vim_configurable: also apply the security patch

This commit is contained in:
Vladimír Čunát
2019-06-05 22:11:17 +02:00
parent b2ec3b6db2
commit e95bbcf5f8
3 changed files with 10 additions and 8 deletions

View File

@@ -13,6 +13,12 @@ rec {
hardeningDisable = [ "fortify" ];
patches = [
# Arbitrary code execution fix
# https://github.com/numirias/security/blob/cf4f74e0c6c6e4bbd6b59823aa1b85fa913e26eb/doc/2019-06-04_ace-vim-neovim.md
./0001-source-command-doesnt-check-for-the-sandbox-5357552.patch
];
postPatch =
# Use man from $PATH; escape sequences are still problematic.
''

View File

@@ -76,7 +76,9 @@ in stdenv.mkDerivation rec {
"default" = common.src; # latest release
};
patches = [ ./cflags-prune.diff ] ++ stdenv.lib.optional ftNixSupport ./ft-nix-support.patch;
patches = common.patches or []
++ [ ./cflags-prune.diff ]
++ stdenv.lib.optional ftNixSupport ./ft-nix-support.patch;
configureFlags = [
"--enable-gui=${guiSupport}"

View File

@@ -15,7 +15,7 @@ in
stdenv.mkDerivation rec {
name = "vim-${version}";
inherit (common) version src postPatch hardeningDisable enableParallelBuilding meta;
inherit (common) version src patches postPatch hardeningDisable enableParallelBuilding meta;
nativeBuildInputs = [ gettext pkgconfig ];
buildInputs = [ ncurses ]
@@ -25,12 +25,6 @@ stdenv.mkDerivation rec {
cf-private
];
patches = [
# Arbitrary code execution fix
# https://github.com/numirias/security/blob/cf4f74e0c6c6e4bbd6b59823aa1b85fa913e26eb/doc/2019-06-04_ace-vim-neovim.md
./0001-source-command-doesnt-check-for-the-sandbox-5357552.patch
];
configureFlags = [
"--enable-multibyte"
"--enable-nls"