From aaa045714c53964418d667aa152196a82a65cc5a Mon Sep 17 00:00:00 2001 From: euxane Date: Thu, 1 Aug 2024 07:24:53 +0200 Subject: [PATCH 01/21] nixos/fcgiwrap-instances: backport isolated multi-instance module This backports the options `services.fcgiwrap.instances.*`, allowing to configure isolated instances of fcgiwrap, as an alternative to the global shared one. This prepares the deprecation of the latter. Backport of: commit efc7aebda7f85f67b52cc334066c6dd344371103 nixos/fcgiwrap: require explicit owner for UNIX sockets commit 4f2da6c9c17d75ba43fbe85d5243a57735a5e4eb nixos/fcgiwrap: add option migration instruction errors (partial: move to instances) commit 51b246a1acd4ce4926b8a78e3e7e0e6927d546ff nixos/fcgiwrap: do not run as root by default commit 81f72015f0b96b1227a2de38409049fba0e73aad nixos/fcgiwrap: add unix socket owner, private by default commit 289c1585c2a1f9ff9e159cbcdab664620dc9f7b3 nixos/fcgiwrap: limit prefork type to positives commit 3955eaf45015c9dd8a5a59412bf9c5e47b789a65 nixos/fcgiwrap: improve readability of CLI args commit 022289f2fadb3a3bad83273cd45d8a3e4753991e nixos/fcgiwrap: group options logically, fix doc commit 41419ca2883f7a3294711faf4961d043868e27ef nixos/fcgiwrap: refactor for multiple instances --- nixos/modules/module-list.nix | 1 + .../web-servers/fcgiwrap-instances.nix | 136 ++++++++++++++++++ 2 files changed, 137 insertions(+) create mode 100644 nixos/modules/services/web-servers/fcgiwrap-instances.nix diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index 2479b219a3bc..0cff23251a09 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -1456,6 +1456,7 @@ ./services/web-servers/caddy/default.nix ./services/web-servers/darkhttpd.nix ./services/web-servers/fcgiwrap.nix + ./services/web-servers/fcgiwrap-instances.nix ./services/web-servers/garage.nix ./services/web-servers/hitch/default.nix ./services/web-servers/hydron.nix diff --git a/nixos/modules/services/web-servers/fcgiwrap-instances.nix b/nixos/modules/services/web-servers/fcgiwrap-instances.nix new file mode 100644 index 000000000000..4c02af7867d5 --- /dev/null +++ b/nixos/modules/services/web-servers/fcgiwrap-instances.nix @@ -0,0 +1,136 @@ +{ config, lib, pkgs, ... }: + +with lib; + +let + forEachInstance = f: flip mapAttrs' config.services.fcgiwrap.instances ( + name: cfg: nameValuePair "fcgiwrap-${name}" (f cfg) + ); + +in { + options.services.fcgiwrap.instances = mkOption { + description = "Configuration for fcgiwrap instances."; + default = { }; + type = types.attrsOf (types.submodule ({ config, ... }: { options = { + process.prefork = mkOption { + type = types.ints.positive; + default = 1; + description = "Number of processes to prefork."; + }; + + process.user = mkOption { + type = types.nullOr types.str; + default = null; + description = '' + User as which this instance of fcgiwrap will be run. + Set to `null` (the default) to use a dynamically allocated user. + ''; + }; + + process.group = mkOption { + type = types.nullOr types.str; + default = null; + description = "Group as which this instance of fcgiwrap will be run."; + }; + + socket.type = mkOption { + type = types.enum [ "unix" "tcp" "tcp6" ]; + default = "unix"; + description = "Socket type: 'unix', 'tcp' or 'tcp6'."; + }; + + socket.address = mkOption { + type = types.str; + default = "/run/fcgiwrap-${config._module.args.name}.sock"; + example = "1.2.3.4:5678"; + description = '' + Socket address. + In case of a UNIX socket, this should be its filesystem path. + ''; + }; + + socket.user = mkOption { + type = types.nullOr types.str; + default = null; + description = '' + User to be set as owner of the UNIX socket. + ''; + }; + + socket.group = mkOption { + type = types.nullOr types.str; + default = null; + description = '' + Group to be set as owner of the UNIX socket. + ''; + }; + + socket.mode = mkOption { + type = types.nullOr types.str; + default = if config.socket.type == "unix" then "0600" else null; + defaultText = literalExpression '' + if config.socket.type == "unix" then "0600" else null + ''; + description = '' + Mode to be set on the UNIX socket. + Defaults to private to the socket's owner. + ''; + }; + }; })); + }; + + config = { + assertions = concatLists (mapAttrsToList (name: cfg: [ + { + assertion = cfg.socket.type == "unix" -> cfg.socket.user != null; + message = "Socket owner is required for the UNIX socket type."; + } + { + assertion = cfg.socket.type == "unix" -> cfg.socket.group != null; + message = "Socket owner is required for the UNIX socket type."; + } + { + assertion = cfg.socket.user != null -> cfg.socket.type == "unix"; + message = "Socket owner can only be set for the UNIX socket type."; + } + { + assertion = cfg.socket.group != null -> cfg.socket.type == "unix"; + message = "Socket owner can only be set for the UNIX socket type."; + } + { + assertion = cfg.socket.mode != null -> cfg.socket.type == "unix"; + message = "Socket mode can only be set for the UNIX socket type."; + } + ]) config.services.fcgiwrap.instances); + + systemd.services = forEachInstance (cfg: { + after = [ "nss-user-lookup.target" ]; + wantedBy = optional (cfg.socket.type != "unix") "multi-user.target"; + + serviceConfig = { + ExecStart = '' + ${pkgs.fcgiwrap}/sbin/fcgiwrap ${cli.toGNUCommandLineShell {} ({ + c = cfg.process.prefork; + } // (optionalAttrs (cfg.socket.type != "unix") { + s = "${cfg.socket.type}:${cfg.socket.address}"; + }))} + ''; + } // (if cfg.process.user != null then { + User = cfg.process.user; + Group = cfg.process.group; + } else { + DynamicUser = true; + }); + }); + + systemd.sockets = forEachInstance (cfg: mkIf (cfg.socket.type == "unix") { + wantedBy = [ "sockets.target" ]; + socketConfig = { + ListenStream = cfg.socket.address; + SocketUser = cfg.socket.user; + SocketGroup = cfg.socket.group; + SocketMode = cfg.socket.mode; + }; + }); + }; +} From 0cb1143443bdadeef1cd62f90219c2db5d898e1e Mon Sep 17 00:00:00 2001 From: euxane Date: Thu, 1 Aug 2024 07:24:53 +0200 Subject: [PATCH 02/21] nixos/fcgiwrap: add deprecation notice and security warning This deprecates the use of the global shared instance of fcgiwrap, due to its security issues (running as root by default, actually insecure control socket, allowing local remote escalation privileges, with no fix due to the multiple consumers). A warning is added to encourage users to migrate to properly isolated instances (`services.fcgiwrap.instances.*`). --- .../modules/services/web-servers/fcgiwrap.nix | 27 ++++++++++++++----- 1 file changed, 21 insertions(+), 6 deletions(-) diff --git a/nixos/modules/services/web-servers/fcgiwrap.nix b/nixos/modules/services/web-servers/fcgiwrap.nix index 3250e9c05ed6..aa0623c3328d 100644 --- a/nixos/modules/services/web-servers/fcgiwrap.nix +++ b/nixos/modules/services/web-servers/fcgiwrap.nix @@ -4,6 +4,12 @@ with lib; let cfg = config.services.fcgiwrap; + deprecationNote = '' + + This global instance option is deprecated in favour of per-instance + options configured through `services.fcgiwrap.instances.*`. + ''; + in { options = { @@ -11,43 +17,52 @@ in { enable = mkOption { type = types.bool; default = false; - description = "Whether to enable fcgiwrap, a server for running CGI applications over FastCGI."; + description = "Whether to enable fcgiwrap, a server for running CGI applications over FastCGI." + deprecationNote; }; preforkProcesses = mkOption { type = types.int; default = 1; - description = "Number of processes to prefork."; + description = "Number of processes to prefork." + deprecationNote; }; socketType = mkOption { type = types.enum [ "unix" "tcp" "tcp6" ]; default = "unix"; - description = "Socket type: 'unix', 'tcp' or 'tcp6'."; + description = "Socket type: 'unix', 'tcp' or 'tcp6'." + deprecationNote; }; socketAddress = mkOption { type = types.str; default = "/run/fcgiwrap.sock"; example = "1.2.3.4:5678"; - description = "Socket address. In case of a UNIX socket, this should be its filesystem path."; + description = "Socket address. In case of a UNIX socket, this should be its filesystem path." + deprecationNote; }; user = mkOption { type = types.nullOr types.str; default = null; - description = "User permissions for the socket."; + description = "User permissions for the socket." + deprecationNote; }; group = mkOption { type = types.nullOr types.str; default = null; - description = "Group permissions for the socket."; + description = "Group permissions for the socket." + deprecationNote; }; }; }; config = mkIf cfg.enable { + warnings = [ + '' + The fcgiwrap module is configured with a global shared instance. + This has security implications: . + Isolated instances should instead be configured through `services.fcgiwrap.instances.*'. + The global options at `services.fcgiwrap.*` will be removed in NixOS 24.11. + '' + ]; + systemd.services.fcgiwrap = { after = [ "nss-user-lookup.target" ]; wantedBy = optional (cfg.socketType != "unix") "multi-user.target"; From 6a8e12421c0e3fa868f3e972b9093fc62788f642 Mon Sep 17 00:00:00 2001 From: euxane Date: Thu, 1 Aug 2024 07:24:53 +0200 Subject: [PATCH 03/21] nixos/smokeping: use isolated fcgiwrap instance This makes the CGI part of smokeping run as the unprivileged "smokeping" user like the rest of the service (instead of root). This also sets proper permissions for the fcgiwrap control socket. Backport of: commit 4f2da6c9c17d75ba43fbe85d5243a57735a5e4eb nixos/fcgiwrap: add option migration instruction errors (partial: move to instances) commit c5dc3e203410bc3bfc77182cd8c6955b1bd64cfd nixos/fcgiwrap: adapt consumer modules and tests commit 8101ae41f8cefce9e518a550881302c4f58a8c5b nixos/fcgiwrap: adapt consumer modules and tests commit bf2ad6f48c95eea96768cc62dda7c6eb2097cbf4 nixos/fcgiwrap: adapt consumer modules and tests --- nixos/modules/services/networking/smokeping.nix | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/nixos/modules/services/networking/smokeping.nix b/nixos/modules/services/networking/smokeping.nix index 3fb3eac45cc8..9973c8cefbbc 100644 --- a/nixos/modules/services/networking/smokeping.nix +++ b/nixos/modules/services/networking/smokeping.nix @@ -328,6 +328,7 @@ in }; preStart = '' mkdir -m 0755 -p ${smokepingHome}/cache ${smokepingHome}/data + chown -R ${cfg.user}:${cfg.user} ${smokepingHome}/{cache,data} ln -snf ${cfg.package}/htdocs/css ${smokepingHome}/css ln -snf ${cfg.package}/htdocs/js ${smokepingHome}/js ln -snf ${cgiHome} ${smokepingHome}/smokeping.fcgi @@ -337,7 +338,11 @@ in }; # use nginx to serve the smokeping web service - services.fcgiwrap.enable = mkIf cfg.webService true; + services.fcgiwrap.instances.smokeping = mkIf cfg.webService { + process.user = cfg.user; + process.group = cfg.user; + socket = { inherit (config.services.nginx) user group; }; + }; services.nginx = mkIf cfg.webService { enable = true; virtualHosts."smokeping" = { @@ -349,7 +354,7 @@ in locations."/smokeping.fcgi" = { extraConfig = '' include ${config.services.nginx.package}/conf/fastcgi_params; - fastcgi_pass unix:${config.services.fcgiwrap.socketAddress}; + fastcgi_pass unix:${config.services.fcgiwrap.instances.smokeping.socket.address}; fastcgi_param SCRIPT_FILENAME ${smokepingHome}/smokeping.fcgi; fastcgi_param DOCUMENT_ROOT ${smokepingHome}; ''; From 483dd7e3c642d0b71f7dce536b4255f0669d028c Mon Sep 17 00:00:00 2001 From: euxane Date: Thu, 1 Aug 2024 07:24:53 +0200 Subject: [PATCH 04/21] nixos/zoneminder: use isolated fcgiwrap instance Backport of: commit fcb2a4a5fff1903d403955a9753a34f79bb24455 nixos/zoneminder: set fcgiwrap socket owner commit 4f2da6c9c17d75ba43fbe85d5243a57735a5e4eb nixos/fcgiwrap: add option migration instruction errors (partial: move to instances) commit 8101ae41f8cefce9e518a550881302c4f58a8c5b nixos/fcgiwrap: adapt consumer modules and tests commit bf2ad6f48c95eea96768cc62dda7c6eb2097cbf4 nixos/fcgiwrap: adapt consumer modules and tests --- nixos/modules/services/misc/zoneminder.nix | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/nixos/modules/services/misc/zoneminder.nix b/nixos/modules/services/misc/zoneminder.nix index d09cd87febff..469af04d106d 100644 --- a/nixos/modules/services/misc/zoneminder.nix +++ b/nixos/modules/services/misc/zoneminder.nix @@ -202,10 +202,11 @@ in { ]; services = { - fcgiwrap = lib.mkIf useNginx { - enable = true; - preforkProcesses = cfg.cameras; - inherit user group; + fcgiwrap.instances.zoneminder = lib.mkIf useNginx { + process.prefork = cfg.cameras; + process.user = user; + process.group = group; + socket = { inherit (config.services.nginx) user group; }; }; mysql = lib.mkIf cfg.database.createLocally { @@ -225,9 +226,7 @@ in { default = true; root = "${pkg}/share/zoneminder/www"; listen = [ { addr = "0.0.0.0"; inherit (cfg) port; } ]; - extraConfig = let - fcgi = config.services.fcgiwrap; - in '' + extraConfig = '' index index.php; location / { @@ -257,7 +256,7 @@ in { fastcgi_param HTTP_PROXY ""; fastcgi_intercept_errors on; - fastcgi_pass ${fcgi.socketType}:${fcgi.socketAddress}; + fastcgi_pass unix:${config.services.fcgiwrap.instances.zoneminder.socket.address}; } location /cache/ { From 31cdff5bafec3425fc1b81ad570f97bf4c10d53a Mon Sep 17 00:00:00 2001 From: euxane Date: Thu, 1 Aug 2024 07:24:53 +0200 Subject: [PATCH 05/21] nixos/cgit: use isolated fcgiwrap instance, add user/group options This adds options to set the users and groups as which cgit instances run, allowing the use of an unprivileged user instead of root. "root" is kept as the default user to avoid breaking existing setups, but a warning is shown in that case to alert the user. Backport of: commit 4f2da6c9c17d75ba43fbe85d5243a57735a5e4eb nixos/fcgiwrap: add option migration instruction errors (partial: move to instances) commit 3d10deb7a5631e057bb5d84b5a6bd8fdf361a00a nixos/cgit: fix GIT_PROJECT_ROOT ownership commit 2d8626bf0a35659a480c1a92bbd2682625a66e0f nixos/cgit: configurable user instead of root commit c5dc3e203410bc3bfc77182cd8c6955b1bd64cfd nixos/fcgiwrap: adapt consumer modules and tests commit 8101ae41f8cefce9e518a550881302c4f58a8c5b nixos/fcgiwrap: adapt consumer modules and tests commit bf2ad6f48c95eea96768cc62dda7c6eb2097cbf4 nixos/fcgiwrap: adapt consumer modules and tests --- nixos/modules/services/networking/cgit.nix | 103 +++++++++++++++------ 1 file changed, 75 insertions(+), 28 deletions(-) diff --git a/nixos/modules/services/networking/cgit.nix b/nixos/modules/services/networking/cgit.nix index 0ccbef756812..6f15e92aa2c4 100644 --- a/nixos/modules/services/networking/cgit.nix +++ b/nixos/modules/services/networking/cgit.nix @@ -25,14 +25,14 @@ let regexLocation = cfg: regexEscape (stripLocation cfg); - mkFastcgiPass = cfg: '' + mkFastcgiPass = name: cfg: '' ${if cfg.nginx.location == "/" then '' fastcgi_param PATH_INFO $uri; '' else '' fastcgi_split_path_info ^(${regexLocation cfg})(/.+)$; fastcgi_param PATH_INFO $fastcgi_path_info; '' - }fastcgi_pass unix:${config.services.fcgiwrap.socketAddress}; + }fastcgi_pass unix:${config.services.fcgiwrap.instances."cgit-${name}".socket.address}; ''; cgitrcLine = name: value: "${name}=${ @@ -72,25 +72,11 @@ let ${cfg.extraConfig} ''; - mkCgitReposDir = cfg: - if cfg.scanPath != null then - cfg.scanPath - else - pkgs.runCommand "cgit-repos" { - preferLocalBuild = true; - allowSubstitutes = false; - } '' - mkdir -p "$out" - ${ - concatStrings ( - mapAttrsToList - (name: value: '' - ln -s ${escapeShellArg value.path} "$out"/${escapeShellArg name} - '') - cfg.repos - ) - } - ''; + fcgiwrapUnitName = name: "fcgiwrap-cgit-${name}"; + fcgiwrapRuntimeDir = name: "/run/${fcgiwrapUnitName name}"; + gitProjectRoot = name: cfg: if cfg.scanPath != null + then cfg.scanPath + else "${fcgiwrapRuntimeDir name}/repos"; in { @@ -154,6 +140,30 @@ in type = types.lines; default = ""; }; + + user = mkOption { + description = '' + User to run the cgit service as. + + Defaults to "root" for compatibility with legacy setups. + Will default to the unprivileged user "cgit" in NixOS 24.11. + ''; + type = types.str; + default = "root"; + example = "cgit"; + }; + + group = mkOption { + description = '' + Group to run the cgit service as. + + Defaults to "root" for compatibility with legacy setups. + Will default to the unprivileged user "cgit" in NixOS 24.11. + ''; + type = types.str; + default = "root"; + example = "cgit"; + }; }; })); }; @@ -165,18 +175,55 @@ in message = "Exactly one of services.cgit.${vhost}.scanPath or services.cgit.${vhost}.repos must be set."; }) cfgs; - services.fcgiwrap.enable = true; + warnings = flatten (flip mapAttrsToList cfgs (inst: cfg: + optional (cfg.user == "root") '' + `services.cgit.${inst}` is configured to run as root. + This has security implications: . + It is recommended to set an unprivileged user explicitly. + This default user will be set to "cgit" in NixOS 24.11. + '' + )); + + users = mkMerge (flip mapAttrsToList cfgs (_: cfg: { + users.${cfg.user} = { + isSystemUser = true; + inherit (cfg) group; + }; + groups.${cfg.group} = { }; + })); + + services.fcgiwrap.instances = flip mapAttrs' cfgs (name: cfg: + nameValuePair "cgit-${name}" { + process = { inherit (cfg) user group; }; + socket = { inherit (config.services.nginx) user group; }; + } + ); + + systemd.services = flip mapAttrs' cfgs (name: cfg: + nameValuePair (fcgiwrapUnitName name) + (mkIf (cfg.repos != { }) { + serviceConfig.RuntimeDirectory = fcgiwrapUnitName name; + preStart = '' + GIT_PROJECT_ROOT=${escapeShellArg (gitProjectRoot name cfg)} + mkdir -p "$GIT_PROJECT_ROOT" + cd "$GIT_PROJECT_ROOT" + ${concatLines (flip mapAttrsToList cfg.repos (name: repo: '' + ln -s ${escapeShellArg repo.path} ${escapeShellArg name} + ''))} + ''; + } + )); services.nginx.enable = true; - services.nginx.virtualHosts = mkMerge (mapAttrsToList (_: cfg: { + services.nginx.virtualHosts = mkMerge (mapAttrsToList (name: cfg: { ${cfg.nginx.virtualHost} = { locations = ( genAttrs' [ "cgit.css" "cgit.png" "favicon.ico" "robots.txt" ] - (name: nameValuePair "= ${stripLocation cfg}/${name}" { + (fileName: nameValuePair "= ${stripLocation cfg}/${fileName}" { extraConfig = '' - alias ${cfg.package}/cgit/${name}; + alias ${cfg.package}/cgit/${fileName}; ''; }) ) // { @@ -184,10 +231,10 @@ in fastcgiParams = rec { SCRIPT_FILENAME = "${pkgs.git}/libexec/git-core/git-http-backend"; GIT_HTTP_EXPORT_ALL = "1"; - GIT_PROJECT_ROOT = mkCgitReposDir cfg; + GIT_PROJECT_ROOT = gitProjectRoot name cfg; HOME = GIT_PROJECT_ROOT; }; - extraConfig = mkFastcgiPass cfg; + extraConfig = mkFastcgiPass name cfg; }; "${stripLocation cfg}/" = { fastcgiParams = { @@ -196,7 +243,7 @@ in HTTP_HOST = "$server_name"; CGIT_CONFIG = mkCgitrc cfg; }; - extraConfig = mkFastcgiPass cfg; + extraConfig = mkFastcgiPass name cfg; }; }; }; From fee11ef959adac33aa2bca8ccbb7dda918fce8f6 Mon Sep 17 00:00:00 2001 From: euxane Date: Thu, 8 Aug 2024 02:22:48 +0200 Subject: [PATCH 06/21] nixos/fcgiwrap: fail eval with security assertion This adds a security assertion when using the global instance of fcgiwrap, which is vulnerable to a local privilege escalation. This is in addition to the current evaluation warning, and is more in line with being loud with security issues, similarly to with vulnerable packages. The evaluation failure can nevertheless be bypassed by setting: `services.fcgiwrap.allowGlobalInstanceLocalPrivilegeEscalation = true`. --- .../modules/services/web-servers/fcgiwrap.nix | 34 +++++++++++++++---- 1 file changed, 27 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/web-servers/fcgiwrap.nix b/nixos/modules/services/web-servers/fcgiwrap.nix index aa0623c3328d..290bcfd9b65c 100644 --- a/nixos/modules/services/web-servers/fcgiwrap.nix +++ b/nixos/modules/services/web-servers/fcgiwrap.nix @@ -9,6 +9,12 @@ let This global instance option is deprecated in favour of per-instance options configured through `services.fcgiwrap.instances.*`. ''; + securityWarning = '' + The fcgiwrap module is configured with a global shared instance. + This has security implications: . + Isolated instances should instead be configured through `services.fcgiwrap.instances.*'. + The global options at `services.fcgiwrap.*` will be removed in NixOS 24.11. + ''; in { @@ -20,6 +26,17 @@ in { description = "Whether to enable fcgiwrap, a server for running CGI applications over FastCGI." + deprecationNote; }; + allowGlobalInstanceLocalPrivilegeEscalation = mkOption { + type = types.bool; + default = false; + description = '' + The global instance of fcgiwrap configured through this module + has a local privilege escalation vulnerability. + Set this option to true to accept the risk and bypass the evaluation + failure regardless. + ''; + }; + preforkProcesses = mkOption { type = types.int; default = 1; @@ -54,15 +71,18 @@ in { }; config = mkIf cfg.enable { - warnings = [ - '' - The fcgiwrap module is configured with a global shared instance. - This has security implications: . - Isolated instances should instead be configured through `services.fcgiwrap.instances.*'. - The global options at `services.fcgiwrap.*` will be removed in NixOS 24.11. - '' + assertions = [ + { + assertion = cfg.allowGlobalInstanceLocalPrivilegeEscalation; + message = securityWarning + '' + To temporarily accept the risk and continue using the global instance, + set `services.fcgiwrap.allowGlobalInstanceLocalPrivilegeEscalation` to true. + ''; + } ]; + warnings = [ securityWarning ]; + systemd.services.fcgiwrap = { after = [ "nss-user-lookup.target" ]; wantedBy = optional (cfg.socketType != "unix") "multi-user.target"; From 692598621b05dac62f22f86c094085249a9011d3 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 3 Jul 2024 04:25:17 +0000 Subject: [PATCH 07/21] argocd: 2.11.3 -> 2.11.4 (cherry picked from commit a73a0c75ee666c53914c60e0ccd4076b6db609c3) --- pkgs/applications/networking/cluster/argocd/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/argocd/default.nix b/pkgs/applications/networking/cluster/argocd/default.nix index 6e860d2318c4..c4698ed9338b 100644 --- a/pkgs/applications/networking/cluster/argocd/default.nix +++ b/pkgs/applications/networking/cluster/argocd/default.nix @@ -2,17 +2,17 @@ buildGoModule rec { pname = "argocd"; - version = "2.11.3"; + version = "2.11.4"; src = fetchFromGitHub { owner = "argoproj"; repo = "argo-cd"; rev = "v${version}"; - hash = "sha256-qSrMqByhOitRltYaVjIeubuoTR74x/pQ1Ad+uTPdpJU="; + hash = "sha256-G7kJrFyAsaAWXKn2Nya66unkYlU3EU1ZDbdXpC8aR+k="; }; proxyVendor = true; # darwin/linux hash mismatch - vendorHash = "sha256-atgNLlHoX+KBtJcYZNqNsYBK0cVGI/k2mXvmcr6wWN4="; + vendorHash = "sha256-IDnOB3GxWKeA/N4Mr+qQh9sJgYsWK38F2yw6jDuHY30="; # Set target as ./cmd per cli-local # https://github.com/argoproj/argo-cd/blob/master/Makefile#L227 From 78de3ca2c29ab65c22b029dc982318251c38c027 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 16 Jul 2024 04:25:49 +0000 Subject: [PATCH 08/21] argocd: 2.11.4 -> 2.11.5 (cherry picked from commit 252969af28d362dd233f140065c45daf0a83e0c6) --- pkgs/applications/networking/cluster/argocd/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/argocd/default.nix b/pkgs/applications/networking/cluster/argocd/default.nix index c4698ed9338b..9432bdd29fc5 100644 --- a/pkgs/applications/networking/cluster/argocd/default.nix +++ b/pkgs/applications/networking/cluster/argocd/default.nix @@ -2,17 +2,17 @@ buildGoModule rec { pname = "argocd"; - version = "2.11.4"; + version = "2.11.5"; src = fetchFromGitHub { owner = "argoproj"; repo = "argo-cd"; rev = "v${version}"; - hash = "sha256-G7kJrFyAsaAWXKn2Nya66unkYlU3EU1ZDbdXpC8aR+k="; + hash = "sha256-0Td4TMi9HTvf+GeW2f/ufRW0Y3KBrBSDWhgPW4noXi4="; }; proxyVendor = true; # darwin/linux hash mismatch - vendorHash = "sha256-IDnOB3GxWKeA/N4Mr+qQh9sJgYsWK38F2yw6jDuHY30="; + vendorHash = "sha256-y6B//zal2OyzZ1slC+x3vxHasFTM+xD+/6Sd2AFHFgY="; # Set target as ./cmd per cli-local # https://github.com/argoproj/argo-cd/blob/master/Makefile#L227 From 9eb18e6db60cdb9df34bf72e440f8f8961d1ded0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 25 Jul 2024 11:39:24 +0000 Subject: [PATCH 09/21] argocd: 2.11.5 -> 2.11.7 (cherry picked from commit 54c550855a6904cfa1ba343f9382ac18a37f94d2) --- pkgs/applications/networking/cluster/argocd/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/cluster/argocd/default.nix b/pkgs/applications/networking/cluster/argocd/default.nix index 9432bdd29fc5..f52622591763 100644 --- a/pkgs/applications/networking/cluster/argocd/default.nix +++ b/pkgs/applications/networking/cluster/argocd/default.nix @@ -2,13 +2,13 @@ buildGoModule rec { pname = "argocd"; - version = "2.11.5"; + version = "2.11.7"; src = fetchFromGitHub { owner = "argoproj"; repo = "argo-cd"; rev = "v${version}"; - hash = "sha256-0Td4TMi9HTvf+GeW2f/ufRW0Y3KBrBSDWhgPW4noXi4="; + hash = "sha256-/gbclPcYSDobwftFi0CECgBp6PNqxHW9svP3A5y8eEY="; }; proxyVendor = true; # darwin/linux hash mismatch From ad8ebb15ad5952cd01df27601a2d8e57e2cad49b Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Mon, 26 Aug 2024 18:01:18 +0100 Subject: [PATCH 10/21] duckdb: add patch for CVE-2024-41672 --- pkgs/development/libraries/duckdb/default.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pkgs/development/libraries/duckdb/default.nix b/pkgs/development/libraries/duckdb/default.nix index 343574f251a8..42a180949be2 100644 --- a/pkgs/development/libraries/duckdb/default.nix +++ b/pkgs/development/libraries/duckdb/default.nix @@ -30,6 +30,14 @@ stdenv.mkDerivation (finalAttrs: { rev = "refs/tags/v${finalAttrs.version}"; }; + patches = [ + (fetchpatch { + name = "CVE-2024-41672.patch"; + url = "https://github.com/duckdb/duckdb/commit/c9b7c98aa0e1cd7363fe8bb8543a95f38e980d8a.patch"; + hash = "sha256-Zb962mWIgy2t/0csbwZ8BcLgpdIA9/JpJ0+EWr1Kg1g="; + }) + ]; + outputs = [ "out" "lib" "dev" ]; nativeBuildInputs = [ cmake ninja python3 ]; From 3eff4070df6e1ed33fc12131b5267170f7ede9f1 Mon Sep 17 00:00:00 2001 From: rnhmjoj Date: Mon, 26 Aug 2024 08:10:23 +0200 Subject: [PATCH 11/21] bup: 0.33.3 -> 0.33.4 (cherry picked from commit e0890103e3518a3bad4fb46c74e17e8cc8d4c4e4) --- pkgs/tools/backup/bup/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/backup/bup/default.nix b/pkgs/tools/backup/bup/default.nix index 07ae258a675f..c5ad1e44a0a1 100644 --- a/pkgs/tools/backup/bup/default.nix +++ b/pkgs/tools/backup/bup/default.nix @@ -6,7 +6,7 @@ assert par2Support -> par2cmdline != null; let - version = "0.33.3"; + version = "0.33.4"; pythonDeps = with python3.pkgs; [ setuptools tornado ] ++ lib.optionals (!stdenv.isDarwin) [ pyxattr pylibacl fuse ]; @@ -20,7 +20,7 @@ stdenv.mkDerivation { repo = "bup"; owner = "bup"; rev = version; - hash = "sha256-w7yPs7hG4v0Kd9i2tYhWH7vW95MAMfI/8g61MB6bfps="; + hash = "sha256-9rWzHONcu4W/JcnDUGPbuGksroODbhdL6bNF+3Dd2ag="; }; buildInputs = [ git python3 ]; From a8f54fe6eaa4bb31a09a7fc8a2399085dc7498e2 Mon Sep 17 00:00:00 2001 From: rnhmjoj Date: Mon, 26 Aug 2024 08:17:59 +0200 Subject: [PATCH 12/21] bup: move to pkgs/by-name and reformat (cherry picked from commit 881aca9e2056d6fe8e99314366832fb692440ec9) --- .../bu/bup/package.nix} | 42 +++++++++++++++---- pkgs/top-level/all-packages.nix | 2 - 2 files changed, 34 insertions(+), 10 deletions(-) rename pkgs/{tools/backup/bup/default.nix => by-name/bu/bup/package.nix} (68%) diff --git a/pkgs/tools/backup/bup/default.nix b/pkgs/by-name/bu/bup/package.nix similarity index 68% rename from pkgs/tools/backup/bup/default.nix rename to pkgs/by-name/bu/bup/package.nix index c5ad1e44a0a1..91fb2b3c3f71 100644 --- a/pkgs/tools/backup/bup/default.nix +++ b/pkgs/by-name/bu/bup/package.nix @@ -1,6 +1,15 @@ -{ lib, stdenv, fetchFromGitHub, makeWrapper -, perl, pandoc, python3, git -, par2cmdline ? null, par2Support ? true +{ + lib, + stdenv, + fetchFromGitHub, + makeWrapper, + perl, + pandoc, + python3, + git, + + par2Support ? true, + par2cmdline ? null, }: assert par2Support -> par2cmdline != null; @@ -8,8 +17,17 @@ assert par2Support -> par2cmdline != null; let version = "0.33.4"; - pythonDeps = with python3.pkgs; [ setuptools tornado ] - ++ lib.optionals (!stdenv.isDarwin) [ pyxattr pylibacl fuse ]; + pythonDeps = + with python3.pkgs; + [ + setuptools + tornado + ] + ++ lib.optionals (!stdenv.isDarwin) [ + pyxattr + pylibacl + fuse + ]; in stdenv.mkDerivation { @@ -23,8 +41,15 @@ stdenv.mkDerivation { hash = "sha256-9rWzHONcu4W/JcnDUGPbuGksroODbhdL6bNF+3Dd2ag="; }; - buildInputs = [ git python3 ]; - nativeBuildInputs = [ pandoc perl makeWrapper ]; + buildInputs = [ + git + python3 + ]; + nativeBuildInputs = [ + pandoc + perl + makeWrapper + ]; postPatch = "patchShebangs ."; @@ -37,7 +62,8 @@ stdenv.mkDerivation { "LIBDIR=$(out)/lib/bup" ]; - env.NIX_CFLAGS_COMPILE = lib.optionalString stdenv.cc.isClang "-Wno-error=implicit-function-declaration -Wno-error=implicit-int"; + env.NIX_CFLAGS_COMPILE = lib.optionalString stdenv.cc.isClang + "-Wno-error=implicit-function-declaration -Wno-error=implicit-int"; postInstall = '' wrapProgram $out/bin/bup \ diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 3fc3bc28e3b0..ea6ed35d0fcf 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6472,8 +6472,6 @@ with pkgs; bumpver = callPackage ../applications/version-management/bumpver { }; - bup = callPackage ../tools/backup/bup { }; - bupstash = darwin.apple_sdk_11_0.callPackage ../tools/backup/bupstash { }; burp = callPackage ../tools/backup/burp { }; From 41e7bbd2ddd55b66c63a30c977b59d52aececcbd Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 29 Aug 2024 19:17:22 +0000 Subject: [PATCH 13/21] mattermost: 9.5.8 -> 9.5.9 (cherry picked from commit 48b042c485eee3af4bc6f338995fe45dda5d21b6) --- pkgs/servers/mattermost/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/mattermost/default.nix b/pkgs/servers/mattermost/default.nix index 666e812a691b..fd66967da051 100644 --- a/pkgs/servers/mattermost/default.nix +++ b/pkgs/servers/mattermost/default.nix @@ -12,13 +12,13 @@ buildGoModule rec { # See https://docs.mattermost.com/upgrade/extended-support-release.html # When a new ESR version is available (e.g. 8.1.x -> 9.5.x), update # the version regex in passthru.updateScript as well. - version = "9.5.8"; + version = "9.5.9"; src = fetchFromGitHub { owner = "mattermost"; repo = "mattermost"; rev = "v${version}"; - hash = "sha256-WK3O1t2mMqftH8EB12g1/xzQnnmJxSsBjaGrRk0Hypw="; + hash = "sha256-mGTLn1aV6pB/ubqtYYF1zNRAaLj5IsdQTLhf1LzcNho="; }; # Needed because buildGoModule does not support go workspaces yet. @@ -34,7 +34,7 @@ buildGoModule rec { webapp = fetchurl { url = "https://releases.mattermost.com/${version}/mattermost-${version}-linux-amd64.tar.gz"; - hash = "sha256-gUp/Y0hI3oZkyTnEvyNXtHtPx77MC5zz+Z4b0FdrsqM="; + hash = "sha256-TgaRDIxGBoow1//99bGpp91HNYgdWRnoS09EDAFcHDs="; }; # Makes nix-update-script pick up the fetchurl for the webapp. From f0bfce09e09d67b7ca60e9177d953975892bb805 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 26 Aug 2024 22:32:01 +0000 Subject: [PATCH 14/21] microsoft-edge: 127.0.2651.86 -> 128.0.2739.42 (cherry picked from commit 03eb79b82a2d2d1b4aea39ceb0c6a818bb705752) --- .../networking/browsers/microsoft-edge/default.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/applications/networking/browsers/microsoft-edge/default.nix b/pkgs/applications/networking/browsers/microsoft-edge/default.nix index 0f596386ace9..6f899c924ff2 100644 --- a/pkgs/applications/networking/browsers/microsoft-edge/default.nix +++ b/pkgs/applications/networking/browsers/microsoft-edge/default.nix @@ -1,20 +1,20 @@ { beta = import ./browser.nix { channel = "beta"; - version = "128.0.2739.5"; + version = "128.0.2739.42"; revision = "1"; - hash = "sha256-y+587iVWgPk2a1P/F2iwSW1NEnAJaigL6rlVmqaIDJk="; + hash = "sha256-VcBn2WL4rdAeEa62XT/dhC2OFLsV0Q/Sp6hqgmc/e0Y="; }; dev = import ./browser.nix { channel = "dev"; - version = "128.0.2739.5"; + version = "129.0.2779.0"; revision = "1"; - hash = "sha256-zY3iGbeYlOoArNNdF1qNwdtp25P0uWJmVMEK7kJIiqQ="; + hash = "sha256-hlamsHTpBMGwOICga0k874q8+xuaZFMofFLG/EvB0NU="; }; stable = import ./browser.nix { channel = "stable"; - version = "127.0.2651.86"; + version = "128.0.2739.42"; revision = "1"; - hash = "sha256-1Dh+OoTrghn9ArvEnBZCkLnUf0m0qnkEtCoWjA8QId4="; + hash = "sha256-AwdZX2Ens2+rhHLYV0efYsXYBTs2a57HyGz2k+IDMeQ="; }; } From 06f99fb537accd088238b01287c5531d6b81feae Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Tue, 27 Aug 2024 21:57:51 +0100 Subject: [PATCH 15/21] litestream: add CVE-2024-41254 to knownVulnerabilities (cherry picked from commit 0875d0ce1c778f344cd2377a5337a45385d6ffa0) --- pkgs/development/tools/database/litestream/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/tools/database/litestream/default.nix b/pkgs/development/tools/database/litestream/default.nix index fa47959a333c..976bc77e544e 100644 --- a/pkgs/development/tools/database/litestream/default.nix +++ b/pkgs/development/tools/database/litestream/default.nix @@ -27,5 +27,6 @@ buildGoModule rec { license = licenses.asl20; homepage = "https://litestream.io/"; maintainers = with maintainers; [ fbrs ]; + knownVulnerabilities = [ "CVE-2024-41254" ]; }; } From e14a73a48fbf880e512f3b50ac3273ad408c34da Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 11 Aug 2024 01:03:25 +0000 Subject: [PATCH 16/21] php83: 8.3.9 -> 8.3.10 (cherry picked from commit f20174de43f75635cc32283b2ec95e7dabeb4a02) --- pkgs/development/interpreters/php/8.3.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/php/8.3.nix b/pkgs/development/interpreters/php/8.3.nix index 53c720a01346..c7cac06ad24c 100644 --- a/pkgs/development/interpreters/php/8.3.nix +++ b/pkgs/development/interpreters/php/8.3.nix @@ -2,8 +2,8 @@ let base = callPackage ./generic.nix (_args // { - version = "8.3.9"; - hash = "sha256-lu3G2Ct1A6ZlBUH8R3q9VFbfKN+qjJOI/54x2f4eMRI="; + version = "8.3.10"; + hash = "sha256-5YQZnDULRjQ8NwabucwgrYk8sEx0fIme8bBercDuo7A="; }); in base.withExtensions ({ all, ... }: with all; ([ From 6a74b22fb8ff9d1104ed5f85e186c8aebaf4ed42 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 30 Aug 2024 18:38:52 +0000 Subject: [PATCH 17/21] php83: 8.3.10 -> 8.3.11 (cherry picked from commit 19f1cc65bdefe395d90c28958bd1136a0bd2a20f) --- pkgs/development/interpreters/php/8.3.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/php/8.3.nix b/pkgs/development/interpreters/php/8.3.nix index c7cac06ad24c..bb314d4e854d 100644 --- a/pkgs/development/interpreters/php/8.3.nix +++ b/pkgs/development/interpreters/php/8.3.nix @@ -2,8 +2,8 @@ let base = callPackage ./generic.nix (_args // { - version = "8.3.10"; - hash = "sha256-5YQZnDULRjQ8NwabucwgrYk8sEx0fIme8bBercDuo7A="; + version = "8.3.11"; + hash = "sha256-ZkDiRVCAqJrcQdTle7BPjCv7fuxif+GZr5c7/zTX8O4="; }); in base.withExtensions ({ all, ... }: with all; ([ From 1f327da5f54ba98b8e7104b7000a42e99efac72e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 4 Aug 2024 00:39:14 +0000 Subject: [PATCH 18/21] php: 8.2.21 -> 8.2.22 (cherry picked from commit cdce031214793d766942068e3f8e5c8c65e4b094) --- pkgs/development/interpreters/php/8.2.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/php/8.2.nix b/pkgs/development/interpreters/php/8.2.nix index d3e051e96bb2..7b533cb13ea9 100644 --- a/pkgs/development/interpreters/php/8.2.nix +++ b/pkgs/development/interpreters/php/8.2.nix @@ -2,8 +2,8 @@ let base = callPackage ./generic.nix (_args // { - version = "8.2.21"; - hash = "sha256-+Ydv59TZbUGs7RmbWKH3rntmVd3JJnMTX+3tf2k5138="; + version = "8.2.22"; + hash = "sha256-Wq5ZZMYFMxhfm+koz315oTOTzFVgzt8fS5d5RMx2pYU="; }); in base.withExtensions ({ all, ... }: with all; ([ From d6c74c5ab76c8b103a2b2ebef976b778b286cf8c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 31 Aug 2024 15:57:14 +0200 Subject: [PATCH 19/21] php82: 8.2.22 -> 8.2.23 ChangeLog: https://www.php.net/ChangeLog-8.php#PHP_8_2 (cherry picked from commit e2bc8e822771fbc5b31c51703d717ba2e560777c) --- pkgs/development/interpreters/php/8.2.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/php/8.2.nix b/pkgs/development/interpreters/php/8.2.nix index 7b533cb13ea9..a119dec0ca4e 100644 --- a/pkgs/development/interpreters/php/8.2.nix +++ b/pkgs/development/interpreters/php/8.2.nix @@ -2,8 +2,8 @@ let base = callPackage ./generic.nix (_args // { - version = "8.2.22"; - hash = "sha256-Wq5ZZMYFMxhfm+koz315oTOTzFVgzt8fS5d5RMx2pYU="; + version = "8.2.23"; + hash = "sha256-98kM2no8HeAfO/t7Rp1S3snrovO4MyCDYAT5wu7K4ms="; }); in base.withExtensions ({ all, ... }: with all; ([ From 8931f18bfaf75e25009b9028657e18de334fe2c5 Mon Sep 17 00:00:00 2001 From: euxane Date: Sat, 31 Aug 2024 17:15:42 +0200 Subject: [PATCH 20/21] nixos/fcgiwrap: add security advisory links to messages --- nixos/modules/services/networking/cgit.nix | 2 +- nixos/modules/services/web-servers/fcgiwrap.nix | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/modules/services/networking/cgit.nix b/nixos/modules/services/networking/cgit.nix index 6f15e92aa2c4..c4ecc86c1235 100644 --- a/nixos/modules/services/networking/cgit.nix +++ b/nixos/modules/services/networking/cgit.nix @@ -178,7 +178,7 @@ in warnings = flatten (flip mapAttrsToList cfgs (inst: cfg: optional (cfg.user == "root") '' `services.cgit.${inst}` is configured to run as root. - This has security implications: . + This has security implications. See advisory: https://discourse.nixos.org/t/51419 It is recommended to set an unprivileged user explicitly. This default user will be set to "cgit" in NixOS 24.11. '' diff --git a/nixos/modules/services/web-servers/fcgiwrap.nix b/nixos/modules/services/web-servers/fcgiwrap.nix index 290bcfd9b65c..1c89ae261bee 100644 --- a/nixos/modules/services/web-servers/fcgiwrap.nix +++ b/nixos/modules/services/web-servers/fcgiwrap.nix @@ -11,7 +11,7 @@ let ''; securityWarning = '' The fcgiwrap module is configured with a global shared instance. - This has security implications: . + This has security implications. See advisory: https://discourse.nixos.org/t/51419 Isolated instances should instead be configured through `services.fcgiwrap.instances.*'. The global options at `services.fcgiwrap.*` will be removed in NixOS 24.11. ''; From d8295132355fc8b19871d56c4859548cf83275df Mon Sep 17 00:00:00 2001 From: Will Fancher Date: Sat, 31 Aug 2024 12:21:36 -0400 Subject: [PATCH 21/21] nixos/iso-image: Compress squashfs with zstd 19 (cherry picked from commit 49192ef7a3dd166fc176e8bf7ad74160b09d58b4) --- nixos/modules/installer/cd-dvd/iso-image.nix | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a/nixos/modules/installer/cd-dvd/iso-image.nix b/nixos/modules/installer/cd-dvd/iso-image.nix index 06949bda1cb2..e516d8ea6f8b 100644 --- a/nixos/modules/installer/cd-dvd/iso-image.nix +++ b/nixos/modules/installer/cd-dvd/iso-image.nix @@ -506,12 +506,7 @@ in }; isoImage.squashfsCompression = mkOption { - default = with pkgs.stdenv.hostPlatform; "xz -Xdict-size 100% " - + lib.optionalString isx86 "-Xbcj x86" - # Untested but should also reduce size for these platforms - + lib.optionalString isAarch "-Xbcj arm" - + lib.optionalString (isPower && is32bit && isBigEndian) "-Xbcj powerpc" - + lib.optionalString (isSparc) "-Xbcj sparc"; + default = "zstd -Xcompression-level 19"; type = lib.types.nullOr lib.types.str; description = '' Compression settings to use for the squashfs nix store.