From c77f7a3881cd6bcfab29c75f118aaf8c856abdc5 Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Mon, 4 Dec 2023 22:38:54 +0000 Subject: [PATCH 1/8] python3Packages.wagtail: add patch for CVE-2023-45809 --- pkgs/development/python-modules/wagtail/default.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/development/python-modules/wagtail/default.nix b/pkgs/development/python-modules/wagtail/default.nix index 54f5a8ce1790..b0be74b76fd0 100644 --- a/pkgs/development/python-modules/wagtail/default.nix +++ b/pkgs/development/python-modules/wagtail/default.nix @@ -9,6 +9,7 @@ , django_treebeard , djangorestframework , draftjs-exporter +, fetchpatch , fetchPypi , html5lib , l18n @@ -30,6 +31,14 @@ buildPythonPackage rec { sha256 = "sha256-s89gs3H//Dc3k6BLZUC4APyDgiWY9LetWAkI+kXQTf8="; }; + patches = [ + (fetchpatch { + name = "CVE-2023-45809.patch"; + url = "https://github.com/wagtail/wagtail/commit/0bacd29473107d9d7f5b723a15a683449679756d.patch"; + sha256 = "sha256-f14ZvO3UYZDlUNYup9OeqSdArGBL7QZYNP0KB/sQgWc="; + }) + ]; + postPatch = '' substituteInPlace setup.py \ --replace "beautifulsoup4>=4.8,<4.12" "beautifulsoup4>=4.8" From 778b25872f809010af13c4b4e288b69b6a445966 Mon Sep 17 00:00:00 2001 From: networkException Date: Sat, 9 Dec 2023 13:55:21 +0100 Subject: [PATCH 2/8] chromium: 119.0.6045.199 -> 120.0.6099.71 https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_6.html This update includes 10 security fixes. CVEs: CVE-2023-6508 CVE-2023-6509 CVE-2023-6510 CVE-2023-6511 CVE-2023-6512 Co-authored-by: emilylange (cherry picked from commit ca726d0a8a74bd04568357eee27e6d4ccbdd5733) --- .../networking/browsers/chromium/upstream-info.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/upstream-info.nix b/pkgs/applications/networking/browsers/chromium/upstream-info.nix index 505d4b54b16f..b754c999deab 100644 --- a/pkgs/applications/networking/browsers/chromium/upstream-info.nix +++ b/pkgs/applications/networking/browsers/chromium/upstream-info.nix @@ -35,15 +35,15 @@ }; deps = { gn = { - rev = "991530ce394efb58fcd848195469022fa17ae126"; - sha256 = "1zpbaspb2mncbsabps8n1iwzc67nhr79ndc9dnqxx1w1qfvaldg2"; + rev = "e4702d7409069c4f12d45ea7b7f0890717ca3f4b"; + sha256 = "1fbkpdsxbma41yja4s27j4i3f1pa38784f8knhq9plzawwc6w2bp"; url = "https://gn.googlesource.com/gn"; - version = "2023-09-12"; + version = "2023-10-23"; }; }; - sha256 = "0f11p5gf98islrp6w10ji8lw9jpnc8jzl54d9902zjai0r3hx81f"; - sha256bin64 = "1if5zzjsnzjnl917hnkb569mi4cgdikxx6lpi6sy7g6pk7466xpn"; - version = "119.0.6045.199"; + sha256 = "0jpmrp6cgm8xbsdrl219h5hr7yi0dan2qrhbwrkx3xxn2wi1v1nq"; + sha256bin64 = "15r1kx4jnbrcw7kfma528ks5ic17s4ydh1ncsb680himhln02z64"; + version = "120.0.6099.71"; }; ungoogled-chromium = { deps = { From fb92de7f45e74eb9b413e4f94fe8d10a025753c7 Mon Sep 17 00:00:00 2001 From: networkException Date: Sat, 9 Dec 2023 13:55:23 +0100 Subject: [PATCH 3/8] ungoogled-chromium: 119.0.6045.199-1 -> 120.0.6099.71-1 https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_6.html This update includes 10 security fixes. CVEs: CVE-2023-6508 CVE-2023-6509 CVE-2023-6510 CVE-2023-6511 CVE-2023-6512 (cherry picked from commit db8b5f058ef1e7809f5838e86ade81483d304d42) --- .../browsers/chromium/upstream-info.nix | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/upstream-info.nix b/pkgs/applications/networking/browsers/chromium/upstream-info.nix index b754c999deab..9ee4c2a2451e 100644 --- a/pkgs/applications/networking/browsers/chromium/upstream-info.nix +++ b/pkgs/applications/networking/browsers/chromium/upstream-info.nix @@ -48,18 +48,18 @@ ungoogled-chromium = { deps = { gn = { - rev = "991530ce394efb58fcd848195469022fa17ae126"; - sha256 = "1zpbaspb2mncbsabps8n1iwzc67nhr79ndc9dnqxx1w1qfvaldg2"; + rev = "e4702d7409069c4f12d45ea7b7f0890717ca3f4b"; + sha256 = "1fbkpdsxbma41yja4s27j4i3f1pa38784f8knhq9plzawwc6w2bp"; url = "https://gn.googlesource.com/gn"; - version = "2023-09-12"; + version = "2023-10-23"; }; ungoogled-patches = { - rev = "119.0.6045.199-1"; - sha256 = "1j64sah88j7q86cjqf0cqa85mc8ka59nm37vz0bxwpnydap3khb5"; + rev = "120.0.6099.71-1"; + sha256 = "1wl8ykvpcww399xi8p3i8bp78fq44hpcnvijlg42ikxmrpsashjb"; }; }; - sha256 = "0f11p5gf98islrp6w10ji8lw9jpnc8jzl54d9902zjai0r3hx81f"; - sha256bin64 = "1if5zzjsnzjnl917hnkb569mi4cgdikxx6lpi6sy7g6pk7466xpn"; - version = "119.0.6045.199"; + sha256 = "0jpmrp6cgm8xbsdrl219h5hr7yi0dan2qrhbwrkx3xxn2wi1v1nq"; + sha256bin64 = "15r1kx4jnbrcw7kfma528ks5ic17s4ydh1ncsb680himhln02z64"; + version = "120.0.6099.71"; }; } From 3d40a42f1c68613c7311b473178a2b4005be86bc Mon Sep 17 00:00:00 2001 From: networkException Date: Sat, 9 Dec 2023 13:55:24 +0100 Subject: [PATCH 4/8] chromedriver: 119.0.6045.105 -> 120.0.6099.71 (cherry picked from commit 4a34a5f2d4587892bdc1df6cde4cd1b6c285bdbe) --- .../networking/browsers/chromium/upstream-info.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/upstream-info.nix b/pkgs/applications/networking/browsers/chromium/upstream-info.nix index 9ee4c2a2451e..c7ca030a6534 100644 --- a/pkgs/applications/networking/browsers/chromium/upstream-info.nix +++ b/pkgs/applications/networking/browsers/chromium/upstream-info.nix @@ -27,11 +27,11 @@ }; stable = { chromedriver = { - sha256_darwin = "08jlxh2xngd8dn1r88d6ryl1mjmhba36ma7yla93yds02bsi845i"; + sha256_darwin = "020qzjy8aq7y4gxpn2vjw71k7p3bvqhsvqkja99n2wndw8w0l6sf"; sha256_darwin_aarch64 = - "137nzad2h2hqpzwqk7jimb23sw2rwz9j2iz7c5cz7v2wzaqw3qsk"; - sha256_linux = "1xkzqc7cja56b4rdbqv1b2996k9jqicvykzcsnic04m9il18p3ns"; - version = "119.0.6045.105"; + "1byi0k7kxg6x23j8161ndrm73j9v4wrpk3ydygnvk48biw54nl2i"; + sha256_linux = "1dvakqyn5s75k5hcjrydqgp003m5l7abvyd9b2whjbasa1my5ijz"; + version = "120.0.6099.71"; }; deps = { gn = { From bd0447257be926709a9fe311d1853684ba84a229 Mon Sep 17 00:00:00 2001 From: emilylange Date: Sat, 9 Dec 2023 13:55:25 +0100 Subject: [PATCH 5/8] chromium: fix build for chromium >=120 (cherry picked from commit 17ca7f65295805d8ebfeef2b81b68122fb30886e) --- .../chromium/chromium-120-llvm-16.patch | 43 +++++++++++++++++++ .../networking/browsers/chromium/common.nix | 4 ++ 2 files changed, 47 insertions(+) create mode 100644 pkgs/applications/networking/browsers/chromium/chromium-120-llvm-16.patch diff --git a/pkgs/applications/networking/browsers/chromium/chromium-120-llvm-16.patch b/pkgs/applications/networking/browsers/chromium/chromium-120-llvm-16.patch new file mode 100644 index 000000000000..99a8c521a08a --- /dev/null +++ b/pkgs/applications/networking/browsers/chromium/chromium-120-llvm-16.patch @@ -0,0 +1,43 @@ +diff --git a/build/config/compiler/BUILD.gn b/build/config/compiler/BUILD.gn +index de1cd6e..bb5700b 100644 +--- a/build/config/compiler/BUILD.gn ++++ b/build/config/compiler/BUILD.gn +@@ -616,24 +616,6 @@ config("compiler") { + } + } + +- # TODO(crbug.com/1488374): This causes binary size growth and potentially +- # other problems. +- # TODO(crbug.com/1491036): This isn't supported by Cronet's mainline llvm version. +- if (default_toolchain != "//build/toolchain/cros:target" && +- !llvm_android_mainline) { +- cflags += [ +- "-mllvm", +- "-split-threshold-for-reg-with-hint=0", +- ] +- if (use_thin_lto && is_a_target_toolchain) { +- if (is_win) { +- ldflags += [ "-mllvm:-split-threshold-for-reg-with-hint=0" ] +- } else { +- ldflags += [ "-Wl,-mllvm,-split-threshold-for-reg-with-hint=0" ] +- } +- } +- } +- + # TODO(crbug.com/1235145): Investigate why/if this should be needed. + if (is_win) { + cflags += [ "/clang:-ffp-contract=off" ] +@@ -800,13 +782,6 @@ config("compiler") { + if (is_apple) { + ldflags += [ "-Wcrl,object_path_lto" ] + } +- if (!is_chromeos) { +- # TODO(https://crbug.com/972449): turn on for ChromeOS when that +- # toolchain has this flag. +- # We only use one version of LLVM within a build so there's no need to +- # upgrade debug info, which can be expensive since it runs the verifier. +- ldflags += [ "-Wl,-mllvm,-disable-auto-upgrade-debug-info" ] +- } + } + + # TODO(https://crbug.com/1211155): investigate why this isn't effective on diff --git a/pkgs/applications/networking/browsers/chromium/common.nix b/pkgs/applications/networking/browsers/chromium/common.nix index e17a43966cca..b890bce8a322 100644 --- a/pkgs/applications/networking/browsers/chromium/common.nix +++ b/pkgs/applications/networking/browsers/chromium/common.nix @@ -195,6 +195,7 @@ let # (we currently package 1.26 in Nixpkgs while Chromium bundles 1.21): # Source: https://bugs.chromium.org/p/angleproject/issues/detail?id=7582#c1 ./patches/angle-wayland-include-protocol.patch + ] ++ lib.optionals (!chromiumVersionAtLeast "120") [ # We need to revert this patch to build M114+ with LLVM 16: (githubPatch { # Reland [clang] Disable autoupgrading debug info in ThinLTO builds @@ -202,6 +203,9 @@ let sha256 = "sha256-Vryjg8kyn3cxWg3PmSwYRG6zrHOqYWBMSdEMGiaPg6M="; revert = true; }) + ] ++ lib.optionals (chromiumVersionAtLeast "120") [ + # We need to revert this patch to build M120+ with LLVM 16: + ./chromium-120-llvm-16.patch ]; postPatch = '' From f9c9bb7e1aa1cfe99c22765d3c00a3fac2eb8745 Mon Sep 17 00:00:00 2001 From: emilylange Date: Sat, 9 Dec 2023 23:29:39 +0100 Subject: [PATCH 6/8] chromium: fix eval due to redundant version bounds --- .../applications/networking/browsers/chromium/common.nix | 9 --------- 1 file changed, 9 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/common.nix b/pkgs/applications/networking/browsers/chromium/common.nix index b890bce8a322..bacdfdcd9326 100644 --- a/pkgs/applications/networking/browsers/chromium/common.nix +++ b/pkgs/applications/networking/browsers/chromium/common.nix @@ -195,15 +195,6 @@ let # (we currently package 1.26 in Nixpkgs while Chromium bundles 1.21): # Source: https://bugs.chromium.org/p/angleproject/issues/detail?id=7582#c1 ./patches/angle-wayland-include-protocol.patch - ] ++ lib.optionals (!chromiumVersionAtLeast "120") [ - # We need to revert this patch to build M114+ with LLVM 16: - (githubPatch { - # Reland [clang] Disable autoupgrading debug info in ThinLTO builds - commit = "54969766fd2029c506befc46e9ce14d67c7ed02a"; - sha256 = "sha256-Vryjg8kyn3cxWg3PmSwYRG6zrHOqYWBMSdEMGiaPg6M="; - revert = true; - }) - ] ++ lib.optionals (chromiumVersionAtLeast "120") [ # We need to revert this patch to build M120+ with LLVM 16: ./chromium-120-llvm-16.patch ]; From 54dc8e9dbfbd6166c7b3ac2ec30070068645afa8 Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Sun, 3 Dec 2023 22:45:31 +0000 Subject: [PATCH 7/8] router: add CVE-2023-45812 to knownVulnerabilities (cherry picked from commit ed972a40b2f3f8b2185f6ecfc7cad859e4d9550a) --- pkgs/servers/http/router/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/servers/http/router/default.nix b/pkgs/servers/http/router/default.nix index 4ce676c1099b..d88a2e4a25fa 100644 --- a/pkgs/servers/http/router/default.nix +++ b/pkgs/servers/http/router/default.nix @@ -42,5 +42,6 @@ rustPlatform.buildRustPackage rec { homepage = "https://www.apollographql.com/docs/router/"; license = licenses.elastic; maintainers = [ maintainers.bbigras ]; + knownVulnerabilities = [ "CVE-2023-45812" ]; }; } From 9a0a31a3fe232f52150e8e38f1f542a48060e0dc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Sat, 9 Dec 2023 17:53:05 +0100 Subject: [PATCH 8/8] linux: drop XEN on 32-bit It doesn't build anymore and I doubt anyone wants to maintain it: https://hydra.nixos.org/build/243596962/nixlog/1 (cherry picked from commit 096639c548e2b0256309c92c53542e052eaa3761) --- .../linux/kernel/common-config.nix | 36 +++++++++---------- 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/common-config.nix b/pkgs/os-specific/linux/kernel/common-config.nix index e2390141800a..8c1305a9cf55 100644 --- a/pkgs/os-specific/linux/kernel/common-config.nix +++ b/pkgs/os-specific/linux/kernel/common-config.nix @@ -648,24 +648,24 @@ let VBOXGUEST = option no; DRM_VBOXVIDEO = option no; - XEN = option yes; - XEN_DOM0 = option yes; - PCI_XEN = option yes; - HVC_XEN = option yes; - HVC_XEN_FRONTEND = option yes; - XEN_SYS_HYPERVISOR = option yes; - SWIOTLB_XEN = option yes; - XEN_BACKEND = option yes; - XEN_BALLOON = option yes; - XEN_BALLOON_MEMORY_HOTPLUG = option yes; - XEN_EFI = option yes; - XEN_HAVE_PVMMU = option yes; - XEN_MCE_LOG = option yes; - XEN_PVH = option yes; - XEN_PVHVM = option yes; - XEN_SAVE_RESTORE = option yes; - XEN_SCRUB_PAGES = whenOlder "4.19" yes; - XEN_SELFBALLOONING = whenOlder "5.3" yes; + XEN = mkIf stdenv.is64bit (option yes); + XEN_DOM0 = mkIf stdenv.is64bit (option yes); + PCI_XEN = mkIf stdenv.is64bit (option yes); + HVC_XEN = mkIf stdenv.is64bit (option yes); + HVC_XEN_FRONTEND = mkIf stdenv.is64bit (option yes); + XEN_SYS_HYPERVISOR = mkIf stdenv.is64bit (option yes); + SWIOTLB_XEN = mkIf stdenv.is64bit (option yes); + XEN_BACKEND = mkIf stdenv.is64bit (option yes); + XEN_BALLOON = mkIf stdenv.is64bit (option yes); + XEN_BALLOON_MEMORY_HOTPLUG = mkIf stdenv.is64bit (option yes); + XEN_EFI = mkIf stdenv.is64bit (option yes); + XEN_HAVE_PVMMU = mkIf stdenv.is64bit (option yes); + XEN_MCE_LOG = mkIf stdenv.is64bit (option yes); + XEN_PVH = mkIf stdenv.is64bit (option yes); + XEN_PVHVM = mkIf stdenv.is64bit (option yes); + XEN_SAVE_RESTORE = mkIf stdenv.is64bit (option yes); + XEN_SCRUB_PAGES = mkIf stdenv.is64bit (whenOlder "4.19" yes); + XEN_SELFBALLOONING = mkIf stdenv.is64bit (whenOlder "5.3" yes); # Enable device detection on virtio-mmio hypervisors VIRTIO_MMIO_CMDLINE_DEVICES = yes;