From 3aa399e2f0a4ba89e8cafdfd5e80b59fad37ba07 Mon Sep 17 00:00:00 2001 From: ajs124 Date: Tue, 13 Dec 2022 17:33:47 +0100 Subject: [PATCH 1/5] openssl_3: patch CVE-2022-3996 https://www.openssl.org/news/secadv/20221213.txt (cherry picked from commit fa8c56b8c747493f18b70ba6436e162e32b311c7) --- .../libraries/openssl/3.0/CVE-2022-3996.patch | 36 +++++++++++++++++++ .../development/libraries/openssl/default.nix | 3 ++ 2 files changed, 39 insertions(+) create mode 100644 pkgs/development/libraries/openssl/3.0/CVE-2022-3996.patch diff --git a/pkgs/development/libraries/openssl/3.0/CVE-2022-3996.patch b/pkgs/development/libraries/openssl/3.0/CVE-2022-3996.patch new file mode 100644 index 000000000000..2acedda0e3a4 --- /dev/null +++ b/pkgs/development/libraries/openssl/3.0/CVE-2022-3996.patch @@ -0,0 +1,36 @@ +From 7725e7bfe6f2ce8146b6552b44e0d226be7638e7 Mon Sep 17 00:00:00 2001 +From: Pauli +Date: Fri, 11 Nov 2022 09:40:19 +1100 +Subject: [PATCH] x509: fix double locking problem + +This reverts commit 9aa4be691f5c73eb3c68606d824c104550c053f7 and removed the +redundant flag setting. + +Fixes #19643 + +Fixes LOW CVE-2022-3996 + +Reviewed-by: Dmitry Belyavskiy +Reviewed-by: Tomas Mraz +(Merged from https://github.com/openssl/openssl/pull/19652) + +(cherry picked from commit 4d0340a6d2f327700a059f0b8f954d6160f8eef5) +--- + crypto/x509/pcy_map.c | 4 ---- + 1 file changed, 4 deletions(-) + +diff --git a/crypto/x509/pcy_map.c b/crypto/x509/pcy_map.c +index 05406c6493fc..60dfd1e3203b 100644 +--- a/crypto/x509/pcy_map.c ++++ b/crypto/x509/pcy_map.c +@@ -73,10 +73,6 @@ int ossl_policy_cache_set_mapping(X509 *x, POLICY_MAPPINGS *maps) + + ret = 1; + bad_mapping: +- if (ret == -1 && CRYPTO_THREAD_write_lock(x->lock)) { +- x->ex_flags |= EXFLAG_INVALID_POLICY; +- CRYPTO_THREAD_unlock(x->lock); +- } + sk_POLICY_MAPPING_pop_free(maps, POLICY_MAPPING_free); + return ret; + diff --git a/pkgs/development/libraries/openssl/default.nix b/pkgs/development/libraries/openssl/default.nix index df52a8b2a29e..f18e08e514e4 100644 --- a/pkgs/development/libraries/openssl/default.nix +++ b/pkgs/development/libraries/openssl/default.nix @@ -213,6 +213,9 @@ in { (if stdenv.hostPlatform.isDarwin then ./use-etc-ssl-certs-darwin.patch else ./use-etc-ssl-certs.patch) + + # Remove with 3.0.8 release + ./3.0/CVE-2022-3996.patch ]; withDocs = true; From 0b822539441edad341e0181295b8f3aef3c8a121 Mon Sep 17 00:00:00 2001 From: ajs124 Date: Fri, 11 Nov 2022 23:33:15 +0100 Subject: [PATCH 2/5] nss_latest: 3.84 -> 3.85 https://github.com/nss-dev/nss/blob/master/doc/rst/releases/nss_3_85.rst (cherry picked from commit 9930d3512987cd2c76b9937dc50acaec5335a7d9) Firefox 108 needs nss >= 3.85 --- ...ity_load.patch => 85_security_load_3.85+.patch} | 14 +++++++------- pkgs/development/libraries/nss/generic.nix | 6 +++--- pkgs/development/libraries/nss/latest.nix | 4 ++-- 3 files changed, 12 insertions(+), 12 deletions(-) rename pkgs/development/libraries/nss/{85_security_load.patch => 85_security_load_3.85+.patch} (91%) diff --git a/pkgs/development/libraries/nss/85_security_load.patch b/pkgs/development/libraries/nss/85_security_load_3.85+.patch similarity index 91% rename from pkgs/development/libraries/nss/85_security_load.patch rename to pkgs/development/libraries/nss/85_security_load_3.85+.patch index 2b2cce465ba7..bc3f48e66744 100644 --- a/pkgs/development/libraries/nss/85_security_load.patch +++ b/pkgs/development/libraries/nss/85_security_load_3.85+.patch @@ -12,13 +12,13 @@ index ad8f3b84e..74676d039 100644 if (!lib) { PR_fprintf(PR_STDERR, "loading softokn3 failed"); diff --git nss/lib/pk11wrap/pk11load.c nss/lib/pk11wrap/pk11load.c -index 9e7a0a546..a0a23a1a4 100644 +index 119c8c512..720d39ccc 100644 --- nss/lib/pk11wrap/pk11load.c +++ nss/lib/pk11wrap/pk11load.c -@@ -466,6 +466,15 @@ secmod_LoadPKCS11Module(SECMODModule *mod, SECMODModule **oldModule) - * unload the library if anything goes wrong from here on out... - */ +@@ -486,6 +486,15 @@ secmod_LoadPKCS11Module(SECMODModule *mod, SECMODModule **oldModule) + #else library = PR_LoadLibrary(mod->dllName); + #endif // defined(_WIN32) +#ifndef NSS_STATIC_SOFTOKEN + if ((library == NULL) && + !rindex(mod->dllName, PR_GetDirectorySeparator())) { @@ -32,7 +32,7 @@ index 9e7a0a546..a0a23a1a4 100644 if (library == NULL) { diff --git nss/lib/util/secload.c nss/lib/util/secload.c -index 12efd2f75..8b74478f6 100644 +index 1cebae4e2..9194bb761 100644 --- nss/lib/util/secload.c +++ nss/lib/util/secload.c @@ -70,9 +70,14 @@ loader_LoadLibInReferenceDir(const char* referencePath, const char* name) @@ -66,8 +66,8 @@ index 12efd2f75..8b74478f6 100644 @@ -89,6 +99,10 @@ loader_LoadLibInReferenceDir(const char* referencePath, const char* name) | PR_LD_ALT_SEARCH_PATH #endif - ); -+ if (! dlh) { + ); ++ if (!dlh) { + strcpy(fullName + referencePathSize, name); + dlh = PR_LoadLibraryWithFlags(libSpec, PR_LD_NOW | PR_LD_LOCAL); + } diff --git a/pkgs/development/libraries/nss/generic.nix b/pkgs/development/libraries/nss/generic.nix index bcc290dd2076..acafc21f0d26 100644 --- a/pkgs/development/libraries/nss/generic.nix +++ b/pkgs/development/libraries/nss/generic.nix @@ -40,10 +40,10 @@ stdenv.mkDerivation rec { patches = [ # Based on http://patch-tracker.debian.org/patch/series/dl/nss/2:3.15.4-1/85_security_load.patch - (if (lib.versionOlder version "3.77") then - ./85_security_load.patch - else + (if (lib.versionOlder version "3.84") then ./85_security_load_3.77+.patch + else + ./85_security_load_3.85+.patch ) ./fix-cross-compilation.patch ]; diff --git a/pkgs/development/libraries/nss/latest.nix b/pkgs/development/libraries/nss/latest.nix index 09eaa64e600a..56d6c0e47103 100644 --- a/pkgs/development/libraries/nss/latest.nix +++ b/pkgs/development/libraries/nss/latest.nix @@ -5,6 +5,6 @@ # Example: nix-shell ./maintainers/scripts/update.nix --argstr package cacert import ./generic.nix { - version = "3.84"; - hash = "sha256-mjh//jUP8U8AHZQ/lswMBkiRVR1x4al6Xdv/5/EgeiU="; + version = "3.85"; + hash = "sha256-r9nWRRCxFU3rvWyrNXHp/2SjNziY4DSD5Mhc2toT0pc="; } From 6cb8f6312dc2a7d8739c9a525f747735c3fca5ef Mon Sep 17 00:00:00 2001 From: ajs124 Date: Fri, 9 Dec 2022 00:21:57 +0100 Subject: [PATCH 3/5] nss_latest: 3.85 -> 3.86 https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/NqCkaX216zY/m/QAUPTaBWCgAJ (cherry picked from commit c13ed541dbd016b9132de3ba55f88b5b1b626d3b) --- pkgs/development/libraries/nss/latest.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/nss/latest.nix b/pkgs/development/libraries/nss/latest.nix index 56d6c0e47103..72c86bf41a81 100644 --- a/pkgs/development/libraries/nss/latest.nix +++ b/pkgs/development/libraries/nss/latest.nix @@ -5,6 +5,6 @@ # Example: nix-shell ./maintainers/scripts/update.nix --argstr package cacert import ./generic.nix { - version = "3.85"; - hash = "sha256-r9nWRRCxFU3rvWyrNXHp/2SjNziY4DSD5Mhc2toT0pc="; + version = "3.86"; + hash = "sha256-PzhfxoZHa7uoEQNfpoIbVCR11VdHsYwgwiHU1mVzuXU="; } From 730f38f455d13e0622fae9758cd8016ddd9f15d8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Thu, 15 Dec 2022 11:06:49 +0100 Subject: [PATCH 4/5] rustPackages_1_64: backport from nixpkgs 22.11 I just copied the parts of nix expressions from 22.11. --- pkgs/development/compilers/rust/1_64.nix | 64 ++++++++++++++++++++++++ pkgs/top-level/all-packages.nix | 5 ++ 2 files changed, 69 insertions(+) create mode 100644 pkgs/development/compilers/rust/1_64.nix diff --git a/pkgs/development/compilers/rust/1_64.nix b/pkgs/development/compilers/rust/1_64.nix new file mode 100644 index 000000000000..f93123fcd70a --- /dev/null +++ b/pkgs/development/compilers/rust/1_64.nix @@ -0,0 +1,64 @@ +# New rust versions should first go to staging. +# Things to check after updating: +# 1. Rustc should produce rust binaries on x86_64-linux, aarch64-linux and x86_64-darwin: +# i.e. nix-shell -p fd or @GrahamcOfBorg build fd on github +# This testing can be also done by other volunteers as part of the pull +# request review, in case platforms cannot be covered. +# 2. The LLVM version used for building should match with rust upstream. +# Check the version number in the src/llvm-project git submodule in: +# https://github.com/rust-lang/rust/blob//.gitmodules +# 3. Firefox and Thunderbird should still build on x86_64-linux. + +{ stdenv, lib +, buildPackages +, newScope, callPackage +, CoreFoundation, Security, SystemConfiguration +, pkgsBuildTarget, pkgsBuildBuild, pkgsBuildHost +, makeRustPlatform +, llvmPackages_11 +, llvmPackages_14, llvm_14 +} @ args: + +import ./default.nix { + rustcVersion = "1.64.0"; + rustcSha256 = "sha256-s82fSB4aKQG/bzgI0wxpzE6oDZPEzE4u1SJYsYA4EgU="; + + llvmSharedForBuild = pkgsBuildBuild.llvmPackages_14.libllvm.override { enableSharedLibraries = true; }; + llvmSharedForHost = pkgsBuildHost.llvmPackages_14.libllvm.override { enableSharedLibraries = true; }; + llvmSharedForTarget = pkgsBuildTarget.llvmPackages_14.libllvm.override { enableSharedLibraries = true; }; + + llvmBootstrapForDarwin = llvmPackages_11; + + # For use at runtime + llvmShared = llvm_14.override { enableSharedLibraries = true; }; + + # Expose llvmPackages used for rustc from rustc via passthru for LTO in Firefox + llvmPackages = llvmPackages_14; + + # Note: the version MUST be one version prior to the version we're + # building + bootstrapVersion = "1.63.0"; + + # fetch hashes by running `print-hashes.sh ${bootstrapVersion}` + bootstrapHashes = { + i686-unknown-linux-gnu = "6ac6ca18f119e099749d67c6dc25ce3f70542b43cc05062d5138fc1052e44c54"; + x86_64-unknown-linux-gnu = "536bcf16807a4ff49b7b29af6e573a2f1821055bfad72c275c60e56edc693984"; + x86_64-unknown-linux-musl = "4516f1fa2a0d9ec9176cc734e5faaa0a3d439bd49f75553a484b6c3c6d7905ab"; + arm-unknown-linux-gnueabihf = "8847d8482e1d5ec962e092a63c95618dc7e17a079a9bf58bec1da39cac0ba4ce"; + armv7-unknown-linux-gnueabihf = "d9227bf6d93f49889c698d35adc7ab3e042988740b9d9d9c81fb54fc0f854474"; + aarch64-unknown-linux-gnu = "26745b57500da293a8147122a5998926301350a610c164f053107cbe026d3a51"; + aarch64-unknown-linux-musl = "8fee65f2bd7e010259763939cbef8ed0794773ec8959c5ef90273cf39dcba180"; + x86_64-apple-darwin = "37f76a45b8616e764c2663850758ce822c730e96af60168a46b818f528c1467d"; + aarch64-apple-darwin = "25c3f43459da9b8683292999c3522d88980b0ca3244fe830f5a87a8092aac5a6"; + powerpc64le-unknown-linux-gnu = "781662048caa48b78540c2fb22f0aa7c06d6d8e81aede0f6ef900c11428056cf"; + riscv64gc-unknown-linux-gnu = "a7f398b45229c5cca833f75421c32897174e365fbbdf78e19b87612736c918aa"; + mips64el-unknown-linux-gnuabi64 = "19f04c576c9d6b171acba65cfe44edcbcf6134a75a853d2f1538fdb2128ec654"; + }; + + selectRustPackage = pkgs: pkgs.rust_1_64; + + rustcPatches = [ + ]; +} + +(builtins.removeAttrs args [ "fetchpatch" "pkgsBuildHost" "llvmPackages_11" "llvmPackages_14" "llvm_14"]) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 30648db1c17c..ce48057c604e 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -13783,6 +13783,10 @@ with pkgs; inherit (darwin.apple_sdk.frameworks) CoreFoundation Security SystemConfiguration; llvm_14 = llvmPackages_14.libllvm; }; + rust_1_64 = callPackage ../development/compilers/rust/1_64.nix { + inherit (darwin.apple_sdk.frameworks) CoreFoundation Security SystemConfiguration; + llvm_14 = llvmPackages_14.libllvm; + }; rust = rust_1_60; mrustc = callPackage ../development/compilers/mrustc { }; @@ -13791,6 +13795,7 @@ with pkgs; rustPackages_1_60 = rust_1_60.packages.stable; rustPackages_1_61 = rust_1_61.packages.stable; + rustPackages_1_64 = rust_1_64.packages.stable; rustPackages = rustPackages_1_60; inherit (rustPackages) cargo clippy rustc rustPlatform; From 8e27fbf2787296aee23a8227d92ecf4b7a18bd43 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Thu, 15 Dec 2022 11:08:18 +0100 Subject: [PATCH 5/5] firefox: fix build by using newer rustc FF 108 needs at least 1.63 https://hydra.nixos.org/build/201985872/nixlog/1/tail --- pkgs/applications/networking/browsers/firefox/common.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/applications/networking/browsers/firefox/common.nix b/pkgs/applications/networking/browsers/firefox/common.nix index f65fda88d7e7..6a259746fcd9 100644 --- a/pkgs/applications/networking/browsers/firefox/common.nix +++ b/pkgs/applications/networking/browsers/firefox/common.nix @@ -35,6 +35,7 @@ , python3 , runCommand , rustPackages_1_61 +, rustPackages_1_64 , rust-cbindgen , unzip , which @@ -142,7 +143,8 @@ assert pipewireSupport -> !waylandSupport || !webrtcSupport -> throw "${pname}: let flag = tf: x: [(if tf then "--enable-${x}" else "--disable-${x}")]; - inherit (rustPackages_1_61) cargo rustc rustPlatform; + inherit (if lib.versionAtLeast version "108" then rustPackages_1_64 else rustPackages_1_61) + cargo rustc rustPlatform; # Target the LLVM version that rustc is built with for LTO. llvmPackages0 = rustc.llvmPackages;