information disclosure and/or dependency poisoning[...] In some cases, Gradle may ignore content filters and search all repositories for dependencies. This only occurs when repository content filtering is used from within a `pluginManagement` block in a settings file.'"
|
||||
"CVE-2021-29428: '[...]the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory.'"
|
||||
"CVE-2021-32751: '[...]start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to change environment variables for the user running the script[...]'"
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -29,7 +29,8 @@
|
||||
|
||||
assert releaseType == "alpha"
|
||||
|| releaseType == "headless"
|
||||
|| releaseType == "demo";
|
||||
|| releaseType == "demo"
|
||||
|| releaseType == "expansion";
|
||||
|
||||
let
|
||||
|
||||
@@ -272,6 +273,7 @@ let
|
||||
cp -a doc-html $out/share/factorio
|
||||
'';
|
||||
};
|
||||
expansion = alpha;
|
||||
};
|
||||
|
||||
in
|
||||
|
||||
@@ -55,6 +55,7 @@ SYSTEMS = [
|
||||
|
||||
RELEASE_TYPES = [
|
||||
ReleaseType("alpha", needs_auth=True),
|
||||
ReleaseType("expansion", needs_auth=True),
|
||||
ReleaseType("demo"),
|
||||
ReleaseType("headless"),
|
||||
]
|
||||
|
||||
58
pkgs/games/factorio/versions-1.json
Normal file
58
pkgs/games/factorio/versions-1.json
Normal file
@@ -0,0 +1,58 @@
|
||||
{
|
||||
"x86_64-linux": {
|
||||
"alpha": {
|
||||
"experimental": {
|
||||
"name": "factorio_alpha_x64-1.1.110.tar.xz",
|
||||
"needsAuth": true,
|
||||
"sha256": "0ndhb94lh47n09a7wshm2inv52fd6rjfa7fk7nk9b7zzh84i7f4x",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/alpha/linux64",
|
||||
"version": "1.1.110"
|
||||
},
|
||||
"stable": {
|
||||
"name": "factorio_alpha_x64-1.1.110.tar.xz",
|
||||
"needsAuth": true,
|
||||
"sha256": "0ndhb94lh47n09a7wshm2inv52fd6rjfa7fk7nk9b7zzh84i7f4x",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/alpha/linux64",
|
||||
"version": "1.1.110"
|
||||
}
|
||||
},
|
||||
"demo": {
|
||||
"experimental": {
|
||||
"name": "factorio_demo_x64-1.1.110.tar.xz",
|
||||
"needsAuth": false,
|
||||
"sha256": "0dasxgrybl00vrabgrlarsvg0hdg5rvn3y4hsljhqc4zpbf93nxx",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/demo/linux64",
|
||||
"version": "1.1.110"
|
||||
},
|
||||
"stable": {
|
||||
"name": "factorio_demo_x64-1.1.110.tar.xz",
|
||||
"needsAuth": false,
|
||||
"sha256": "0dasxgrybl00vrabgrlarsvg0hdg5rvn3y4hsljhqc4zpbf93nxx",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/demo/linux64",
|
||||
"version": "1.1.110"
|
||||
}
|
||||
},
|
||||
"headless": {
|
||||
"experimental": {
|
||||
"name": "factorio_headless_x64-1.1.110.tar.xz",
|
||||
"needsAuth": false,
|
||||
"sha256": "0sk4g9y051xjhiwdhj1yz808308zwsbpq3nps1ywvpp56vdycps8",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/headless/linux64",
|
||||
"version": "1.1.110"
|
||||
},
|
||||
"stable": {
|
||||
"name": "factorio_headless_x64-1.1.110.tar.xz",
|
||||
"needsAuth": false,
|
||||
"sha256": "0sk4g9y051xjhiwdhj1yz808308zwsbpq3nps1ywvpp56vdycps8",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/headless/linux64",
|
||||
"version": "1.1.110"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -2,20 +2,20 @@
|
||||
"x86_64-linux": {
|
||||
"alpha": {
|
||||
"experimental": {
|
||||
"name": "factorio_alpha_x64-1.1.110.tar.xz",
|
||||
"name": "factorio_alpha_x64-2.0.8.tar.xz",
|
||||
"needsAuth": true,
|
||||
"sha256": "0ndhb94lh47n09a7wshm2inv52fd6rjfa7fk7nk9b7zzh84i7f4x",
|
||||
"sha256": "11g1fgfm0lki9j2jsfmvlxzisbyx7482ia2qf7gnjcqhp6jkdsll",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/alpha/linux64",
|
||||
"version": "1.1.110"
|
||||
"url": "https://factorio.com/get-download/2.0.8/alpha/linux64",
|
||||
"version": "2.0.8"
|
||||
},
|
||||
"stable": {
|
||||
"name": "factorio_alpha_x64-1.1.110.tar.xz",
|
||||
"name": "factorio_alpha_x64-2.0.8.tar.xz",
|
||||
"needsAuth": true,
|
||||
"sha256": "0ndhb94lh47n09a7wshm2inv52fd6rjfa7fk7nk9b7zzh84i7f4x",
|
||||
"sha256": "11g1fgfm0lki9j2jsfmvlxzisbyx7482ia2qf7gnjcqhp6jkdsll",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/alpha/linux64",
|
||||
"version": "1.1.110"
|
||||
"url": "https://factorio.com/get-download/2.0.8/alpha/linux64",
|
||||
"version": "2.0.8"
|
||||
}
|
||||
},
|
||||
"demo": {
|
||||
@@ -36,22 +36,32 @@
|
||||
"version": "1.1.110"
|
||||
}
|
||||
},
|
||||
"expansion": {
|
||||
"stable": {
|
||||
"name": "factorio_expansion_x64-2.0.8.tar.xz",
|
||||
"needsAuth": true,
|
||||
"sha256": "0q3abb01ld1mlbp21lgzpa62j1gybs982yzan5j1axma9n1ax3j0",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/2.0.8/expansion/linux64",
|
||||
"version": "2.0.8"
|
||||
}
|
||||
},
|
||||
"headless": {
|
||||
"experimental": {
|
||||
"name": "factorio_headless_x64-1.1.110.tar.xz",
|
||||
"name": "factorio_headless_x64-2.0.8.tar.xz",
|
||||
"needsAuth": false,
|
||||
"sha256": "0sk4g9y051xjhiwdhj1yz808308zwsbpq3nps1ywvpp56vdycps8",
|
||||
"sha256": "1jp1vlc4indicgy0xnrxq87h32wcv9s4g2hqbfb4ygiaam6lqnfr",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/headless/linux64",
|
||||
"version": "1.1.110"
|
||||
"url": "https://factorio.com/get-download/2.0.8/headless/linux64",
|
||||
"version": "2.0.8"
|
||||
},
|
||||
"stable": {
|
||||
"name": "factorio_headless_x64-1.1.110.tar.xz",
|
||||
"name": "factorio_headless_x64-2.0.8.tar.xz",
|
||||
"needsAuth": false,
|
||||
"sha256": "0sk4g9y051xjhiwdhj1yz808308zwsbpq3nps1ywvpp56vdycps8",
|
||||
"sha256": "1jp1vlc4indicgy0xnrxq87h32wcv9s4g2hqbfb4ygiaam6lqnfr",
|
||||
"tarDirectory": "x64",
|
||||
"url": "https://factorio.com/get-download/1.1.110/headless/linux64",
|
||||
"version": "1.1.110"
|
||||
"url": "https://factorio.com/get-download/2.0.8/headless/linux64",
|
||||
"version": "2.0.8"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{ callPackage
|
||||
, fetchFromGitHub
|
||||
, gradle_6
|
||||
, fetchpatch
|
||||
, substitute
|
||||
}:
|
||||
|
||||
@@ -16,10 +16,26 @@ callPackage ./generic.nix rec {
|
||||
hash = "sha256-VQcWkbGe/0qyt3M5WWgTxczwC5mE3lRHbYidOwRoukI=";
|
||||
};
|
||||
|
||||
patches = [(substitute {
|
||||
src = ./disable-git-version.patch;
|
||||
substitutions = [ "--subst-var-by" "version" version ];
|
||||
})];
|
||||
patches = [
|
||||
(substitute {
|
||||
src = ./disable-git-version.patch;
|
||||
substitutions = [ "--subst-var-by" "version" version ];
|
||||
})
|
||||
# FIXME: Remove after next release
|
||||
(fetchpatch {
|
||||
name = "Update-desktop-build-script-for-Gradle-7.0+";
|
||||
url = "https://github.com/TrashboxBobylev/Summoning-Pixel-Dungeon/commit/5610142126e161cbdc78a07c5d5abfbcd6eaf8a6.patch";
|
||||
hash = "sha256-zAiOz/Cu89Y+VmAyLCf7fzq0Mr0sYFZu14sqBZ/XvZU=";
|
||||
})
|
||||
];
|
||||
|
||||
postPatch = ''
|
||||
# Upstream patched this in https://github.com/TrashboxBobylev/Summoning-Pixel-Dungeon/commit/c8a6fdd57c49fd91bf65be48679ae6a77578ef9f,
|
||||
# but the patch fails to apply cleanly. Manually replace the deprecated option instead.
|
||||
# FIXME: Remove after next release
|
||||
substituteInPlace gradle.properties \
|
||||
--replace-fail "-XX:MaxPermSize" "-XX:MaxMetaspaceSize"
|
||||
'';
|
||||
|
||||
depsHash = "sha256-0P/BcjNnbDN25DguRcCyzPuUG7bouxEx1ySodIbSwvg=";
|
||||
|
||||
@@ -30,7 +46,4 @@ callPackage ./generic.nix rec {
|
||||
downloadPage = "https://github.com/TrashboxBobylev/Summoning-Pixel-Dungeon/releases";
|
||||
description = "A fork of the Shattered Pixel Dungeon roguelike with added summoning mechanics";
|
||||
};
|
||||
|
||||
# Probably due to https://github.com/gradle/gradle/issues/17236
|
||||
gradle = gradle_6;
|
||||
}
|
||||
|
||||
@@ -2,13 +2,13 @@
|
||||
|
||||
stdenv.mkDerivation rec {
|
||||
pname = "microcode-intel";
|
||||
version = "20240910";
|
||||
version = "20241029";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "intel";
|
||||
repo = "Intel-Linux-Processor-Microcode-Data-Files";
|
||||
rev = "microcode-${version}";
|
||||
hash = "sha256-cn0qK81dwbamh5PBlPuC9KtDWyT2NwSxDD0XlCRAv6s=";
|
||||
hash = "sha256-iS7OSWjAYBRHP7X1C+DiMwX2xudA6tXX6cEv/IcICxc=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [ iucode-tool libarchive ];
|
||||
|
||||
79
pkgs/os-specific/linux/scx/default.nix
Normal file
79
pkgs/os-specific/linux/scx/default.nix
Normal file
@@ -0,0 +1,79 @@
|
||||
{
|
||||
lib,
|
||||
callPackage,
|
||||
pkg-config,
|
||||
rustPlatform,
|
||||
llvmPackages,
|
||||
elfutils,
|
||||
zlib,
|
||||
fetchFromGitHub,
|
||||
}:
|
||||
let
|
||||
versionInfo = lib.importJSON ./version.json;
|
||||
|
||||
# Useful function for packaging schedulers, should be used unless the build system is too complex
|
||||
# passes some default values like src, version (all of which can be overridden)
|
||||
mkScxScheduler =
|
||||
packageType:
|
||||
args@{ schedulerName, ... }:
|
||||
(if packageType == "rust" then rustPlatform.buildRustPackage else llvmPackages.stdenv.mkDerivation)
|
||||
(
|
||||
args
|
||||
// {
|
||||
pname = "${schedulerName}";
|
||||
version = args.version or versionInfo.scx.version;
|
||||
|
||||
src = args.src or fetchFromGitHub {
|
||||
owner = "sched-ext";
|
||||
repo = "scx";
|
||||
rev = "refs/tags/v${versionInfo.scx.version}";
|
||||
inherit (versionInfo.scx) hash;
|
||||
};
|
||||
|
||||
nativeBuildInputs = [
|
||||
pkg-config
|
||||
llvmPackages.clang
|
||||
] ++ (args.nativeBuildInputs or [ ]);
|
||||
buildInputs = [
|
||||
elfutils
|
||||
zlib
|
||||
] ++ (args.buildInputs or [ ]);
|
||||
|
||||
env.LIBCLANG_PATH = args.env.LIBCLANG_PATH or "${llvmPackages.libclang.lib}/lib";
|
||||
|
||||
# Needs to be disabled in BPF builds
|
||||
hardeningDisable = [
|
||||
"zerocallusedregs"
|
||||
] ++ (args.hardeningDisable or [ ]);
|
||||
|
||||
meta = (args.meta or { }) // {
|
||||
description = args.meta.description or "";
|
||||
longDescription =
|
||||
(args.meta.longDescription or "")
|
||||
+ ''
|
||||
\n\nSched-ext schedulers are only available on supported kernels
|
||||
(6.12 and above or any kernel with the scx patchset applied).'';
|
||||
|
||||
homepage = args.meta.homepage or "https://github.com/sched-ext/scx";
|
||||
license = args.meta.license or lib.licenses.gpl2Only;
|
||||
platforms = args.meta.platforms or lib.platforms.linux;
|
||||
maintainers = (args.meta.maintainers or [ ]) ++ (with lib.maintainers; [ johnrtitor ]);
|
||||
};
|
||||
}
|
||||
);
|
||||
|
||||
schedulers = lib.mergeAttrsList [
|
||||
{ bpfland = import ./scx_bpfland; }
|
||||
{ lavd = import ./scx_lavd; }
|
||||
{ layered = import ./scx_layered; }
|
||||
{ rlfifo = import ./scx_rlfifo; }
|
||||
{ rustland = import ./scx_rustland; }
|
||||
{ rusty = import ./scx_rusty; }
|
||||
{ csheds = import ./scx_csheds.nix; }
|
||||
{ full = import ./scx_full.nix; }
|
||||
];
|
||||
in
|
||||
(lib.mapAttrs (name: scheduler: callPackage scheduler { inherit mkScxScheduler; }) schedulers)
|
||||
// {
|
||||
inherit mkScxScheduler;
|
||||
}
|
||||
1530
pkgs/os-specific/linux/scx/scx_bpfland/Cargo.lock
generated
Normal file
1530
pkgs/os-specific/linux/scx/scx_bpfland/Cargo.lock
generated
Normal file
File diff suppressed because it is too large
Load Diff
38
pkgs/os-specific/linux/scx/scx_bpfland/default.nix
Normal file
38
pkgs/os-specific/linux/scx/scx_bpfland/default.nix
Normal file
@@ -0,0 +1,38 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
mkScxScheduler,
|
||||
}:
|
||||
|
||||
mkScxScheduler "rust" {
|
||||
schedulerName = "scx_bpfland";
|
||||
|
||||
cargoRoot = "scheds/rust/scx_bpfland";
|
||||
cargoLock.lockFile = ./Cargo.lock;
|
||||
postPatch = ''
|
||||
rm Cargo.toml Cargo.lock
|
||||
ln -fs ${./Cargo.lock} scheds/rust/scx_bpfland/Cargo.lock
|
||||
'';
|
||||
|
||||
preBuild = ''
|
||||
cd scheds/rust/scx_bpfland
|
||||
'';
|
||||
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
mkdir -p $out/bin
|
||||
cp target/${stdenv.targetPlatform.config}/release/scx_bpfland $out/bin/
|
||||
runHook postInstall
|
||||
'';
|
||||
|
||||
meta = {
|
||||
description = "Sched-ext Rust userspace scheduler";
|
||||
longDescription = ''
|
||||
Vruntime-based Sched-ext scheduler that prioritizes interactive workloads. This
|
||||
scheduler is derived from scx_rustland, but it is fully implemented in BPF. It
|
||||
has a minimal user-space Rust part to process command line options, collect metrics
|
||||
and log out scheduling statistics. The BPF part makes all the scheduling decisions.
|
||||
'';
|
||||
mainProgram = "scx_bpfland";
|
||||
};
|
||||
}
|
||||
109
pkgs/os-specific/linux/scx/scx_csheds.nix
Normal file
109
pkgs/os-specific/linux/scx/scx_csheds.nix
Normal file
@@ -0,0 +1,109 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
mkScxScheduler,
|
||||
fetchFromGitHub,
|
||||
writeShellScript,
|
||||
bash,
|
||||
meson,
|
||||
ninja,
|
||||
jq,
|
||||
bpftools,
|
||||
elfutils,
|
||||
zlib,
|
||||
libbpf,
|
||||
}:
|
||||
|
||||
let
|
||||
versionInfo = lib.importJSON ./version.json;
|
||||
|
||||
# scx needs a specific commit of bpftool
|
||||
# can be found in meson.build of scx src
|
||||
# grep 'bpftool_commit =' ./meson.build
|
||||
bpftools_src = fetchFromGitHub {
|
||||
owner = "libbpf";
|
||||
repo = "bpftool";
|
||||
inherit (versionInfo.bpftool) rev hash;
|
||||
fetchSubmodules = true;
|
||||
};
|
||||
|
||||
# scx needs a specific commit of bpftool
|
||||
# this imitates the fetch_bpftool script in src/meson-scripts
|
||||
fetchBpftool = writeShellScript "fetch_bpftool" ''
|
||||
[ "$2" == '${bpftools_src.rev}' ] || exit 1
|
||||
cd "$1"
|
||||
cp --no-preserve=mode,owner -r "${bpftools_src}/" ./bpftool
|
||||
'';
|
||||
|
||||
# Fixes a bug with the meson build script where it specifies
|
||||
# /bin/bash twice in the script
|
||||
misbehaviorBash = writeShellScript "bash" ''
|
||||
shift 1
|
||||
exec ${lib.getExe bash} "$@"
|
||||
'';
|
||||
|
||||
# Won't build with stable libbpf, so use the latest commit
|
||||
libbpf-git = libbpf.overrideAttrs (oldAttrs: {
|
||||
src = fetchFromGitHub {
|
||||
owner = "libbpf";
|
||||
repo = "libbpf";
|
||||
inherit (versionInfo.libbpf) rev hash;
|
||||
fetchSubmodules = true;
|
||||
};
|
||||
});
|
||||
|
||||
in
|
||||
mkScxScheduler "c" {
|
||||
schedulerName = "scx_csheds";
|
||||
|
||||
postPatch = ''
|
||||
rm meson-scripts/fetch_bpftool
|
||||
patchShebangs ./meson-scripts
|
||||
cp ${fetchBpftool} meson-scripts/fetch_bpftool
|
||||
substituteInPlace meson.build \
|
||||
--replace-fail '[build_bpftool' "['${misbehaviorBash}', build_bpftool"
|
||||
'';
|
||||
|
||||
nativeBuildInputs = [
|
||||
meson
|
||||
ninja
|
||||
jq
|
||||
] ++ bpftools.buildInputs ++ bpftools.nativeBuildInputs;
|
||||
|
||||
buildInputs = [
|
||||
elfutils
|
||||
zlib
|
||||
libbpf-git
|
||||
];
|
||||
|
||||
mesonFlags = [
|
||||
(lib.mapAttrsToList lib.mesonEnable {
|
||||
# systemd unit is implemented in the nixos module
|
||||
# upstream systemd files are a hassle to patch
|
||||
"systemd" = false;
|
||||
"openrc" = false;
|
||||
# libbpf is already fetched as FOD
|
||||
"libbpf_a" = false;
|
||||
# not for nix
|
||||
"libalpm" = false;
|
||||
})
|
||||
(lib.mapAttrsToList lib.mesonBool {
|
||||
# needed libs are already fetched as FOD
|
||||
"offline" = true;
|
||||
# rust based schedulers are built seperately
|
||||
"enable_rust" = false;
|
||||
})
|
||||
];
|
||||
|
||||
hardeningDisable = [
|
||||
"stackprotector"
|
||||
];
|
||||
|
||||
meta = {
|
||||
description = "Sched-ext C userspace schedulers";
|
||||
longDescription = ''
|
||||
This includes C based schedulers such as scx_central, scx_flatcg,
|
||||
scx_nest, scx_pair, scx_qmap, scx_simple, scx_userland.
|
||||
'';
|
||||
};
|
||||
}
|
||||
28
pkgs/os-specific/linux/scx/scx_full.nix
Normal file
28
pkgs/os-specific/linux/scx/scx_full.nix
Normal file
@@ -0,0 +1,28 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
scx,
|
||||
mkScxScheduler,
|
||||
}:
|
||||
scx.csheds.overrideAttrs (oldAttrs: {
|
||||
pname = "scx_full";
|
||||
postInstall =
|
||||
(oldAttrs.postInstall or "")
|
||||
+ ''
|
||||
cp ${lib.getExe scx.bpfland} $out/bin/
|
||||
cp ${lib.getExe scx.lavd} $out/bin/
|
||||
cp ${lib.getExe scx.layered} $out/bin/
|
||||
cp ${lib.getExe scx.rlfifo} $out/bin/
|
||||
cp ${lib.getExe scx.rustland} $out/bin/
|
||||
cp ${lib.getExe scx.rusty} $out/bin/
|
||||
'';
|
||||
|
||||
meta = oldAttrs.meta // {
|
||||
description = "Sched-ext C and Rust userspace schedulers";
|
||||
longDescription = ''
|
||||
This includes C based schedulers such as scx_central, scx_flatcg,
|
||||
scx_pair, scx_qmap, scx_simple, scx_userland and Rust based schedulers
|
||||
like scx_rustland, scx_bpfland, scx_lavd, scx_layered, scx_rlfifo.
|
||||
'';
|
||||
};
|
||||
})
|
||||
1646
pkgs/os-specific/linux/scx/scx_lavd/Cargo.lock
generated
Normal file
1646
pkgs/os-specific/linux/scx/scx_lavd/Cargo.lock
generated
Normal file
File diff suppressed because it is too large
Load Diff
37
pkgs/os-specific/linux/scx/scx_lavd/default.nix
Normal file
37
pkgs/os-specific/linux/scx/scx_lavd/default.nix
Normal file
@@ -0,0 +1,37 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
mkScxScheduler,
|
||||
}:
|
||||
|
||||
mkScxScheduler "rust" {
|
||||
schedulerName = "scx_lavd";
|
||||
|
||||
cargoRoot = "scheds/rust/scx_lavd";
|
||||
cargoLock.lockFile = ./Cargo.lock;
|
||||
postPatch = ''
|
||||
rm Cargo.toml Cargo.lock
|
||||
ln -fs ${./Cargo.lock} scheds/rust/scx_lavd/Cargo.lock
|
||||
'';
|
||||
|
||||
preBuild = ''
|
||||
cd scheds/rust/scx_lavd
|
||||
'';
|
||||
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
mkdir -p $out/bin
|
||||
cp target/${stdenv.targetPlatform.config}/release/scx_lavd $out/bin/
|
||||
runHook postInstall
|
||||
'';
|
||||
|
||||
meta = {
|
||||
description = "Sched-ext Rust userspace scheduler";
|
||||
longDescription = ''
|
||||
BPF scheduler that implements an LAVD (Latency-criticality Aware Virtual Deadline)
|
||||
scheduling algorithm. typical use case involves highly interactive applications,
|
||||
such as gaming, which requires high throughput and low tail latencies.
|
||||
'';
|
||||
mainProgram = "scx_lavd";
|
||||
};
|
||||
}
|
||||
1672
pkgs/os-specific/linux/scx/scx_layered/Cargo.lock
generated
Normal file
1672
pkgs/os-specific/linux/scx/scx_layered/Cargo.lock
generated
Normal file
File diff suppressed because it is too large
Load Diff
36
pkgs/os-specific/linux/scx/scx_layered/default.nix
Normal file
36
pkgs/os-specific/linux/scx/scx_layered/default.nix
Normal file
@@ -0,0 +1,36 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
mkScxScheduler,
|
||||
}:
|
||||
|
||||
mkScxScheduler "rust" {
|
||||
schedulerName = "scx_layered";
|
||||
|
||||
cargoRoot = "scheds/rust/scx_layered";
|
||||
cargoLock.lockFile = ./Cargo.lock;
|
||||
postPatch = ''
|
||||
rm Cargo.toml Cargo.lock
|
||||
ln -fs ${./Cargo.lock} scheds/rust/scx_layered/Cargo.lock
|
||||
'';
|
||||
|
||||
preBuild = ''
|
||||
cd scheds/rust/scx_layered
|
||||
'';
|
||||
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
mkdir -p $out/bin
|
||||
cp target/${stdenv.targetPlatform.config}/release/scx_layered $out/bin/
|
||||
runHook postInstall
|
||||
'';
|
||||
|
||||
meta = {
|
||||
description = "Sched-ext Rust userspace scheduler";
|
||||
longDescription = ''
|
||||
Highly configurable multi-layer BPF/userspace hybrid scheduler.
|
||||
It is designed to be highly customizable, and can be targeted for specific applications.
|
||||
'';
|
||||
mainProgram = "scx_layered";
|
||||
};
|
||||
}
|
||||
1486
pkgs/os-specific/linux/scx/scx_rlfifo/Cargo.lock
generated
Normal file
1486
pkgs/os-specific/linux/scx/scx_rlfifo/Cargo.lock
generated
Normal file
File diff suppressed because it is too large
Load Diff
37
pkgs/os-specific/linux/scx/scx_rlfifo/default.nix
Normal file
37
pkgs/os-specific/linux/scx/scx_rlfifo/default.nix
Normal file
@@ -0,0 +1,37 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
mkScxScheduler,
|
||||
}:
|
||||
|
||||
mkScxScheduler "rust" {
|
||||
schedulerName = "scx_rlfifo";
|
||||
|
||||
cargoRoot = "scheds/rust/scx_rlfifo";
|
||||
cargoLock.lockFile = ./Cargo.lock;
|
||||
postPatch = ''
|
||||
rm Cargo.toml Cargo.lock
|
||||
ln -fs ${./Cargo.lock} scheds/rust/scx_rlfifo/Cargo.lock
|
||||
'';
|
||||
|
||||
preBuild = ''
|
||||
cd scheds/rust/scx_rlfifo
|
||||
'';
|
||||
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
mkdir -p $out/bin
|
||||
cp target/${stdenv.targetPlatform.config}/release/scx_rlfifo $out/bin/
|
||||
runHook postInstall
|
||||
'';
|
||||
|
||||
meta = {
|
||||
description = "Sched-ext Rust userspace scheduler";
|
||||
longDescription = ''
|
||||
scx_rlfifo is a simple FIFO scheduler runs in user-space, based on the
|
||||
scx_rustland_core framework. Not for production use, but useful to test as a
|
||||
baseline against complex scheduling polices or for a basic FIFO scheduling approach.
|
||||
'';
|
||||
mainProgram = "scx_rlfifo";
|
||||
};
|
||||
}
|
||||
1630
pkgs/os-specific/linux/scx/scx_rustland/Cargo.lock
generated
Normal file
1630
pkgs/os-specific/linux/scx/scx_rustland/Cargo.lock
generated
Normal file
File diff suppressed because it is too large
Load Diff
38
pkgs/os-specific/linux/scx/scx_rustland/default.nix
Normal file
38
pkgs/os-specific/linux/scx/scx_rustland/default.nix
Normal file
@@ -0,0 +1,38 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
mkScxScheduler,
|
||||
}:
|
||||
|
||||
mkScxScheduler "rust" {
|
||||
schedulerName = "scx_rustland";
|
||||
|
||||
cargoRoot = "scheds/rust/scx_rustland";
|
||||
cargoLock.lockFile = ./Cargo.lock;
|
||||
postPatch = ''
|
||||
rm Cargo.toml Cargo.lock
|
||||
ln -fs ${./Cargo.lock} scheds/rust/scx_rustland/Cargo.lock
|
||||
'';
|
||||
|
||||
preBuild = ''
|
||||
cd scheds/rust/scx_rustland
|
||||
'';
|
||||
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
mkdir -p $out/bin
|
||||
cp target/${stdenv.targetPlatform.config}/release/scx_rustland $out/bin/
|
||||
runHook postInstall
|
||||
'';
|
||||
|
||||
meta = {
|
||||
description = "Sched-ext Rust userspace scheduler";
|
||||
longDescription = ''
|
||||
Made of a BPF component (scx_rustland_core) that implements the low level sched-ext functionalities
|
||||
and a user-space counterpart (scheduler), written in Rust, that implements the actual scheduling policy.
|
||||
It is designed to prioritize interactive workloads over background CPU-intensive workloads. Typical use
|
||||
case involves low-latency interactive applications, such as gaming, video conferencing and live streaming.
|
||||
'';
|
||||
mainProgram = "scx_rustland";
|
||||
};
|
||||
}
|
||||
1689
pkgs/os-specific/linux/scx/scx_rusty/Cargo.lock
generated
Normal file
1689
pkgs/os-specific/linux/scx/scx_rusty/Cargo.lock
generated
Normal file
File diff suppressed because it is too large
Load Diff
38
pkgs/os-specific/linux/scx/scx_rusty/default.nix
Normal file
38
pkgs/os-specific/linux/scx/scx_rusty/default.nix
Normal file
@@ -0,0 +1,38 @@
|
||||
{
|
||||
stdenv,
|
||||
lib,
|
||||
mkScxScheduler,
|
||||
}:
|
||||
|
||||
mkScxScheduler "rust" {
|
||||
schedulerName = "scx_rusty";
|
||||
|
||||
cargoRoot = "scheds/rust/scx_rusty";
|
||||
cargoLock.lockFile = ./Cargo.lock;
|
||||
postPatch = ''
|
||||
rm Cargo.toml Cargo.lock
|
||||
ln -fs ${./Cargo.lock} scheds/rust/scx_rusty/Cargo.lock
|
||||
'';
|
||||
|
||||
preBuild = ''
|
||||
cd scheds/rust/scx_rusty
|
||||
'';
|
||||
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
mkdir -p $out/bin
|
||||
cp target/${stdenv.targetPlatform.config}/release/scx_rusty $out/bin/
|
||||
runHook postInstall
|
||||
'';
|
||||
|
||||
meta = {
|
||||
description = "Sched-ext Rust userspace scheduler";
|
||||
longDescription = ''
|
||||
Multi-domain, BPF/userspace hybrid scheduler. BPF portion of the scheduler does
|
||||
a simple round robin in each domain, and the userspace portion calculates the load
|
||||
factor of each domain, and informs BPF of how tasks should be load balanced accordingly.
|
||||
Rusty is designed to be flexible, accommodating different architectures and workloads.
|
||||
'';
|
||||
mainProgram = "scx_rusty";
|
||||
};
|
||||
}
|
||||
50
pkgs/os-specific/linux/scx/update.sh
Executable file
50
pkgs/os-specific/linux/scx/update.sh
Executable file
@@ -0,0 +1,50 @@
|
||||
#! /usr/bin/env nix-shell
|
||||
#! nix-shell -i bash -p coreutils moreutils curl jq nix-prefetch-git cargo gnugrep gawk
|
||||
# shellcheck shell=bash
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
versionJson="$(realpath "./pkgs/os-specific/linux/scx/version.json")"
|
||||
nixFolder="$(dirname "$versionJson")"
|
||||
|
||||
localVer=$(jq -r .version <$versionJson)
|
||||
latestVer=$(curl -s https://api.github.com/repos/sched-ext/scx/releases/latest | jq -r .tag_name | sed 's/v//g')
|
||||
|
||||
if [ "$localVer" == "$latestVer" ]; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
latestHash=$(nix-prefetch-git https://github.com/sched-ext/scx.git --rev refs/tags/v$latestVer --quiet | jq -r .hash)
|
||||
|
||||
tmp=$(mktemp -d)
|
||||
trap 'rm -rf -- "${tmp}"' EXIT
|
||||
|
||||
git clone --depth 1 --branch "v$latestVer" https://github.com/sched-ext/scx.git "$tmp/scx"
|
||||
|
||||
pushd "$tmp/scx"
|
||||
|
||||
bpftoolRev=$(grep 'bpftool_commit =' ./meson.build | awk -F"'" '{print $2}')
|
||||
bpftoolHash=$(nix-prefetch-git https://github.com/libbpf/bpftool.git --rev $bpftoolRev --fetch-submodules --quiet | jq -r .hash)
|
||||
|
||||
libbpfRev=$(curl -s "https://api.github.com/repos/libbpf/libbpf/commits/master" | jq -r '.sha')
|
||||
libbpfHash=$(nix-prefetch-git https://github.com/libbpf/libbpf.git --rev $libbpfRev --fetch-submodules --quiet | jq -r .hash)
|
||||
|
||||
jq \
|
||||
--arg latestVer "$latestVer" --arg latestHash "$latestHash" \
|
||||
--arg bpftoolRev "$bpftoolRev" --arg bpftoolHash "$bpftoolHash" \
|
||||
--arg libbpfRev "$libbpfRev" --arg libbpfHash "$libbpfHash" \
|
||||
".scx.version = \$latestVer | .scx.hash = \$latestHash |\
|
||||
.bpftool.rev = \$bpftoolRev | .bpftool.hash = \$bpftoolHash |\
|
||||
.libbpf.rev = \$libbpfRev | .libbpf.hash = \$libbpfHash" \
|
||||
"$versionJson" | sponge $versionJson
|
||||
|
||||
rm -f Cargo.toml Cargo.lock
|
||||
|
||||
for scheduler in bpfland lavd layered rlfifo rustland rusty; do
|
||||
pushd "scheds/rust/scx_$scheduler"
|
||||
|
||||
cargo generate-lockfile
|
||||
cp Cargo.lock "$nixFolder/scx_$scheduler/Cargo.lock"
|
||||
|
||||
popd
|
||||
done
|
||||
14
pkgs/os-specific/linux/scx/version.json
Normal file
14
pkgs/os-specific/linux/scx/version.json
Normal file
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"scx": {
|
||||
"version": "1.0.5",
|
||||
"hash": "sha256-nb2bzEanPPWTUhMmGw/8/bwOkdgNmwoZX2lMFq5Av5Q="
|
||||
},
|
||||
"bpftool": {
|
||||
"rev": "77a72987353fcae8ce330fd87d4c7afb7677a169",
|
||||
"hash": "sha256-pItTVewlXgB97AC/WH9rW9J/eYSe2ZdBkJaAgGnDeUU="
|
||||
},
|
||||
"libbpf": {
|
||||
"rev": "09b9e83102eb8ab9e540d36b4559c55f3bcdb95d",
|
||||
"hash": "sha256-0PadA9OppNGmgSTLi8sXrh3syxPVkqrnTkBr8cyp+Ug="
|
||||
}
|
||||
}
|
||||
@@ -28,11 +28,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
bdftopcf = callPackage ({ stdenv, pkg-config, fetchurl, xorgproto, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "bdftopcf";
|
||||
version = "1.1.1";
|
||||
version = "1.1.2";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/util/bdftopcf-1.1.1.tar.xz";
|
||||
sha256 = "026rzs92h9jsc7r0kvvyvwhm22q0805gp38rs14x6ghg7kam7j8i";
|
||||
url = "mirror://xorg/individual/util/bdftopcf-1.1.2.tar.xz";
|
||||
sha256 = "0fjjn1z0cbsmhxkms93w73j2jbzf9f3xgbnjvnisl3rk0icvwq5w";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -854,11 +854,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
fonttosfnt = callPackage ({ stdenv, pkg-config, fetchurl, libfontenc, freetype, xorgproto, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "fonttosfnt";
|
||||
version = "1.2.3";
|
||||
version = "1.2.4";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/app/fonttosfnt-1.2.3.tar.xz";
|
||||
sha256 = "1bv1glfz4jqvkwx8hmv2vqilvxxl6jww3rvbzv6zbl6b83r96yma";
|
||||
url = "mirror://xorg/individual/app/fonttosfnt-1.2.4.tar.xz";
|
||||
sha256 = "0wk3fs038sh2sl1sqayzfjvygmcdp903qa1pd3aankxrgzv3b5i4";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -2418,11 +2418,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xcmsdb = callPackage ({ stdenv, pkg-config, fetchurl, libX11, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xcmsdb";
|
||||
version = "1.0.6";
|
||||
version = "1.0.7";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/app/xcmsdb-1.0.6.tar.xz";
|
||||
sha256 = "0magrza0i5qwpf0zlpqjychp3bzxgdw3p5v616xl4nbxag2fwxrw";
|
||||
url = "mirror://xorg/individual/app/xcmsdb-1.0.7.tar.xz";
|
||||
sha256 = "0f5wddi707cjqm21hynckkqr12mpjqn3dq9fm5gb11w19270di2y";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -2618,11 +2618,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xf86inputevdev = callPackage ({ stdenv, pkg-config, fetchurl, xorgproto, libevdev, udev, mtdev, xorgserver, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xf86-input-evdev";
|
||||
version = "2.10.6";
|
||||
version = "2.11.0";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/driver/xf86-input-evdev-2.10.6.tar.bz2";
|
||||
sha256 = "1h1y0fwnawlp4yc5llr1l7hwfcxxpln2fxhy6arcf6w6h4z0f9l7";
|
||||
url = "mirror://xorg/individual/driver/xf86-input-evdev-2.11.0.tar.xz";
|
||||
sha256 = "058k0xdf4hkn8lz5gx4c08mgbzvv58haz7a32axndhscjgg2403k";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -2678,11 +2678,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xf86inputlibinput = callPackage ({ stdenv, pkg-config, fetchurl, xorgproto, libinput, xorgserver, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xf86-input-libinput";
|
||||
version = "1.4.0";
|
||||
version = "1.5.0";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/driver/xf86-input-libinput-1.4.0.tar.xz";
|
||||
sha256 = "1673ydfrvfqd4inz3vx1qyxa0mhr0f4bi0r7mrcmpisxi76i8g9s";
|
||||
url = "mirror://xorg/individual/driver/xf86-input-libinput-1.5.0.tar.xz";
|
||||
sha256 = "1rl06l0gdqmc4v08mya93m74ana76b7s3fzkmq8ylm3535gw6915";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -3078,11 +3078,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xf86videomga = callPackage ({ stdenv, pkg-config, fetchurl, xorgproto, libdrm, libpciaccess, xorgserver, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xf86-video-mga";
|
||||
version = "2.0.1";
|
||||
version = "2.1.0";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/driver/xf86-video-mga-2.0.1.tar.xz";
|
||||
sha256 = "1aq3aqh2yg09gy864kkshfx5pjl5w05jdz97bx5bnrbrhdq3p8r7";
|
||||
url = "mirror://xorg/individual/driver/xf86-video-mga-2.1.0.tar.xz";
|
||||
sha256 = "0wxbcgg5i4yq22pbc50567877z8irxhqzgl3sk6vf5zs9szmvy3v";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -3238,11 +3238,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xf86videor128 = callPackage ({ stdenv, pkg-config, fetchurl, xorgproto, libdrm, libpciaccess, xorgserver, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xf86-video-r128";
|
||||
version = "6.12.1";
|
||||
version = "6.13.0";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/driver/xf86-video-r128-6.12.1.tar.xz";
|
||||
sha256 = "0hf7h54wxgs8njavp0kgadjq1787fhbd588j7pj685hz2wmkq0kx";
|
||||
url = "mirror://xorg/individual/driver/xf86-video-r128-6.13.0.tar.xz";
|
||||
sha256 = "0igpfgls5nx4sz8a7yppr42qi37prqmxsy08zqbxbv81q9dfs2zj";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -3858,11 +3858,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xkbprint = callPackage ({ stdenv, pkg-config, fetchurl, libX11, libxkbfile, xorgproto, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xkbprint";
|
||||
version = "1.0.6";
|
||||
version = "1.0.7";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/app/xkbprint-1.0.6.tar.xz";
|
||||
sha256 = "1c57kb8d8cbf720n9bcjhhaqpk08lac0sk4l0jp8j0mryw299k4r";
|
||||
url = "mirror://xorg/individual/app/xkbprint-1.0.7.tar.xz";
|
||||
sha256 = "1k2rm8lvc2klcdz2s3mymb9a2ahgwqwkgg67v3phv7ij6304jkqw";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
@@ -4016,18 +4016,18 @@ self: with self; {
|
||||
})) {};
|
||||
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xmag = callPackage ({ stdenv, pkg-config, fetchurl, libX11, libXaw, libXmu, libXt, wrapWithXFileSearchPathHook, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
xmag = callPackage ({ stdenv, pkg-config, fetchurl, libX11, libXaw, libXmu, xorgproto, libXt, wrapWithXFileSearchPathHook, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xmag";
|
||||
version = "1.0.7";
|
||||
version = "1.0.8";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/app/xmag-1.0.7.tar.xz";
|
||||
sha256 = "0qblrqrhxml2asgbck53a1v7c4y7ap7jcyqjg500h1i7bb63d680";
|
||||
url = "mirror://xorg/individual/app/xmag-1.0.8.tar.xz";
|
||||
sha256 = "0clm0vm35lkcir5w3bkypax9j57vyzkl9l89qqxbanvr7mc3qv9j";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
nativeBuildInputs = [ pkg-config wrapWithXFileSearchPathHook ];
|
||||
buildInputs = [ libX11 libXaw libXmu libXt ];
|
||||
buildInputs = [ libX11 libXaw libXmu xorgproto libXt ];
|
||||
passthru.tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage;
|
||||
meta = {
|
||||
pkgConfigModules = [ ];
|
||||
@@ -4478,11 +4478,11 @@ self: with self; {
|
||||
# THIS IS A GENERATED FILE. DO NOT EDIT!
|
||||
xwud = callPackage ({ stdenv, pkg-config, fetchurl, libX11, xorgproto, testers }: stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "xwud";
|
||||
version = "1.0.6";
|
||||
version = "1.0.7";
|
||||
builder = ./builder.sh;
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/app/xwud-1.0.6.tar.xz";
|
||||
sha256 = "1zhsih1l3x1038fi1wi9npvfnn8j7580ca73saixjg5sbv8qq134";
|
||||
url = "mirror://xorg/individual/app/xwud-1.0.7.tar.xz";
|
||||
sha256 = "07n6q1z33sjkx8lx8lbd26m8ri5gi145k3mz39kmyykdngdbwp75";
|
||||
};
|
||||
hardeningDisable = [ "bindnow" "relro" ];
|
||||
strictDeps = true;
|
||||
|
||||
@@ -9,7 +9,7 @@ mirror://xorg/individual/xcb/xcb-util-wm-0.4.2.tar.xz
|
||||
mirror://xorg/individual/app/appres-1.0.6.tar.xz
|
||||
mirror://xorg/individual/app/bitmap-1.1.1.tar.xz
|
||||
mirror://xorg/individual/app/editres-1.0.9.tar.xz
|
||||
mirror://xorg/individual/app/fonttosfnt-1.2.3.tar.xz
|
||||
mirror://xorg/individual/app/fonttosfnt-1.2.4.tar.xz
|
||||
mirror://xorg/individual/app/iceauth-1.0.10.tar.xz
|
||||
mirror://xorg/individual/app/ico-1.0.6.tar.xz
|
||||
mirror://xorg/individual/app/listres-1.0.6.tar.xz
|
||||
@@ -26,7 +26,7 @@ mirror://xorg/individual/app/xauth-1.1.3.tar.xz
|
||||
mirror://xorg/individual/app/xbacklight-1.2.3.tar.bz2
|
||||
mirror://xorg/individual/app/xcalc-1.1.2.tar.xz
|
||||
mirror://xorg/individual/app/xclock-1.1.1.tar.xz
|
||||
mirror://xorg/individual/app/xcmsdb-1.0.6.tar.xz
|
||||
mirror://xorg/individual/app/xcmsdb-1.0.7.tar.xz
|
||||
mirror://xorg/individual/app/xcompmgr-1.1.9.tar.xz
|
||||
mirror://xorg/individual/app/xconsole-1.0.8.tar.xz
|
||||
mirror://xorg/individual/app/xcursorgen-1.0.8.tar.xz
|
||||
@@ -46,14 +46,14 @@ mirror://xorg/individual/app/xinit-1.4.2.tar.xz
|
||||
mirror://xorg/individual/app/xinput-1.6.4.tar.xz
|
||||
mirror://xorg/individual/app/xkbcomp-1.4.7.tar.xz
|
||||
mirror://xorg/individual/app/xkbevd-1.1.5.tar.xz
|
||||
mirror://xorg/individual/app/xkbprint-1.0.6.tar.xz
|
||||
mirror://xorg/individual/app/xkbprint-1.0.7.tar.xz
|
||||
mirror://xorg/individual/app/xkbutils-1.0.6.tar.xz
|
||||
mirror://xorg/individual/app/xkill-1.0.6.tar.xz
|
||||
mirror://xorg/individual/app/xload-1.2.0.tar.xz
|
||||
mirror://xorg/individual/app/xlsatoms-1.1.4.tar.xz
|
||||
mirror://xorg/individual/app/xlsclients-1.1.5.tar.xz
|
||||
mirror://xorg/individual/app/xlsfonts-1.0.8.tar.xz
|
||||
mirror://xorg/individual/app/xmag-1.0.7.tar.xz
|
||||
mirror://xorg/individual/app/xmag-1.0.8.tar.xz
|
||||
mirror://xorg/individual/app/xmessage-1.0.7.tar.xz
|
||||
mirror://xorg/individual/app/xmodmap-1.0.11.tar.xz
|
||||
mirror://xorg/individual/app/xmore-1.0.4.tar.xz
|
||||
@@ -70,16 +70,16 @@ mirror://xorg/individual/app/xtrap-1.0.3.tar.bz2
|
||||
mirror://xorg/individual/app/xvinfo-1.1.5.tar.xz
|
||||
mirror://xorg/individual/app/xwd-1.0.9.tar.xz
|
||||
mirror://xorg/individual/app/xwininfo-1.1.6.tar.xz
|
||||
mirror://xorg/individual/app/xwud-1.0.6.tar.xz
|
||||
mirror://xorg/individual/app/xwud-1.0.7.tar.xz
|
||||
mirror://xorg/individual/data/xbitmaps-1.1.3.tar.xz
|
||||
mirror://xorg/individual/data/xcursor-themes-1.0.7.tar.xz
|
||||
mirror://xorg/individual/data/xkeyboard-config/xkeyboard-config-2.41.tar.xz
|
||||
mirror://xorg/individual/doc/xorg-docs-1.7.3.tar.xz
|
||||
mirror://xorg/individual/doc/xorg-sgml-doctools-1.12.1.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-evdev-2.10.6.tar.bz2
|
||||
mirror://xorg/individual/driver/xf86-input-evdev-2.11.0.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-joystick-1.6.4.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-keyboard-2.0.0.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-libinput-1.4.0.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-libinput-1.5.0.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-mouse-1.9.5.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-synaptics-1.9.2.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-input-vmmouse-13.2.0.tar.xz
|
||||
@@ -99,7 +99,7 @@ mirror://xorg/individual/driver/xf86-video-glint-1.2.9.tar.bz2
|
||||
mirror://xorg/individual/driver/xf86-video-i128-1.4.1.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-i740-1.4.0.tar.bz2
|
||||
mirror://xorg/individual/driver/xf86-video-intel-2.99.917.tar.bz2
|
||||
mirror://xorg/individual/driver/xf86-video-mga-2.0.1.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-mga-2.1.0.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-neomagic-1.3.1.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-newport-0.2.4.tar.bz2
|
||||
https://gitlab.freedesktop.org/xorg/driver/xf86-video-nouveau/-/archive/3ee7cbca8f9144a3bb5be7f71ce70558f548d268/xf86-video-nouveau-3ee7cbca8f9144a3bb5be7f71ce70558f548d268.tar.bz2
|
||||
@@ -107,7 +107,7 @@ mirror://xorg/individual/driver/xf86-video-nv-2.1.23.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-omap-0.4.5.tar.bz2
|
||||
mirror://xorg/individual/driver/xf86-video-openchrome-0.6.0.tar.bz2
|
||||
mirror://xorg/individual/driver/xf86-video-qxl-0.1.6.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-r128-6.12.1.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-r128-6.13.0.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-rendition-4.2.7.tar.bz2
|
||||
mirror://xorg/individual/driver/xf86-video-s3virge-1.11.1.tar.xz
|
||||
mirror://xorg/individual/driver/xf86-video-savage-2.4.1.tar.xz
|
||||
@@ -211,7 +211,7 @@ mirror://xorg/individual/lib/xcb-util-cursor-0.1.5.tar.xz
|
||||
mirror://xorg/individual/lib/xtrans-1.5.0.tar.xz
|
||||
mirror://xorg/individual/proto/xcb-proto-1.17.0.tar.xz
|
||||
mirror://xorg/individual/proto/xorgproto-2024.1.tar.xz
|
||||
mirror://xorg/individual/util/bdftopcf-1.1.1.tar.xz
|
||||
mirror://xorg/individual/util/bdftopcf-1.1.2.tar.xz
|
||||
mirror://xorg/individual/util/gccmakedep-1.0.4.tar.xz
|
||||
mirror://xorg/individual/util/imake-1.0.10.tar.xz
|
||||
mirror://xorg/individual/util/lndir-1.0.5.tar.xz
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{ egl-wayland
|
||||
, bash
|
||||
, libepoxy
|
||||
, fetchurl
|
||||
, fetchpatch
|
||||
, fontutil
|
||||
, lib
|
||||
, libdecor
|
||||
@@ -49,22 +49,17 @@
|
||||
|
||||
stdenv.mkDerivation rec {
|
||||
pname = "xwayland";
|
||||
version = "24.1.0";
|
||||
version = "24.1.4";
|
||||
|
||||
src = fetchurl {
|
||||
url = "mirror://xorg/individual/xserver/${pname}-${version}.tar.xz";
|
||||
hash = "sha256-vvIcTxiAek7VccTi32CrY7VGa71QLszrJIW4kqt23MI=";
|
||||
hash = "sha256-2Wp426uBn1V1AXNERESZW1Ax69zBW3ev672NvAKvNPQ=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
# Backport fix for pkg-config generation to make CMake happy
|
||||
# FIXME: remove when merged
|
||||
# Upstream PR: https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1543
|
||||
(fetchpatch {
|
||||
url = "https://gitlab.freedesktop.org/xorg/xserver/-/commit/8cb1c21a4240a5b6bf4aeeef51819639b4e0ad24.patch";
|
||||
hash = "sha256-MZPP9QgYO4RFJ/vcjkpu7SVSo5Dh09ZdZjOwTopjdYQ=";
|
||||
})
|
||||
];
|
||||
postPatch = ''
|
||||
substituteInPlace os/utils.c \
|
||||
--replace-fail '/bin/sh' '${lib.getExe' bash "sh"}'
|
||||
'';
|
||||
|
||||
depsBuildBuild = [
|
||||
pkg-config
|
||||
|
||||
@@ -1,17 +1,24 @@
|
||||
{ lib, stdenv, fetchFromGitHub, makeWrapper,
|
||||
libinput, wmctrl, python3,
|
||||
coreutils, xdotool ? null,
|
||||
extraUtilsPath ? lib.optional (xdotool != null) xdotool
|
||||
{
|
||||
lib,
|
||||
stdenv,
|
||||
fetchFromGitHub,
|
||||
makeWrapper,
|
||||
libinput,
|
||||
wmctrl,
|
||||
python3,
|
||||
coreutils,
|
||||
xdotool ? null,
|
||||
extraUtilsPath ? lib.optional (xdotool != null) xdotool,
|
||||
}:
|
||||
stdenv.mkDerivation rec {
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "libinput-gestures";
|
||||
version = "2.76";
|
||||
version = "2.77";
|
||||
|
||||
src = fetchFromGitHub {
|
||||
owner = "bulletmark";
|
||||
repo = "libinput-gestures";
|
||||
rev = version;
|
||||
sha256 = "sha256-Tb/gQ/2Ul4JzEiLEUPJBj9T6ZAqzMSPdgiofdnDj73Q=";
|
||||
rev = "refs/tags/${finalAttrs.version}";
|
||||
hash = "sha256-eMXNlSgQSuN+/5SXJQjsylC1ygHS87sIEmnVGFk3pzA=";
|
||||
};
|
||||
patches = [
|
||||
./0001-hardcode-name.patch
|
||||
@@ -21,36 +28,35 @@ stdenv.mkDerivation rec {
|
||||
nativeBuildInputs = [ makeWrapper ];
|
||||
buildInputs = [ python3 ];
|
||||
|
||||
postPatch =
|
||||
''
|
||||
substituteInPlace libinput-gestures-setup --replace /usr/ /
|
||||
postPatch = ''
|
||||
substituteInPlace libinput-gestures-setup --replace-fail /usr/ /
|
||||
|
||||
substituteInPlace libinput-gestures \
|
||||
--replace /etc "$out/etc" \
|
||||
--subst-var-by libinput "${libinput}/bin/libinput" \
|
||||
--subst-var-by wmctrl "${wmctrl}/bin/wmctrl"
|
||||
'';
|
||||
installPhase =
|
||||
''
|
||||
runHook preInstall
|
||||
${stdenv.shell} libinput-gestures-setup -d "$out" install
|
||||
runHook postInstall
|
||||
'';
|
||||
postFixup =
|
||||
''
|
||||
rm "$out/bin/libinput-gestures-setup"
|
||||
substituteInPlace "$out/share/systemd/user/libinput-gestures.service" --replace "/usr" "$out"
|
||||
substituteInPlace "$out/share/applications/libinput-gestures.desktop" --replace "/usr" "$out"
|
||||
chmod +x "$out/share/applications/libinput-gestures.desktop"
|
||||
wrapProgram "$out/bin/libinput-gestures" --prefix PATH : "${lib.makeBinPath ([coreutils] ++ extraUtilsPath)}"
|
||||
'';
|
||||
substituteInPlace libinput-gestures \
|
||||
--replace-fail /etc "$out/etc" \
|
||||
--subst-var-by libinput "${libinput}/bin/libinput" \
|
||||
--subst-var-by wmctrl "${wmctrl}/bin/wmctrl"
|
||||
'';
|
||||
installPhase = ''
|
||||
runHook preInstall
|
||||
${stdenv.shell} libinput-gestures-setup -d "$out" install
|
||||
runHook postInstall
|
||||
'';
|
||||
postFixup = ''
|
||||
rm "$out/bin/libinput-gestures-setup"
|
||||
substituteInPlace "$out/share/systemd/user/libinput-gestures.service" --replace "/usr" "$out"
|
||||
substituteInPlace "$out/share/applications/libinput-gestures.desktop" --replace "/usr" "$out"
|
||||
chmod +x "$out/share/applications/libinput-gestures.desktop"
|
||||
wrapProgram "$out/bin/libinput-gestures" --prefix PATH : "${
|
||||
lib.makeBinPath ([ coreutils ] ++ extraUtilsPath)
|
||||
}"
|
||||
'';
|
||||
|
||||
meta = with lib; {
|
||||
meta = {
|
||||
homepage = "https://github.com/bulletmark/libinput-gestures";
|
||||
description = "Gesture mapper for libinput";
|
||||
mainProgram = "libinput-gestures";
|
||||
license = licenses.gpl3Plus;
|
||||
platforms = platforms.linux;
|
||||
maintainers = with maintainers; [ teozkr ];
|
||||
license = lib.licenses.gpl3Plus;
|
||||
platforms = lib.platforms.linux;
|
||||
maintainers = with lib.maintainers; [ teozkr ];
|
||||
};
|
||||
}
|
||||
})
|
||||
|
||||
@@ -2,11 +2,11 @@
|
||||
|
||||
stdenvNoCC.mkDerivation rec {
|
||||
pname = "panoply";
|
||||
version = "5.5.3";
|
||||
version = "5.5.4";
|
||||
|
||||
src = fetchurl {
|
||||
url = "https://www.giss.nasa.gov/tools/panoply/download/PanoplyJ-${version}.tgz";
|
||||
hash = "sha256-TCuCLWMVp7t0JpHA6TbwUdURj/aBggzLa9I7llRY0TU=";
|
||||
hash = "sha256-rC2vQcaanK2nNSDtiXNhyBiV0SN3QqtwU8WNBc7D/Nw=";
|
||||
};
|
||||
|
||||
nativeBuildInputs = [ makeWrapper ];
|
||||
|
||||
@@ -16,6 +16,7 @@ let
|
||||
atLeast210 = lib.versionAtLeast version "2.10pre";
|
||||
atLeast213 = lib.versionAtLeast version "2.13pre";
|
||||
atLeast214 = lib.versionAtLeast version "2.14pre";
|
||||
atLeast218 = lib.versionAtLeast version "2.18pre";
|
||||
atLeast219 = lib.versionAtLeast version "2.19pre";
|
||||
atLeast220 = lib.versionAtLeast version "2.20pre";
|
||||
atLeast221 = lib.versionAtLeast version "2.21pre";
|
||||
@@ -42,6 +43,7 @@ in
|
||||
, callPackage
|
||||
, coreutils
|
||||
, curl
|
||||
, darwin
|
||||
, docbook_xsl_ns
|
||||
, docbook5
|
||||
, editline
|
||||
@@ -150,6 +152,8 @@ self = stdenv.mkDerivation {
|
||||
libseccomp
|
||||
] ++ lib.optionals withAWS [
|
||||
aws-sdk-cpp
|
||||
] ++ lib.optional (atLeast218 && stdenv.hostPlatform.isDarwin) [
|
||||
darwin.apple_sdk.libs.sandbox
|
||||
];
|
||||
|
||||
installCheckInputs = lib.optionals atLeast221 [
|
||||
|
||||
@@ -176,42 +176,85 @@ in lib.makeExtensible (self: ({
|
||||
version = "2.18.8";
|
||||
hash = "sha256-0rHRifdjzzxMh/im8pRx6XoY62irDTDUes+Pn0CR65I=";
|
||||
self_attribute_name = "nix_2_18";
|
||||
patches = [
|
||||
./patches/2_18/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/2_18/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/2_18/0003-local-derivation-goal-Refactor.patch
|
||||
./patches/2_18/0004-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
};
|
||||
|
||||
nix_2_19 = common {
|
||||
version = "2.19.6";
|
||||
hash = "sha256-XT5xiwOLgXf+TdyOjbJVOl992wu9mBO25WXHoyli/Tk=";
|
||||
self_attribute_name = "nix_2_19";
|
||||
patches = [
|
||||
./patches/2_19/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/2_19/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/2_19/0003-local-derivation-goal-Refactor.patch
|
||||
./patches/2_19/0004-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
};
|
||||
|
||||
nix_2_20 = common {
|
||||
version = "2.20.8";
|
||||
hash = "sha256-M2tkMtjKi8LDdNLsKi3IvD8oY/i3rtarjMpvhybS3WY=";
|
||||
self_attribute_name = "nix_2_20";
|
||||
patches = [
|
||||
./patches/2_20/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/2_20/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/2_20/0003-local-derivation-goal-Refactor.patch
|
||||
./patches/2_20/0004-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
};
|
||||
|
||||
nix_2_21 = common {
|
||||
version = "2.21.4";
|
||||
hash = "sha256-c6nVZ0pSrfhFX3eVKqayS+ioqyAGp3zG9ZPO5rkXFRQ=";
|
||||
self_attribute_name = "nix_2_21";
|
||||
patches = [
|
||||
./patches/2_21/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/2_21/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/2_21/0003-local-derivation-goal-Refactor.patch
|
||||
./patches/2_21/0004-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
};
|
||||
|
||||
nix_2_22 = common {
|
||||
version = "2.22.3";
|
||||
hash = "sha256-l04csH5rTWsK7eXPWVxJBUVRPMZXllFoSkYFTq/i8WU=";
|
||||
self_attribute_name = "nix_2_22";
|
||||
patches = [
|
||||
./patches/2_22/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/2_22/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/2_22/0003-local-derivation-goal-Refactor.patch
|
||||
./patches/2_22/0004-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
};
|
||||
|
||||
nix_2_23 = common {
|
||||
version = "2.23.3";
|
||||
hash = "sha256-lAoLGVIhRFrfgv7wcyduEkyc83QKrtsfsq4of+WrBeg=";
|
||||
self_attribute_name = "nix_2_23";
|
||||
patches = [
|
||||
./patches/2_23/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/2_23/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/2_23/0003-local-derivation-goal-Refactor.patch
|
||||
./patches/2_23/0004-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
};
|
||||
|
||||
nix_2_24 = (common {
|
||||
version = "2.24.8";
|
||||
hash = "sha256-YPJA0stZucs13Y2DQr3JIL6JfakP//LDbYXNhic/rKk=";
|
||||
self_attribute_name = "nix_2_24";
|
||||
patches = [
|
||||
./patches/2_24/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/2_24/0002-packaging-Add-darwin-lsandbox-in-meson.patch
|
||||
./patches/2_24/0003-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/2_24/0004-local-derivation-goal-Refactor.patch
|
||||
./patches/2_24/0005-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
}).override (lib.optionalAttrs (stdenv.isDarwin && stdenv.isx86_64) {
|
||||
# Fix the following error with the default x86_64-darwin SDK:
|
||||
#
|
||||
@@ -232,6 +275,14 @@ in lib.makeExtensible (self: ({
|
||||
rev = "ca3fc1693b309ab6b8b0c09408a08d0055bf0363";
|
||||
hash = "sha256-Hp7dkx7zfB9a4l5QusXUob0b1T2qdZ23LFo5dcp3xrU=";
|
||||
};
|
||||
patches = [
|
||||
./patches/git/0001-Fix-meson-build-on-darwin.patch
|
||||
./patches/git/0002-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch
|
||||
./patches/git/0003-packaging-Add-darwin-lsandbox-in-meson.patch
|
||||
./patches/git/0004-local-derivation-goal-Print-sandbox-error-detail-on-.patch
|
||||
./patches/git/0005-local-derivation-goal-Refactor.patch
|
||||
./patches/git/0006-local-derivation-goal-Move-builder-preparation-to-no.patch
|
||||
];
|
||||
self_attribute_name = "git";
|
||||
}).override (lib.optionalAttrs (stdenv.isDarwin && stdenv.isx86_64) {
|
||||
# Fix the following error with the default x86_64-darwin SDK:
|
||||
|
||||
@@ -0,0 +1,315 @@
|
||||
From 3c4bc6929eb13cf648c54931a28797bb1c289052 Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
flake.nix | 1 +
|
||||
src/libstore/build/local-derivation-goal.cc | 221 ++++++++++----------
|
||||
3 files changed, 114 insertions(+), 114 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 4e50d0913..44852ad79 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -58,13 +58,17 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
AC_STRUCT_DIRENT_D_TYPE
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/flake.nix b/flake.nix
|
||||
index 6c9bef4d8..66ac1bfd8 100644
|
||||
--- a/flake.nix
|
||||
+++ b/flake.nix
|
||||
@@ -173,6 +173,7 @@
|
||||
boost
|
||||
lowdown-nix
|
||||
]
|
||||
+ ++ lib.optionals stdenv.isDarwin [darwin.apple_sdk.libs.sandbox]
|
||||
++ lib.optionals stdenv.isLinux [(libseccomp.overrideAttrs (_: rec {
|
||||
version = "2.5.5";
|
||||
src = fetchurl {
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index 4d690beaf..fb83cfdc7 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -53,6 +53,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2034,141 +2038,132 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : dirsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
|
||||
- /* And we want the store in there regardless of how empty dirsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ if (useChroot) {
|
||||
+
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : dirsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- dirsInChroot[p] = p;
|
||||
- }
|
||||
-
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty dirsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
- ;
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ dirsInChroot[p] = p;
|
||||
+ }
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : dirsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- struct stat st;
|
||||
- if (lstat(path.c_str(), &st)) {
|
||||
- if (i.second.optional && errno == ENOENT)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(st.st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : dirsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+ std::string path = i.first;
|
||||
+ struct stat st;
|
||||
+ if (lstat(path.c_str(), &st)) {
|
||||
+ if (i.second.optional && errno == ENOENT)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(st.st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
- globalTmpDir.pop_back();
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
+
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
+
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
+ globalTmpDir.pop_back();
|
||||
+
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From 4ac099d6ab4b6851aeb8b7a1e37f5794716d5138 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index fb83cfdc7..d41d1c1e5 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2154,8 +2154,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From 6fe3a5e26def808b99856099d74aa3017ecf6d9d Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 3/4] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index d41d1c1e5..faecc403b 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2160,15 +2160,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From d219faa93badcfc8134c81ba0d2b821775eb947c Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index faecc403b..23d5d5e3f 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2033,11 +2033,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2162,14 +2157,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2199,6 +2186,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2220,9 +2215,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,312 @@
|
||||
From 172734f47a8062285cec0055133efcc45df03e54 Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
flake.nix | 1 +
|
||||
src/libstore/build/local-derivation-goal.cc | 217 ++++++++++----------
|
||||
3 files changed, 112 insertions(+), 112 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 281ba2c32..6d73804e2 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -58,13 +58,17 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
AC_STRUCT_DIRENT_D_TYPE
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/flake.nix b/flake.nix
|
||||
index 6deb09f22..98f9cc25f 100644
|
||||
--- a/flake.nix
|
||||
+++ b/flake.nix
|
||||
@@ -202,6 +202,7 @@
|
||||
libsodium
|
||||
]
|
||||
++ lib.optionals stdenv.isLinux [libseccomp]
|
||||
+ ++ lib.optionals stdenv.isDarwin [darwin.apple_sdk.libs.sandbox]
|
||||
++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid;
|
||||
|
||||
checkDeps = [
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index b6c7666e5..effd9c613 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -55,6 +55,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2031,140 +2035,131 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
|
||||
- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ if (useChroot) {
|
||||
+
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- pathsInChroot[p] = p;
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ pathsInChroot[p] = p;
|
||||
+ }
|
||||
+
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
+
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- struct stat st;
|
||||
- if (lstat(path.c_str(), &st)) {
|
||||
- if (i.second.optional && errno == ENOENT)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(st.st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
- ;
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
+
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
+
|
||||
+ std::string path = i.first;
|
||||
+ struct stat st;
|
||||
+ if (lstat(path.c_str(), &st)) {
|
||||
+ if (i.second.optional && errno == ENOENT)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(st.st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true);
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true);
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- if (globalTmpDir.back() == '/') globalTmpDir.pop_back();
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ if (globalTmpDir.back() == '/') globalTmpDir.pop_back();
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From 4a5018019e969537fdba36314fe5c19fe91828af Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index effd9c613..a67347b59 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2150,8 +2150,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From f9e5b3b52323fdcac4e21bfec4d03bd66ea6a503 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 3/4] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index a67347b59..eeb2635ee 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2156,15 +2156,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From 126a1fd3385175ac94ae4000a9798e0cafb3c168 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index eeb2635ee..e29330f0e 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2030,11 +2030,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2158,14 +2153,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2195,6 +2182,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2216,9 +2211,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,320 @@
|
||||
From aa54b01af503644a393e4e4055c4ce2a23ce9139 Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
package.nix | 2 +
|
||||
src/libstore/build/local-derivation-goal.cc | 217 ++++++++++----------
|
||||
3 files changed, 113 insertions(+), 112 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 8c29c1e62..8c524fd93 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -58,13 +58,17 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
AC_STRUCT_DIRENT_D_TYPE
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/package.nix b/package.nix
|
||||
index d1d14d10e..40283ffcf 100644
|
||||
--- a/package.nix
|
||||
+++ b/package.nix
|
||||
@@ -24,6 +24,7 @@
|
||||
, libgit2
|
||||
, libseccomp
|
||||
, libsodium
|
||||
+, darwin
|
||||
, lowdown
|
||||
, mdbook
|
||||
, mdbook-linkcheck
|
||||
@@ -233,6 +234,7 @@ in {
|
||||
gtest
|
||||
rapidcheck
|
||||
] ++ lib.optional stdenv.isLinux libseccomp
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid
|
||||
# There have been issues building these dependencies
|
||||
++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin))
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index b8228bc11..9ab676429 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -57,6 +57,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2023,140 +2027,131 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
|
||||
- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ if (useChroot) {
|
||||
+
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- pathsInChroot[p] = p;
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ pathsInChroot[p] = p;
|
||||
+ }
|
||||
+
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
+
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- struct stat st;
|
||||
- if (lstat(path.c_str(), &st)) {
|
||||
- if (i.second.optional && errno == ENOENT)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(st.st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
- ;
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
+
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
+
|
||||
+ std::string path = i.first;
|
||||
+ struct stat st;
|
||||
+ if (lstat(path.c_str(), &st)) {
|
||||
+ if (i.second.optional && errno == ENOENT)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(st.st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true);
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true);
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- if (globalTmpDir.back() == '/') globalTmpDir.pop_back();
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ if (globalTmpDir.back() == '/') globalTmpDir.pop_back();
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From b78e489f79165457b59faa2270fd89769d0fc17d Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index 9ab676429..8476e038e 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2142,8 +2142,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From db6bcf3f7714929d5a21b655c5f8ccd2ddbdf7f2 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 3/4] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index 8476e038e..12b67df69 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2148,15 +2148,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From 55be7deee1471e77e3ad408c5e23842df0d5bc28 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index 12b67df69..ada86dbb8 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2022,11 +2022,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2150,14 +2145,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2187,6 +2174,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2208,9 +2203,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,320 @@
|
||||
From ae8a38d29cc0fbd6394acd72fdaaa62b3798f698 Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
package.nix | 2 +
|
||||
src/libstore/build/local-derivation-goal.cc | 217 ++++++++++----------
|
||||
3 files changed, 113 insertions(+), 112 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 676b145a5..f6fa35c81 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -62,13 +62,17 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
AC_STRUCT_DIRENT_D_TYPE
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/package.nix b/package.nix
|
||||
index 7d9a39771..de2e1aff1 100644
|
||||
--- a/package.nix
|
||||
+++ b/package.nix
|
||||
@@ -25,6 +25,7 @@
|
||||
, libseccomp
|
||||
, libsodium
|
||||
, man
|
||||
+, darwin
|
||||
, lowdown
|
||||
, mdbook
|
||||
, mdbook-linkcheck
|
||||
@@ -239,6 +240,7 @@ in {
|
||||
gtest
|
||||
rapidcheck
|
||||
] ++ lib.optional stdenv.isLinux libseccomp
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid
|
||||
# There have been issues building these dependencies
|
||||
++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin))
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index 710304b67..c73b30b80 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -58,6 +58,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2018,140 +2022,131 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
|
||||
- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ if (useChroot) {
|
||||
+
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- pathsInChroot[p] = p;
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ pathsInChroot[p] = p;
|
||||
+ }
|
||||
+
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
+
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- struct stat st;
|
||||
- if (lstat(path.c_str(), &st)) {
|
||||
- if (i.second.optional && errno == ENOENT)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(st.st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
- ;
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
+
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
+
|
||||
+ std::string path = i.first;
|
||||
+ struct stat st;
|
||||
+ if (lstat(path.c_str(), &st)) {
|
||||
+ if (i.second.optional && errno == ENOENT)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(st.st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true);
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true);
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- if (globalTmpDir.back() == '/') globalTmpDir.pop_back();
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ if (globalTmpDir.back() == '/') globalTmpDir.pop_back();
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From b429e96583e2d005c77df8c82261022397f20648 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index c73b30b80..e6f4c397d 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2137,8 +2137,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From 74b93c1edba00c2601e20b8acdcc78e29bd3f092 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 3/4] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index e6f4c397d..e81818fa8 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2143,15 +2143,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From c8de35f74cbce58651c3b64ba66061040f546b9f Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc
|
||||
index e81818fa8..078f1a5be 100644
|
||||
--- a/src/libstore/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/build/local-derivation-goal.cc
|
||||
@@ -2017,11 +2017,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2145,14 +2140,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2183,6 +2170,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2204,9 +2199,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,327 @@
|
||||
From 8217054e3554ffd376f42fb0a65087a7af2ddfab Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
package.nix | 5 +-
|
||||
.../unix/build/local-derivation-goal.cc | 223 +++++++++---------
|
||||
3 files changed, 118 insertions(+), 116 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 8f60bf4be..5e67e04be 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -62,13 +62,17 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
AC_STRUCT_DIRENT_D_TYPE
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/package.nix b/package.nix
|
||||
index 59265f522..28be97400 100644
|
||||
--- a/package.nix
|
||||
+++ b/package.nix
|
||||
@@ -27,6 +27,7 @@
|
||||
, libseccomp
|
||||
, libsodium
|
||||
, man
|
||||
+, darwin
|
||||
, lowdown
|
||||
, mdbook
|
||||
, mdbook-linkcheck
|
||||
@@ -249,7 +250,9 @@ in {
|
||||
] ++ lib.optionals buildUnitTests [
|
||||
gtest
|
||||
rapidcheck
|
||||
- ] ++ lib.optional stdenv.isLinux (libseccomp.overrideAttrs (_: rec {
|
||||
+ ]
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
+ ++ lib.optional stdenv.isLinux (libseccomp.overrideAttrs (_: rec {
|
||||
version = "2.5.5";
|
||||
src = fetchurl {
|
||||
url = "https://github.com/seccomp/libseccomp/releases/download/v${version}/libseccomp-${version}.tar.gz";
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index b8ccdf834..449d4b07c 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -58,6 +58,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2026,141 +2030,132 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
+
|
||||
+ if (useChroot) {
|
||||
|
||||
- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- pathsInChroot[p] = p;
|
||||
- }
|
||||
-
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
- ;
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ pathsInChroot[p] = p;
|
||||
+ }
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- auto optSt = maybeLstat(path.c_str());
|
||||
- if (!optSt) {
|
||||
- if (i.second.optional)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of required path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(optSt->st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
-
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
+
|
||||
+ std::string path = i.first;
|
||||
+ auto optSt = maybeLstat(path.c_str());
|
||||
+ if (!optSt) {
|
||||
+ if (i.second.optional)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of required path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(optSt->st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
- globalTmpDir.pop_back();
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
+
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
+
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
+ globalTmpDir.pop_back();
|
||||
+
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From f0677f190d0bd042c3a864508a5307b19a2c2d26 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 449d4b07c..b74bd2e64 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2146,8 +2146,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From 1b39753f4d63465c709d18482945ce680b6f3f1e Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 3/4] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index b74bd2e64..9b8b3c51b 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2152,15 +2152,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From 9e198a75f76ac08f835975d4b2743e156616a219 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
.../unix/build/local-derivation-goal.cc | 25 ++++++++-----------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 9b8b3c51b..08366712c 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2025,11 +2025,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2154,14 +2149,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2192,6 +2179,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2213,9 +2208,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,323 @@
|
||||
From 05994033d58e358ddafe51d1d04626eb76b8a192 Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
package.nix | 2 +
|
||||
.../unix/build/local-derivation-goal.cc | 223 +++++++++---------
|
||||
3 files changed, 116 insertions(+), 115 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 90a6d45d5..f98a0a5ea 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -62,12 +62,16 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/package.nix b/package.nix
|
||||
index cf1654c6a..1dfe7ab31 100644
|
||||
--- a/package.nix
|
||||
+++ b/package.nix
|
||||
@@ -27,6 +27,7 @@
|
||||
, libseccomp
|
||||
, libsodium
|
||||
, man
|
||||
+, darwin
|
||||
, lowdown
|
||||
, mdbook
|
||||
, mdbook-linkcheck
|
||||
@@ -250,6 +251,7 @@ in {
|
||||
gtest
|
||||
rapidcheck
|
||||
] ++ lib.optional stdenv.isLinux libseccomp
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid
|
||||
# There have been issues building these dependencies
|
||||
++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin))
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index ae9c715d6..878644fa5 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -58,6 +58,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2017,141 +2021,132 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
+
|
||||
+ if (useChroot) {
|
||||
|
||||
- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- pathsInChroot[p] = p;
|
||||
- }
|
||||
-
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
- ;
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ pathsInChroot[p] = p;
|
||||
+ }
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- auto optSt = maybeLstat(path.c_str());
|
||||
- if (!optSt) {
|
||||
- if (i.second.optional)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of required path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(optSt->st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
-
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
+
|
||||
+ std::string path = i.first;
|
||||
+ auto optSt = maybeLstat(path.c_str());
|
||||
+ if (!optSt) {
|
||||
+ if (i.second.optional)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of required path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(optSt->st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
- globalTmpDir.pop_back();
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
+
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
+
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
+ globalTmpDir.pop_back();
|
||||
+
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From c43954ffac356b4168cbcfe2a67b4bad3f0dff5d Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 878644fa5..0df1f0683 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2137,8 +2137,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From 53b4bdcb8b0f114bea978cffbea325fd73f779b5 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 3/4] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 0df1f0683..9e67283c9 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2143,15 +2143,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From 67b5c7004302cbd344f63ccd306673a9adec4520 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
.../unix/build/local-derivation-goal.cc | 25 ++++++++-----------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 9e67283c9..1f4bafb56 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2016,11 +2016,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2145,14 +2140,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2183,6 +2170,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2204,9 +2199,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,323 @@
|
||||
From 170242cf0ca3e9fadbad2004126793634d56623e Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 1/5] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
package.nix | 2 +
|
||||
.../unix/build/local-derivation-goal.cc | 223 +++++++++---------
|
||||
3 files changed, 116 insertions(+), 115 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 5c22ed176..dff35981b 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -62,12 +62,16 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/package.nix b/package.nix
|
||||
index a7c8923e8..fcd1e1898 100644
|
||||
--- a/package.nix
|
||||
+++ b/package.nix
|
||||
@@ -23,6 +23,7 @@
|
||||
, libseccomp
|
||||
, libsodium
|
||||
, man
|
||||
+, darwin
|
||||
, lowdown
|
||||
, mdbook
|
||||
, mdbook-linkcheck
|
||||
@@ -235,6 +236,7 @@ in {
|
||||
gtest
|
||||
rapidcheck
|
||||
] ++ lib.optional stdenv.isLinux libseccomp
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid
|
||||
# There have been issues building these dependencies
|
||||
++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin))
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 54ca69580..7ce266122 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -58,6 +58,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2039,141 +2043,132 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
+
|
||||
+ if (useChroot) {
|
||||
|
||||
- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- pathsInChroot[p] = p;
|
||||
- }
|
||||
-
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
- ;
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ pathsInChroot[p] = p;
|
||||
+ }
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- auto optSt = maybeLstat(path.c_str());
|
||||
- if (!optSt) {
|
||||
- if (i.second.optional)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of required path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(optSt->st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
-
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
+
|
||||
+ std::string path = i.first;
|
||||
+ auto optSt = maybeLstat(path.c_str());
|
||||
+ if (!optSt) {
|
||||
+ if (i.second.optional)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of required path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(optSt->st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
- globalTmpDir.pop_back();
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
+
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
+
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
+ globalTmpDir.pop_back();
|
||||
+
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,53 @@
|
||||
From f8a1a149c73113e01c44b73ce9e1005575d52a9a Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:23:17 +0200
|
||||
Subject: [PATCH 2/5] packaging: Add darwin -lsandbox in meson
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/meson.build | 5 +++++
|
||||
src/libstore/package.nix | 2 ++
|
||||
2 files changed, 7 insertions(+)
|
||||
|
||||
diff --git a/src/libstore/meson.build b/src/libstore/meson.build
|
||||
index 50b15e15d..b23c85061 100644
|
||||
--- a/src/libstore/meson.build
|
||||
+++ b/src/libstore/meson.build
|
||||
@@ -68,6 +68,11 @@ has_acl_support = cxx.has_header('sys/xattr.h') \
|
||||
and cxx.has_function('lremovexattr')
|
||||
configdata.set('HAVE_ACL_SUPPORT', has_acl_support.to_int())
|
||||
|
||||
+if host_machine.system() == 'darwin'
|
||||
+ sandbox = cxx.find_library('sandbox')
|
||||
+ deps_other += [sandbox]
|
||||
+endif
|
||||
+
|
||||
subdir('build-utils-meson/threads')
|
||||
|
||||
boost = dependency(
|
||||
diff --git a/src/libstore/package.nix b/src/libstore/package.nix
|
||||
index 4582ba0d2..d98bac16d 100644
|
||||
--- a/src/libstore/package.nix
|
||||
+++ b/src/libstore/package.nix
|
||||
@@ -7,6 +7,7 @@
|
||||
, ninja
|
||||
, pkg-config
|
||||
, unixtools
|
||||
+, darwin
|
||||
|
||||
, nix-util
|
||||
, boost
|
||||
@@ -65,6 +66,7 @@ mkMesonDerivation (finalAttrs: {
|
||||
sqlite
|
||||
] ++ lib.optional stdenv.hostPlatform.isLinux libseccomp
|
||||
# There have been issues building these dependencies
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin))
|
||||
aws-sdk-cpp
|
||||
;
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From ae7a2ea74136363c2f6ac6e624ea95da7abfafcc Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 3/5] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 7ce266122..706771e8e 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2159,8 +2159,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From 047ee50db2f660eb3f50fab8f7543ce95e814b7c Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 4/5] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 706771e8e..d9738a1ea 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2165,15 +2165,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From 50f83e4bbd9107576399f94449ac9cb4e80d575e Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 5/5] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
.../unix/build/local-derivation-goal.cc | 25 ++++++++-----------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index d9738a1ea..2a09e3dd4 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2038,11 +2038,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2167,14 +2162,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2205,6 +2192,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2226,9 +2221,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
From 766263d53ae69d70c5915426e6e8f58abd988226 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Tue, 22 Oct 2024 15:28:04 +0200
|
||||
Subject: [PATCH 1/6] Fix meson build on darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
std::stringbuf is defined in <sstream>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libutil/strings.cc | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/src/libutil/strings.cc b/src/libutil/strings.cc
|
||||
index d1c9f700c..c221a43c6 100644
|
||||
--- a/src/libutil/strings.cc
|
||||
+++ b/src/libutil/strings.cc
|
||||
@@ -1,5 +1,6 @@
|
||||
#include <filesystem>
|
||||
#include <string>
|
||||
+#include <sstream>
|
||||
|
||||
#include "strings-inline.hh"
|
||||
#include "os-string.hh"
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,323 @@
|
||||
From d2c880b03f58eb4fdd6d19eb3ffa4345a0477419 Mon Sep 17 00:00:00 2001
|
||||
From: Puck Meerburg <puck@puckipedia.com>
|
||||
Date: Fri, 1 Mar 2024 11:42:24 -0500
|
||||
Subject: [PATCH 2/6] fix: Run all derivation builders inside the sandbox on
|
||||
macOS
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
configure.ac | 6 +-
|
||||
package.nix | 2 +
|
||||
.../unix/build/local-derivation-goal.cc | 223 +++++++++---------
|
||||
3 files changed, 116 insertions(+), 115 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 198198dea..c7c9b3f4b 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -62,12 +62,16 @@ AC_CHECK_TOOL([AR], [ar])
|
||||
AC_SYS_LARGEFILE
|
||||
|
||||
|
||||
-# Solaris-specific stuff.
|
||||
+# OS-specific stuff.
|
||||
case "$host_os" in
|
||||
solaris*)
|
||||
# Solaris requires -lsocket -lnsl for network functions
|
||||
LDFLAGS="-lsocket -lnsl $LDFLAGS"
|
||||
;;
|
||||
+ darwin*)
|
||||
+ # Need to link to libsandbox.
|
||||
+ LDFLAGS="-lsandbox $LDFLAGS"
|
||||
+ ;;
|
||||
esac
|
||||
|
||||
|
||||
diff --git a/package.nix b/package.nix
|
||||
index 00621d475..77f1de58c 100644
|
||||
--- a/package.nix
|
||||
+++ b/package.nix
|
||||
@@ -23,6 +23,7 @@
|
||||
, libseccomp
|
||||
, libsodium
|
||||
, man
|
||||
+, darwin
|
||||
, lowdown
|
||||
, mdbook
|
||||
, mdbook-linkcheck
|
||||
@@ -232,6 +233,7 @@ in {
|
||||
gtest
|
||||
rapidcheck
|
||||
] ++ lib.optional stdenv.isLinux libseccomp
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid
|
||||
# There have been issues building these dependencies
|
||||
++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin))
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index b4685b3a7..067755c0d 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -58,6 +58,10 @@
|
||||
#if __APPLE__
|
||||
#include <spawn.h>
|
||||
#include <sys/sysctl.h>
|
||||
+#include <sandbox.h>
|
||||
+
|
||||
+/* This definition is undocumented but depended upon by all major browsers. */
|
||||
+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf);
|
||||
#endif
|
||||
|
||||
#include <pwd.h>
|
||||
@@ -2088,141 +2092,132 @@ void LocalDerivationGoal::runChild()
|
||||
|
||||
std::string builder = "invalid";
|
||||
|
||||
- if (drv->isBuiltin()) {
|
||||
- ;
|
||||
- }
|
||||
#if __APPLE__
|
||||
- else {
|
||||
- /* This has to appear before import statements. */
|
||||
- std::string sandboxProfile = "(version 1)\n";
|
||||
-
|
||||
- if (useChroot) {
|
||||
-
|
||||
- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
- PathSet ancestry;
|
||||
-
|
||||
- /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
- all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
- particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- Path cur = i.first;
|
||||
- while (cur.compare("/") != 0) {
|
||||
- cur = dirOf(cur);
|
||||
- ancestry.insert(cur);
|
||||
- }
|
||||
- }
|
||||
+ /* This has to appear before import statements. */
|
||||
+ std::string sandboxProfile = "(version 1)\n";
|
||||
+
|
||||
+ if (useChroot) {
|
||||
|
||||
- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
- path component this time, since it's typically /nix/store and we care about that. */
|
||||
- Path cur = worker.store.storeDir;
|
||||
+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */
|
||||
+ PathSet ancestry;
|
||||
+
|
||||
+ /* We build the ancestry before adding all inputPaths to the store because we know they'll
|
||||
+ all have the same parents (the store), and there might be lots of inputs. This isn't
|
||||
+ particularly efficient... I doubt it'll be a bottleneck in practice */
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ Path cur = i.first;
|
||||
while (cur.compare("/") != 0) {
|
||||
- ancestry.insert(cur);
|
||||
cur = dirOf(cur);
|
||||
+ ancestry.insert(cur);
|
||||
}
|
||||
+ }
|
||||
|
||||
- /* Add all our input paths to the chroot */
|
||||
- for (auto & i : inputPaths) {
|
||||
- auto p = worker.store.printStorePath(i);
|
||||
- pathsInChroot[p] = p;
|
||||
- }
|
||||
-
|
||||
- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
- if (settings.darwinLogSandboxViolations) {
|
||||
- sandboxProfile += "(deny default)\n";
|
||||
- } else {
|
||||
- sandboxProfile += "(deny default (with no-log))\n";
|
||||
- }
|
||||
+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost
|
||||
+ path component this time, since it's typically /nix/store and we care about that. */
|
||||
+ Path cur = worker.store.storeDir;
|
||||
+ while (cur.compare("/") != 0) {
|
||||
+ ancestry.insert(cur);
|
||||
+ cur = dirOf(cur);
|
||||
+ }
|
||||
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-defaults.sb"
|
||||
- ;
|
||||
+ /* Add all our input paths to the chroot */
|
||||
+ for (auto & i : inputPaths) {
|
||||
+ auto p = worker.store.printStorePath(i);
|
||||
+ pathsInChroot[p] = p;
|
||||
+ }
|
||||
|
||||
- if (!derivationType->isSandboxed())
|
||||
- sandboxProfile +=
|
||||
- #include "sandbox-network.sb"
|
||||
- ;
|
||||
-
|
||||
- /* Add the output paths we'll use at build-time to the chroot */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & [_, path] : scratchOutputs)
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
-
|
||||
- sandboxProfile += ")\n";
|
||||
-
|
||||
- /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
-
|
||||
- without file-write* allowed, access() incorrectly returns EPERM
|
||||
- */
|
||||
- sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
- for (auto & i : pathsInChroot) {
|
||||
- if (i.first != i.second.source)
|
||||
- throw Error(
|
||||
- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
- i.first, i.second.source);
|
||||
-
|
||||
- std::string path = i.first;
|
||||
- auto optSt = maybeLstat(path.c_str());
|
||||
- if (!optSt) {
|
||||
- if (i.second.optional)
|
||||
- continue;
|
||||
- throw SysError("getting attributes of required path '%s", path);
|
||||
- }
|
||||
- if (S_ISDIR(optSt->st_mode))
|
||||
- sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
- else
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */
|
||||
+ if (settings.darwinLogSandboxViolations) {
|
||||
+ sandboxProfile += "(deny default)\n";
|
||||
+ } else {
|
||||
+ sandboxProfile += "(deny default (with no-log))\n";
|
||||
+ }
|
||||
|
||||
- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
- sandboxProfile += "(allow file-read*\n";
|
||||
- for (auto & i : ancestry) {
|
||||
- sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
- }
|
||||
- sandboxProfile += ")\n";
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-defaults.sb"
|
||||
+ ;
|
||||
|
||||
- sandboxProfile += additionalSandboxProfile;
|
||||
- } else
|
||||
+ if (!derivationType->isSandboxed())
|
||||
sandboxProfile +=
|
||||
- #include "sandbox-minimal.sb"
|
||||
+ #include "sandbox-network.sb"
|
||||
;
|
||||
|
||||
- debug("Generated sandbox profile:");
|
||||
- debug(sandboxProfile);
|
||||
-
|
||||
- Path sandboxFile = tmpDir + "/.sandbox.sb";
|
||||
+ /* Add the output paths we'll use at build-time to the chroot */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & [_, path] : scratchOutputs)
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path));
|
||||
|
||||
- writeFile(sandboxFile, sandboxProfile);
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+ /* Our inputs (transitive dependencies and any impurities computed above)
|
||||
|
||||
- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
- Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+ without file-write* allowed, access() incorrectly returns EPERM
|
||||
+ */
|
||||
+ sandboxProfile += "(allow file-read* file-write* process-exec\n";
|
||||
+ for (auto & i : pathsInChroot) {
|
||||
+ if (i.first != i.second.source)
|
||||
+ throw Error(
|
||||
+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin",
|
||||
+ i.first, i.second.source);
|
||||
+
|
||||
+ std::string path = i.first;
|
||||
+ auto optSt = maybeLstat(path.c_str());
|
||||
+ if (!optSt) {
|
||||
+ if (i.second.optional)
|
||||
+ continue;
|
||||
+ throw SysError("getting attributes of required path '%s", path);
|
||||
+ }
|
||||
+ if (S_ISDIR(optSt->st_mode))
|
||||
+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path);
|
||||
+ else
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", path);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- /* They don't like trailing slashes on subpath directives */
|
||||
- while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
- globalTmpDir.pop_back();
|
||||
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
|
||||
+ sandboxProfile += "(allow file-read*\n";
|
||||
+ for (auto & i : ancestry) {
|
||||
+ sandboxProfile += fmt("\t(literal \"%s\")\n", i);
|
||||
+ }
|
||||
+ sandboxProfile += ")\n";
|
||||
|
||||
- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
- builder = "/usr/bin/sandbox-exec";
|
||||
- args.push_back("sandbox-exec");
|
||||
- args.push_back("-f");
|
||||
- args.push_back(sandboxFile);
|
||||
- args.push_back("-D");
|
||||
- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir);
|
||||
- if (allowLocalNetworking) {
|
||||
- args.push_back("-D");
|
||||
- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1"));
|
||||
- }
|
||||
- args.push_back(drv->builder);
|
||||
- } else {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+ sandboxProfile += additionalSandboxProfile;
|
||||
+ } else
|
||||
+ sandboxProfile +=
|
||||
+ #include "sandbox-minimal.sb"
|
||||
+ ;
|
||||
+
|
||||
+ debug("Generated sandbox profile:");
|
||||
+ debug(sandboxProfile);
|
||||
+
|
||||
+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking");
|
||||
+
|
||||
+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms
|
||||
+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */
|
||||
+ Path globalTmpDir = canonPath(defaultTempDir(), true);
|
||||
+
|
||||
+ /* They don't like trailing slashes on subpath directives */
|
||||
+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/')
|
||||
+ globalTmpDir.pop_back();
|
||||
+
|
||||
+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") {
|
||||
+ Strings sandboxArgs;
|
||||
+ sandboxArgs.push_back("_GLOBAL_TMP_DIR");
|
||||
+ sandboxArgs.push_back(globalTmpDir);
|
||||
+ if (allowLocalNetworking) {
|
||||
+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
+ sandboxArgs.push_back("1");
|
||||
+ }
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
+ writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ _exit(1);
|
||||
}
|
||||
}
|
||||
+
|
||||
+ builder = drv->builder;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
#else
|
||||
- else {
|
||||
+ if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,53 @@
|
||||
From f7335530619f9b18d6cc249a297e4dca369101a5 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:23:17 +0200
|
||||
Subject: [PATCH 3/6] packaging: Add darwin -lsandbox in meson
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/meson.build | 5 +++++
|
||||
src/libstore/package.nix | 2 ++
|
||||
2 files changed, 7 insertions(+)
|
||||
|
||||
diff --git a/src/libstore/meson.build b/src/libstore/meson.build
|
||||
index 6a6aabf97..c2aa5bff3 100644
|
||||
--- a/src/libstore/meson.build
|
||||
+++ b/src/libstore/meson.build
|
||||
@@ -69,6 +69,11 @@ has_acl_support = cxx.has_header('sys/xattr.h') \
|
||||
and cxx.has_function('lremovexattr')
|
||||
configdata.set('HAVE_ACL_SUPPORT', has_acl_support.to_int())
|
||||
|
||||
+if host_machine.system() == 'darwin'
|
||||
+ sandbox = cxx.find_library('sandbox')
|
||||
+ deps_other += [sandbox]
|
||||
+endif
|
||||
+
|
||||
subdir('build-utils-meson/threads')
|
||||
|
||||
boost = dependency(
|
||||
diff --git a/src/libstore/package.nix b/src/libstore/package.nix
|
||||
index 9568462b5..f04e3b95f 100644
|
||||
--- a/src/libstore/package.nix
|
||||
+++ b/src/libstore/package.nix
|
||||
@@ -3,6 +3,7 @@
|
||||
, mkMesonLibrary
|
||||
|
||||
, unixtools
|
||||
+, darwin
|
||||
|
||||
, nix-util
|
||||
, boost
|
||||
@@ -56,6 +57,7 @@ mkMesonLibrary (finalAttrs: {
|
||||
sqlite
|
||||
] ++ lib.optional stdenv.hostPlatform.isLinux libseccomp
|
||||
# There have been issues building these dependencies
|
||||
+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox
|
||||
++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin))
|
||||
aws-sdk-cpp
|
||||
;
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
From 14d09e0b55898ac22d4cdeade3bf6c4174052ffd Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:44:12 +0200
|
||||
Subject: [PATCH 4/6] local-derivation-goal: Print sandbox error detail on
|
||||
darwin
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +++--
|
||||
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index 067755c0d..f34d68403 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2208,8 +2208,9 @@ void LocalDerivationGoal::runChild()
|
||||
sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING");
|
||||
sandboxArgs.push_back("1");
|
||||
}
|
||||
- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) {
|
||||
- writeFull(STDERR_FILENO, "failed to configure sandbox\n");
|
||||
+ char * sandbox_errbuf = nullptr;
|
||||
+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) {
|
||||
+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)"));
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
From 06e27042e176b79561f50decb0fdf836b7bec3f5 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:50:27 +0200
|
||||
Subject: [PATCH 5/6] local-derivation-goal: Refactor
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This works because the `builder` and `args` variables are only used
|
||||
in the non-builtin code path.
|
||||
|
||||
Co-Authored-By: Théophane Hufschmitt <theophane.hufschmitt@tweag.io>
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
src/libstore/unix/build/local-derivation-goal.cc | 5 +----
|
||||
1 file changed, 1 insertion(+), 4 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index f34d68403..f781a84c6 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2214,15 +2214,12 @@ void LocalDerivationGoal::runChild()
|
||||
_exit(1);
|
||||
}
|
||||
}
|
||||
+#endif
|
||||
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
-#else
|
||||
if (!drv->isBuiltin()) {
|
||||
builder = drv->builder;
|
||||
args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
}
|
||||
-#endif
|
||||
|
||||
for (auto & i : drv->args)
|
||||
args.push_back(rewriteStrings(i, inputRewrites));
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
From d1e0bae55afb3c3ef0bcad5d644b0e04da6279b3 Mon Sep 17 00:00:00 2001
|
||||
From: Robert Hensing <robert@roberthensing.nl>
|
||||
Date: Thu, 3 Oct 2024 12:57:00 +0200
|
||||
Subject: [PATCH 6/6] local-derivation-goal: Move builder preparation to
|
||||
non-builtin code path
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
Signed-off-by: Jörg Thalheim <joerg@thalheim.io>
|
||||
---
|
||||
.../unix/build/local-derivation-goal.cc | 25 ++++++++-----------
|
||||
1 file changed, 10 insertions(+), 15 deletions(-)
|
||||
|
||||
diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
index f781a84c6..dcfaadeef 100644
|
||||
--- a/src/libstore/unix/build/local-derivation-goal.cc
|
||||
+++ b/src/libstore/unix/build/local-derivation-goal.cc
|
||||
@@ -2087,11 +2087,6 @@ void LocalDerivationGoal::runChild()
|
||||
throw SysError("setuid failed");
|
||||
}
|
||||
|
||||
- /* Fill in the arguments. */
|
||||
- Strings args;
|
||||
-
|
||||
- std::string builder = "invalid";
|
||||
-
|
||||
#if __APPLE__
|
||||
/* This has to appear before import statements. */
|
||||
std::string sandboxProfile = "(version 1)\n";
|
||||
@@ -2216,14 +2211,6 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
#endif
|
||||
|
||||
- if (!drv->isBuiltin()) {
|
||||
- builder = drv->builder;
|
||||
- args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
- }
|
||||
-
|
||||
- for (auto & i : drv->args)
|
||||
- args.push_back(rewriteStrings(i, inputRewrites));
|
||||
-
|
||||
/* Indicate that we managed to set up the build environment. */
|
||||
writeFull(STDERR_FILENO, std::string("\2\n"));
|
||||
|
||||
@@ -2254,6 +2241,14 @@ void LocalDerivationGoal::runChild()
|
||||
}
|
||||
}
|
||||
|
||||
+ // Now builder is not builtin
|
||||
+
|
||||
+ Strings args;
|
||||
+ args.push_back(std::string(baseNameOf(drv->builder)));
|
||||
+
|
||||
+ for (auto & i : drv->args)
|
||||
+ args.push_back(rewriteStrings(i, inputRewrites));
|
||||
+
|
||||
#if __APPLE__
|
||||
posix_spawnattr_t attrp;
|
||||
|
||||
@@ -2275,9 +2270,9 @@ void LocalDerivationGoal::runChild()
|
||||
posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL);
|
||||
}
|
||||
|
||||
- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#else
|
||||
- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data());
|
||||
#endif
|
||||
|
||||
throw SysError("executing '%1%'", drv->builder);
|
||||
--
|
||||
2.46.1
|
||||
|
||||
@@ -33193,6 +33193,8 @@ with pkgs;
|
||||
|
||||
scudcloud = callPackage ../applications/networking/instant-messengers/scudcloud { };
|
||||
|
||||
scx = recurseIntoAttrs (callPackage ../os-specific/linux/scx { });
|
||||
|
||||
shod = callPackage ../applications/window-managers/shod { };
|
||||
|
||||
shotcut = qt6Packages.callPackage ../applications/video/shotcut {
|
||||
@@ -36625,7 +36627,10 @@ with pkgs;
|
||||
fltk = fltk-minimal;
|
||||
};
|
||||
|
||||
factorio = callPackage ../games/factorio { releaseType = "alpha"; };
|
||||
factorio = callPackage ../games/factorio {
|
||||
releaseType = "alpha";
|
||||
versionsJson = ../games/factorio/versions-1.json;
|
||||
};
|
||||
|
||||
factorio-experimental = factorio.override { releaseType = "alpha"; experimental = true; };
|
||||
|
||||
@@ -36635,6 +36640,30 @@ with pkgs;
|
||||
|
||||
factorio-demo = factorio.override { releaseType = "demo"; };
|
||||
|
||||
factorio_1 = factorio;
|
||||
|
||||
factorio_1-experimental = factorio-experimental;
|
||||
|
||||
factorio_1-headless = factorio-headless;
|
||||
|
||||
factorio_1-headless-experimental = factorio-headless-experimental;
|
||||
|
||||
factorio_1-demo = factorio-demo;
|
||||
|
||||
factorio_2 = factorio.override { versionsJson = ../games/factorio/versions.json; };
|
||||
|
||||
factorio_2-experimental = factorio-experimental.override { versionsJson = ../games/factorio/versions.json; };
|
||||
|
||||
factorio_2-headless = factorio-headless.override { versionsJson = ../games/factorio/versions.json; };
|
||||
|
||||
factorio_2-headless-experimental = factorio-headless-experimental.override { versionsJson = ../games/factorio/versions.json; };
|
||||
|
||||
# there is no factorio_2-demo
|
||||
|
||||
factorio-space-age = factorio_2.override { releaseType = "expansion"; };
|
||||
|
||||
factorio-space-age-experimental = factorio_2.override { releaseType = "expansion"; experimental = true; };
|
||||
|
||||
factorio-mods = callPackage ../games/factorio/mods.nix { };
|
||||
|
||||
factorio-utils = callPackage ../games/factorio/utils.nix { };
|
||||
|
||||
Reference in New Issue
Block a user