mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-28 02:40:50 +00:00
vim_configurable: also apply the security patch
This commit is contained in:
@@ -13,6 +13,12 @@ rec {
|
||||
|
||||
hardeningDisable = [ "fortify" ];
|
||||
|
||||
patches = [
|
||||
# Arbitrary code execution fix
|
||||
# https://github.com/numirias/security/blob/cf4f74e0c6c6e4bbd6b59823aa1b85fa913e26eb/doc/2019-06-04_ace-vim-neovim.md
|
||||
./0001-source-command-doesnt-check-for-the-sandbox-5357552.patch
|
||||
];
|
||||
|
||||
postPatch =
|
||||
# Use man from $PATH; escape sequences are still problematic.
|
||||
''
|
||||
|
||||
@@ -76,7 +76,9 @@ in stdenv.mkDerivation rec {
|
||||
"default" = common.src; # latest release
|
||||
};
|
||||
|
||||
patches = [ ./cflags-prune.diff ] ++ stdenv.lib.optional ftNixSupport ./ft-nix-support.patch;
|
||||
patches = common.patches or []
|
||||
++ [ ./cflags-prune.diff ]
|
||||
++ stdenv.lib.optional ftNixSupport ./ft-nix-support.patch;
|
||||
|
||||
configureFlags = [
|
||||
"--enable-gui=${guiSupport}"
|
||||
|
||||
@@ -15,7 +15,7 @@ in
|
||||
stdenv.mkDerivation rec {
|
||||
name = "vim-${version}";
|
||||
|
||||
inherit (common) version src postPatch hardeningDisable enableParallelBuilding meta;
|
||||
inherit (common) version src patches postPatch hardeningDisable enableParallelBuilding meta;
|
||||
|
||||
nativeBuildInputs = [ gettext pkgconfig ];
|
||||
buildInputs = [ ncurses ]
|
||||
@@ -25,12 +25,6 @@ stdenv.mkDerivation rec {
|
||||
cf-private
|
||||
];
|
||||
|
||||
patches = [
|
||||
# Arbitrary code execution fix
|
||||
# https://github.com/numirias/security/blob/cf4f74e0c6c6e4bbd6b59823aa1b85fa913e26eb/doc/2019-06-04_ace-vim-neovim.md
|
||||
./0001-source-command-doesnt-check-for-the-sandbox-5357552.patch
|
||||
];
|
||||
|
||||
configureFlags = [
|
||||
"--enable-multibyte"
|
||||
"--enable-nls"
|
||||
|
||||
Reference in New Issue
Block a user