From 4919ba60c519a8d0a886a619349bd2a4f65e48ee Mon Sep 17 00:00:00 2001 From: Ilan Joselevich Date: Wed, 14 Jun 2023 21:22:31 +0300 Subject: [PATCH 01/15] age-plugin-tpm: init at unstable-2023-05-02 (cherry picked from commit c6dfb26702fa23aaa1c289af3cf5b61ff0915c73) --- .../tools/security/age-plugin-tpm/default.nix | 41 +++++++++++++++++++ pkgs/top-level/all-packages.nix | 2 + 2 files changed, 43 insertions(+) create mode 100644 pkgs/tools/security/age-plugin-tpm/default.nix diff --git a/pkgs/tools/security/age-plugin-tpm/default.nix b/pkgs/tools/security/age-plugin-tpm/default.nix new file mode 100644 index 000000000000..d79f8805c943 --- /dev/null +++ b/pkgs/tools/security/age-plugin-tpm/default.nix @@ -0,0 +1,41 @@ +{ lib +, buildGoModule +, fetchFromGitHub +, swtpm +}: + +buildGoModule { + pname = "age-plugin-tpm"; + version = "unstable-2023-05-02"; + + src = fetchFromGitHub { + owner = "Foxboron"; + repo = "age-plugin-tpm"; + rev = "c570739b05c067087c44f651efce6890eedc0647"; + hash = "sha256-xlJtyNAYi/6vBWLsjymFLGfr30w80OplwG2xGTEB118="; + }; + + vendorHash = "sha256-S9wSxw0ZMibCOspgGt5vjzFhPL+bZncjTdIX2mkX5vE="; + + postConfigure = '' + substituteInPlace vendor/github.com/foxboron/swtpm_test/swtpm.go \ + --replace "/usr/share/swtpm/swtpm-create-user-config-files" "${swtpm}/share/swtpm/swtpm-create-user-config-files" + ''; + + nativeCheckInputs = [ + swtpm + ]; + + ldflags = [ + "-s" + "-w" + ]; + + meta = with lib; { + description = "TPM 2.0 plugin for age"; + homepage = "https://github.com/Foxboron/age-plugin-tpm"; + license = licenses.mit; + platforms = platforms.linux; + maintainers = with maintainers; [ kranzes ]; + }; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 7287d40de49d..fd41ee2b7c9f 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6477,6 +6477,8 @@ with pkgs; agebox = callPackage ../tools/security/agebox { }; + age-plugin-tpm = callPackage ../tools/security/age-plugin-tpm { }; + age-plugin-yubikey = darwin.apple_sdk_11_0.callPackage ../tools/security/age-plugin-yubikey { inherit (darwin.apple_sdk_11_0.frameworks) Foundation PCSC IOKit; }; From 8a69500c387f7a147c3441bed5169e7d33f94195 Mon Sep 17 00:00:00 2001 From: Vika Date: Wed, 12 Jul 2023 17:36:57 +0300 Subject: [PATCH 02/15] age-plugin-tpm: unstable-2023-05-02 -> 0.1.0 (cherry picked from commit 5ecef29242fbf2cae6e9eb0d0e0dbc2f25466b77) --- pkgs/tools/security/age-plugin-tpm/default.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/tools/security/age-plugin-tpm/default.nix b/pkgs/tools/security/age-plugin-tpm/default.nix index d79f8805c943..200a3e67f22d 100644 --- a/pkgs/tools/security/age-plugin-tpm/default.nix +++ b/pkgs/tools/security/age-plugin-tpm/default.nix @@ -4,18 +4,18 @@ , swtpm }: -buildGoModule { +buildGoModule rec { pname = "age-plugin-tpm"; - version = "unstable-2023-05-02"; + version = "0.1.0"; src = fetchFromGitHub { owner = "Foxboron"; repo = "age-plugin-tpm"; - rev = "c570739b05c067087c44f651efce6890eedc0647"; - hash = "sha256-xlJtyNAYi/6vBWLsjymFLGfr30w80OplwG2xGTEB118="; + rev = "v${version}"; + hash = "sha256-Gp7n2/+vgQbsm/En6PQ1to/W6lvFam4Wh3LHdCZnafc="; }; - vendorHash = "sha256-S9wSxw0ZMibCOspgGt5vjzFhPL+bZncjTdIX2mkX5vE="; + vendorHash = "sha256-oZni/n2J0N3ZxNhf+RlUWyWeOFwL4+6KUIk6DQF8YpA="; postConfigure = '' substituteInPlace vendor/github.com/foxboron/swtpm_test/swtpm.go \ From 13c184d38a0fef420cd21c28225a4a64e5d72909 Mon Sep 17 00:00:00 2001 From: Ilan Joselevich Date: Tue, 18 Jul 2023 16:02:44 +0300 Subject: [PATCH 03/15] age-plugin-tpm: add disclaimer about experimentalness (cherry picked from commit dd3fec45d4cc8803d3a1491d0d20b0b5ed6bf4ec) --- pkgs/tools/security/age-plugin-tpm/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/tools/security/age-plugin-tpm/default.nix b/pkgs/tools/security/age-plugin-tpm/default.nix index 200a3e67f22d..89291096db9b 100644 --- a/pkgs/tools/security/age-plugin-tpm/default.nix +++ b/pkgs/tools/security/age-plugin-tpm/default.nix @@ -32,7 +32,7 @@ buildGoModule rec { ]; meta = with lib; { - description = "TPM 2.0 plugin for age"; + description = "TPM 2.0 plugin for age (This software is experimental, use it at your own risk)"; homepage = "https://github.com/Foxboron/age-plugin-tpm"; license = licenses.mit; platforms = platforms.linux; From 7daba769db9e3d58234f8def2d7944cf54daddeb Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Tue, 18 Jul 2023 20:38:00 +0200 Subject: [PATCH 04/15] palemoon-bin: 32.2.1 -> 32.3.1 (cherry picked from commit cc4091be0fac90a1ef1f22b7c33104023af74bc2) --- pkgs/applications/networking/browsers/palemoon/bin.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/browsers/palemoon/bin.nix b/pkgs/applications/networking/browsers/palemoon/bin.nix index cdae7b7c552d..ece75ad87257 100644 --- a/pkgs/applications/networking/browsers/palemoon/bin.nix +++ b/pkgs/applications/networking/browsers/palemoon/bin.nix @@ -19,7 +19,7 @@ stdenv.mkDerivation rec { pname = "palemoon-bin"; - version = "32.2.1"; + version = "32.3.1"; src = fetchzip { urls = [ @@ -27,9 +27,9 @@ stdenv.mkDerivation rec { "https://rm-us.palemoon.org/release/palemoon-${version}.linux-x86_64-gtk${if withGTK3 then "3" else "2"}.tar.xz" ]; hash = if withGTK3 then - "sha256-brF9ACAG+JM7bk/JarB208f8ihI/1d90l+6e1pHmC20=" + "sha256-1JYaxxkqgg/gLdZ+uGDB5BI0NKjHO4huk0b/M9QFuII=" else - "sha256-205rhW89Jlk4ICraqndTbJ6/88+ZqhtDOIvhFTiEUz0="; + "sha256-p/Lid6Uv3XTEg+43Gke5VLILhzENHoBP6XjGVHy7wCY="; }; preferLocalBuild = true; From 321258cff56ce682c47989b12f66d29808ac1134 Mon Sep 17 00:00:00 2001 From: COLAMAroro Date: Fri, 21 Jul 2023 00:24:37 +0200 Subject: [PATCH 05/15] [Backport release-23.05] pulsar: 1.104.0 -> 1.106.0 --- .../editors/pulsar/001-patch-wrapper.patch | 18 +------------ pkgs/applications/editors/pulsar/default.nix | 8 +++--- pkgs/applications/editors/pulsar/update.mjs | 25 ++++++++++++++++--- 3 files changed, 27 insertions(+), 24 deletions(-) diff --git a/pkgs/applications/editors/pulsar/001-patch-wrapper.patch b/pkgs/applications/editors/pulsar/001-patch-wrapper.patch index 252dc5328ef2..2270ad3c8aea 100644 --- a/pkgs/applications/editors/pulsar/001-patch-wrapper.patch +++ b/pkgs/applications/editors/pulsar/001-patch-wrapper.patch @@ -1,27 +1,11 @@ --- a/resources/pulsar.sh 2023-03-16 04:11:14.000000000 +0100 +++ b/resources/pulsar.sh 2023-03-24 14:37:13.468813964 +0100 -@@ -123,22 +123,9 @@ +@@ -123,7 +123,7 @@ elif [ $OS == 'Linux' ]; then SCRIPT=$(readlink -f "$0") - PULSAR_PATH="/opt/Pulsar/pulsar" + # PULSAR_PATH is set-up via `wrapProgram` in the postFixup phase - -- #Will allow user to get context menu on cinnamon desktop enviroment -- #Add a check to make sure that DESKTOP_SESSION is set before attempting to grep it -- #expr substr is expecting 3 arguments string, index, length -- #If grep doesnt find anything is provides an empty string which causes the expr: syntax error: missing argument after '8' error - see pulsar-edit/pulsar#174 -- #Im also not quite sure why they used grep instead of simply [ "${DESKTOP_SESSION}" == "cinnamon" ] -- if [ -n "${DESKTOP_SESSION}" ] && [ "$(expr substr $(printenv | grep 'DESKTOP_SESSION=') 17 8)" == "cinnamon" ]; then -- #This local path is almost assuredly wrong as it shouldnt exist in a standard install -- ACTION_PATH="resources/linux/desktopenviroment/cinnamon/pulsar.nemo_action" -- -- #Validate the file exists before attempting to copy it -- if [ -f "${ACTION_PATH}" ]; then -- cp "${$ACTION_PATH}" "/usr/share/nemo/actions/pulsar.nemo_action" -- fi -- fi -+ # We remove the nemo integration. It is handled by the postFixup phase #Set tmpdir only if tmpdir is unset : ${TMPDIR:=/tmp} diff --git a/pkgs/applications/editors/pulsar/default.nix b/pkgs/applications/editors/pulsar/default.nix index 85b28061e45d..fe850a8f427f 100644 --- a/pkgs/applications/editors/pulsar/default.nix +++ b/pkgs/applications/editors/pulsar/default.nix @@ -23,13 +23,13 @@ let pname = "pulsar"; - version = "1.104.0"; + version = "1.106.0"; sourcesPath = { x86_64-linux.tarname = "Linux.${pname}-${version}.tar.gz"; - x86_64-linux.hash = "sha256-HEMUQVNPb6qWIXX25N79HwHo7j11MyFiBRsq9otdAL8="; + x86_64-linux.hash = "sha256-Wd0z6kHd6qZgrgZBxZQjwVC1dDqYtJ94L7aAnbuJoO8="; aarch64-linux.tarname = "ARM.Linux.${pname}-${version}-arm64.tar.gz"; - aarch64-linux.hash = "sha256-f+s54XtLLdhTFY9caKTKngJF6zLai0F7ur9v37bwuNE="; + aarch64-linux.hash = "sha256-Xadjqw8PRrq0ksif6te0gxn8xeYTCYnJcsrezfl2SYs="; }.${stdenv.hostPlatform.system} or (throw "Unsupported system: ${stdenv.hostPlatform.system}"); additionalLibs = lib.makeLibraryPath [ @@ -119,7 +119,7 @@ stdenv.mkDerivation rec { # But asar complains because the node_gyp unpacked dependency uses a prebuilt Python3 itself rm $opt/resources/app.asar.unpacked/node_modules/tree-sitter-bash/build/node_gyp_bins/python3 - ln -s ${python3}/bin/python3 $opt/resources/app.asar.unpacked/node_modules/tree-sitter-bash/build/node_gyp_bins/python3 + ln -s ${python3.interpreter} $opt/resources/app.asar.unpacked/node_modules/tree-sitter-bash/build/node_gyp_bins/python3 '' + '' # Patch the bundled node executables find $opt -name "*.node" -exec patchelf --set-rpath "${newLibpath}:$opt" {} \; diff --git a/pkgs/applications/editors/pulsar/update.mjs b/pkgs/applications/editors/pulsar/update.mjs index 2e4155d87422..4f3d2993e973 100755 --- a/pkgs/applications/editors/pulsar/update.mjs +++ b/pkgs/applications/editors/pulsar/update.mjs @@ -13,6 +13,17 @@ const constants = { targetFile: new URL("default.nix", import.meta.url).pathname, }; +async function utf16ToUtf8(blob) { + // Sometime, upstream saves the SHA256SUMS.txt file in UTF-16, which absolutely breaks node's string handling + // So we need to convert this blob to UTF-8 + + // We need to skip the first 2 bytes, which are the BOM + const arrayBuffer = await blob.slice(2).arrayBuffer(); + const buffer = Buffer.from(arrayBuffer); + const utf8String = buffer.toString('utf16le'); + return utf8String; +} + async function getLatestVersion() { const requestResult = await fetch(constants.githubUrl); if (!requestResult.ok) { @@ -37,6 +48,7 @@ async function getSha256Sum(hashFileContent, targetFile) { let sha256 = hashFileContent. split('\n'). + map(line => line.replace("\r", "")). // Side-effect of the UTF-16 conversion, if the file was created from Windows filter((line) => line.endsWith(targetFile))[0]. split(' ')[0]; @@ -47,14 +59,21 @@ async function getSha256Sums(newVersion) { // Upstream provides a file with the hashes of the files, but it's not in the SRI format, and it refers to the compressed tarball // So let's just use nix-prefetch-url to get the hashes of the decompressed tarball, and `nix hash to-sri` to convert them to SRI format const hashFileUrl = constants.sha256FileURL(newVersion); - const hashFileContent = await fetch(hashFileUrl).then((response) => response.text()); + const hashFileContent = await fetch(hashFileUrl).then((response) => response.blob()); + const headerbuffer = await hashFileContent.slice(0, 2).arrayBuffer() + const header = Buffer.from(headerbuffer).toString('hex'); + + // We must detect if it's UTF-16 or UTF-8. If it's UTF-16, we must convert it to UTF-8, otherwise just use it as-is + const hashFileContentString = header == 'fffe' ? + await utf16ToUtf8(hashFileContent) : + await hashFileContent.text(); let x86_64; let aarch64; console.log("Getting new hashes"); let promises = [ - getSha256Sum(hashFileContent, constants.x86_64FileName(newVersion)).then((hash) => { x86_64 = hash; }), - getSha256Sum(hashFileContent, constants.aarch64FileName(newVersion)).then((hash) => { aarch64 = hash; }), + getSha256Sum(hashFileContentString, constants.x86_64FileName(newVersion)).then((hash) => { x86_64 = hash; }), + getSha256Sum(hashFileContentString, constants.aarch64FileName(newVersion)).then((hash) => { aarch64 = hash; }), ]; await Promise.all(promises); return { x86_64, aarch64 }; From f2377be63e598c10b651dcf71c869c2bb761040f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fabi=C3=A1n=20Heredia=20Montiel?= Date: Thu, 20 Jul 2023 09:06:24 -0600 Subject: [PATCH 06/15] linux: 6.1.38 -> 6.1.39 (cherry picked from commit bd015ca446fe010d0c181b2c8df7a9606709350e) --- pkgs/os-specific/linux/kernel/linux-6.1.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-6.1.nix b/pkgs/os-specific/linux/kernel/linux-6.1.nix index 31345c786690..b52a2798fcc2 100644 --- a/pkgs/os-specific/linux/kernel/linux-6.1.nix +++ b/pkgs/os-specific/linux/kernel/linux-6.1.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.1.38"; + version = "6.1.39"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v6.x/linux-${version}.tar.xz"; - sha256 = "0hrdh1w9z8bgy4cxqsxfkwa01yincfw1mq1bbwm36zczc0dzk97r"; + sha256 = "1f45j3ch1ljbacjlg8q45iva9lvwys938rdg0s516mznzlifxpac"; }; } // (args.argsOverride or { })) From b9c332f487ec7df3ee2724502242ed1cf12f9251 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fabi=C3=A1n=20Heredia=20Montiel?= Date: Thu, 20 Jul 2023 09:06:27 -0600 Subject: [PATCH 07/15] linux: 6.3.12 -> 6.3.13 (cherry picked from commit 1ebfd26de10d8190ab5d964f65ba49bdd6c53a2c) --- pkgs/os-specific/linux/kernel/linux-6.3.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-6.3.nix b/pkgs/os-specific/linux/kernel/linux-6.3.nix index 4580c8054d3d..0f1a8f9866da 100644 --- a/pkgs/os-specific/linux/kernel/linux-6.3.nix +++ b/pkgs/os-specific/linux/kernel/linux-6.3.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.3.12"; + version = "6.3.13"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v6.x/linux-${version}.tar.xz"; - sha256 = "1mvcirkhqnf03cci3jiq077fs9b42a3xdk3zjkpyim3x43ydwzyb"; + sha256 = "1ywijjhf19bciip75ppzjjh7bkadd449jr64yg2j5049w9h0aipa"; }; } // (args.argsOverride or { })) From e3d60233c8729d2623ebd92ddbfea863a987a2cd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fabi=C3=A1n=20Heredia=20Montiel?= Date: Thu, 20 Jul 2023 09:06:30 -0600 Subject: [PATCH 08/15] linux: 6.4.3 -> 6.4.4 (cherry picked from commit ad22fa6bab3f0d7f183b80321fc433a72cf7b095) --- pkgs/os-specific/linux/kernel/linux-6.4.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-6.4.nix b/pkgs/os-specific/linux/kernel/linux-6.4.nix index 19aa95a1a10d..189f4da7ecae 100644 --- a/pkgs/os-specific/linux/kernel/linux-6.4.nix +++ b/pkgs/os-specific/linux/kernel/linux-6.4.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.4.3"; + version = "6.4.4"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v6.x/linux-${version}.tar.xz"; - sha256 = "18c8ikghvlr6h9jajy11dldck4h57wl301j14rxg7xhd6qlysd3i"; + sha256 = "0apzfnn04w6jda9yw5cbgj8784frvqrryb1iw5ad390lwwmlmg4w"; }; } // (args.argsOverride or { })) From 397380e4caa105456b4dfaf23d4229f2f2689821 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fabi=C3=A1n=20Heredia=20Montiel?= Date: Thu, 20 Jul 2023 09:08:24 -0600 Subject: [PATCH 09/15] =?UTF-8?q?linux/hardened/patches/6.1:=206.1.38-hard?= =?UTF-8?q?ened1=20=E2=86=92=206.1.39-hardened1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (cherry picked from commit 829b85f78056405e3a3e4eacebc9c58831e6228b) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index d61e13b25aec..0e383a93df0c 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -52,12 +52,12 @@ "6.1": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-6.1.38-hardened1.patch", - "sha256": "0sv8i26xwgw3a36yga79n36a5xbrs3ajn8wdkqn40ydbzp24i0qc", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.1.38-hardened1/linux-hardened-6.1.38-hardened1.patch" + "name": "linux-hardened-6.1.39-hardened1.patch", + "sha256": "0j4sgcs6m2mq9dn1v525bymhdhha3x8ivrpfrhqm553q4vdnmbg7", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.1.39-hardened1/linux-hardened-6.1.39-hardened1.patch" }, - "sha256": "0hrdh1w9z8bgy4cxqsxfkwa01yincfw1mq1bbwm36zczc0dzk97r", - "version": "6.1.38" + "sha256": "1f45j3ch1ljbacjlg8q45iva9lvwys938rdg0s516mznzlifxpac", + "version": "6.1.39" }, "6.3": { "patch": { From 206e50cda7abe4ff8dfcfafb8ae51c1583868fbd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fabi=C3=A1n=20Heredia=20Montiel?= Date: Thu, 20 Jul 2023 09:08:56 -0600 Subject: [PATCH 10/15] =?UTF-8?q?linux/hardened/patches/6.3:=206.3.12-hard?= =?UTF-8?q?ened1=20=E2=86=92=206.3.13-hardened1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (cherry picked from commit 455dbe71a272374870f53d699a8250ad8fdcb2b0) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 0e383a93df0c..cdb5731fd3d4 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -62,12 +62,12 @@ "6.3": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-6.3.12-hardened1.patch", - "sha256": "12dqdn2prr0mczwcy48907wpp235n87pl22gwyfilsxcj94x2wrx", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.3.12-hardened1/linux-hardened-6.3.12-hardened1.patch" + "name": "linux-hardened-6.3.13-hardened1.patch", + "sha256": "1iy95awbkrdk5529w9s07axb21l2snab4kifbzjghhz9vwzx22rp", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.3.13-hardened1/linux-hardened-6.3.13-hardened1.patch" }, - "sha256": "1mvcirkhqnf03cci3jiq077fs9b42a3xdk3zjkpyim3x43ydwzyb", - "version": "6.3.12" + "sha256": "1ywijjhf19bciip75ppzjjh7bkadd449jr64yg2j5049w9h0aipa", + "version": "6.3.13" }, "6.4": { "patch": { From 237ee6d67435e289a7b6ce705fcebee5318eeb9f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fabi=C3=A1n=20Heredia=20Montiel?= Date: Thu, 20 Jul 2023 09:09:17 -0600 Subject: [PATCH 11/15] =?UTF-8?q?linux/hardened/patches/6.4:=206.4.3-harde?= =?UTF-8?q?ned1=20=E2=86=92=206.4.4-hardened1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (cherry picked from commit 675e71c8f921a1c42a1865e44f8d7a374f5d11b2) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index cdb5731fd3d4..c1cb0cfe72e3 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -72,11 +72,11 @@ "6.4": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-6.4.3-hardened1.patch", - "sha256": "1xwy9088f8qy7algv1gad90gd6sv03diz16jvfnk2yb01k4f87wv", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.4.3-hardened1/linux-hardened-6.4.3-hardened1.patch" + "name": "linux-hardened-6.4.4-hardened1.patch", + "sha256": "0yy02hn190wvl24z1j9kjmnyxrlp6s9fhkyvqgcm8i56d7d69zhb", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.4.4-hardened1/linux-hardened-6.4.4-hardened1.patch" }, - "sha256": "18c8ikghvlr6h9jajy11dldck4h57wl301j14rxg7xhd6qlysd3i", - "version": "6.4.3" + "sha256": "0apzfnn04w6jda9yw5cbgj8784frvqrryb1iw5ad390lwwmlmg4w", + "version": "6.4.4" } } From 41bbe2dde149d1c0158580b00bf5b10ceb61c421 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Wed, 19 Jul 2023 13:11:14 +0200 Subject: [PATCH 12/15] retroarch: add support for declarative settings Add a new optional 'settings' attrset to the wrapper derivation, which gets serialized to a file and passed to RetroArch as --appendconfig= at runtime. This allows overriding settings from ~/.config/retroarch/retroarch.cfg (which initially gets created as a dump of all internal retroarch settings -- stateful and messy). (cherry picked from commit 801cc447659ee28e15b521f08e84df9c3d5f1bb6) --- .../emulators/retroarch/wrapper.nix | 18 +++++++++++++++--- pkgs/top-level/all-packages.nix | 4 ++-- 2 files changed, 17 insertions(+), 5 deletions(-) diff --git a/pkgs/applications/emulators/retroarch/wrapper.nix b/pkgs/applications/emulators/retroarch/wrapper.nix index afef0bef8a48..4698bbe5bbed 100644 --- a/pkgs/applications/emulators/retroarch/wrapper.nix +++ b/pkgs/applications/emulators/retroarch/wrapper.nix @@ -3,16 +3,28 @@ , makeWrapper , retroarch , symlinkJoin +, runCommand , cores ? [ ] +, settings ? { } }: let + settingsPath = runCommand "declarative-retroarch.cfg" + { + value = lib.concatStringsSep "\n" (lib.mapAttrsToList (n: v: "${n} = \"${v}\"") settings); + passAsFile = [ "value" ]; + } + '' + cp "$valuePath" "$out" + ''; + # All cores should be located in the same path after symlinkJoin, # but let's be safe here coresPath = lib.lists.unique (map (c: c.libretroCore) cores); - wrapperArgs = lib.strings.escapeShellArgs - (lib.lists.flatten - (map (p: [ "--add-flags" "-L ${placeholder "out" + p}" ]) coresPath)); + wrapperArgs = lib.strings.escapeShellArgs ( + (lib.lists.flatten (map (p: [ "--add-flags" "-L ${placeholder "out" + p}" ]) coresPath)) + ++ [ "--add-flags" "--appendconfig=${settingsPath}" ] + ); in symlinkJoin { name = "retroarch-with-cores-${lib.getVersion retroarch}"; diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 2a4c4a8647dc..345ef3ea92bf 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -2491,9 +2491,9 @@ with pkgs; (builtins.attrValues libretro); }; - wrapRetroArch = { retroarch }: + wrapRetroArch = { retroarch, settings ? {} }: callPackage ../applications/emulators/retroarch/wrapper.nix - { inherit retroarch; }; + { inherit retroarch settings; }; retroarch = wrapRetroArch { retroarch = retroarchBare.override { From f9f8c1c65c1f9ad4ea1da3238538272705d6836a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Wed, 19 Jul 2023 13:29:45 +0200 Subject: [PATCH 13/15] retroarch-joypad-autoconfig: init at 1.15.0 https://github.com/libretro/retroarch-joypad-autoconfig (In preparation for making joypads work out-of-the-box in RetroArch.) (cherry picked from commit 35c3c81655802b4d039754e0b2ba0248583e11b3) --- .../retroarch/retroarch-joypad-autoconfig.nix | 28 +++++++++++++++++++ pkgs/top-level/all-packages.nix | 2 ++ 2 files changed, 30 insertions(+) create mode 100644 pkgs/applications/emulators/retroarch/retroarch-joypad-autoconfig.nix diff --git a/pkgs/applications/emulators/retroarch/retroarch-joypad-autoconfig.nix b/pkgs/applications/emulators/retroarch/retroarch-joypad-autoconfig.nix new file mode 100644 index 000000000000..92ba7f20c8b3 --- /dev/null +++ b/pkgs/applications/emulators/retroarch/retroarch-joypad-autoconfig.nix @@ -0,0 +1,28 @@ +{ lib +, stdenvNoCC +, fetchFromGitHub +}: + +stdenvNoCC.mkDerivation rec { + pname = "retroarch-joypad-autoconfig"; + version = "1.15.0"; + + src = fetchFromGitHub { + owner = "libretro"; + repo = "retroarch-joypad-autoconfig"; + rev = "v${version}"; + hash = "sha256-/F2Y08uDA/pIIeLiLfOQfGVjX2pkuOqPourlx2RbZ28="; + }; + + makeFlags = [ + "PREFIX=$(out)" + ]; + + meta = with lib; { + description = "Joypad autoconfig files"; + homepage = "https://www.libretro.com/"; + license = licenses.mit; + maintainers = with maintainers; teams.libretro.members ++ [ ]; + platforms = platforms.all; + }; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 345ef3ea92bf..ac6a663cd378 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -2504,6 +2504,8 @@ with pkgs; retroarch-assets = callPackage ../applications/emulators/retroarch/retroarch-assets.nix { }; + retroarch-joypad-autoconfig = callPackage ../applications/emulators/retroarch/retroarch-joypad-autoconfig.nix { }; + libretro = recurseIntoAttrs (callPackage ../applications/emulators/retroarch/cores.nix { retroarch = retroarchBare; From e1bbe258a6dc025221b2bad99d1cd8d17bcc5708 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Wed, 19 Jul 2023 14:01:25 +0200 Subject: [PATCH 14/15] retroarch: auto-detect joypads Set the 'joypad_autoconfig_dir' setting to where autoconfig files are, instead of using the built-in default of ~/.config/retroarch/autoconfig, which is empty. Tested with my PS5 DualSense controller, which now works. (cherry picked from commit 9d793505b9e2b5d58f50e60ebfa74d7bd0665cc4) --- pkgs/top-level/all-packages.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index ac6a663cd378..3a87148ca4f9 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -2500,6 +2500,9 @@ with pkgs; withAssets = true; withCoreInfo = true; }; + settings = { + joypad_autoconfig_dir = "${retroarch-joypad-autoconfig}/share/libretro/autoconfig"; + }; }; retroarch-assets = callPackage ../applications/emulators/retroarch/retroarch-assets.nix { }; From e07a89f7f8904604c7e62bb7df2d45151d8c4737 Mon Sep 17 00:00:00 2001 From: meppu Date: Tue, 18 Jul 2023 19:09:10 +0300 Subject: [PATCH 15/15] elixir_1_15: 1.15.2 -> 1.15.4 (cherry picked from commit 853be7c712ac4a8b747ea590c54760422647c949) --- pkgs/development/interpreters/elixir/1.15.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/elixir/1.15.nix b/pkgs/development/interpreters/elixir/1.15.nix index 6dada168cc37..6c23d3d326f4 100644 --- a/pkgs/development/interpreters/elixir/1.15.nix +++ b/pkgs/development/interpreters/elixir/1.15.nix @@ -1,7 +1,7 @@ { mkDerivation }: mkDerivation { - version = "1.15.0"; - sha256 = "sha256-o5MfA0UG8vpnPCH1EYspzcN62yKZQcz5uVUY47hOL9w="; + version = "1.15.4"; + sha256 = "sha256-0DrfKQPyFX+zurCIZ6RVj9vm1lHSkJSfhiUaRpa3FFo="; # https://hexdocs.pm/elixir/1.15.0/compatibility-and-deprecations.html#compatibility-between-elixir-and-erlang-otp minimumOTPVersion = "24"; escriptPath = "lib/elixir/scripts/generate_app.escript";