Commit Graph

97929 Commits

Author SHA1 Message Date
Jörg Thalheim
b368cceed7 nixVersions.nix_2_30: 2.30.3 -> 2.30.4
The 2.30.4 tarball already contains the mdbook 0.5, lowdown 3.0 and
GHSA-g3g9-5vj6-r3gj fixes that were previously backported downstream,
so drop the now-redundant patches.
2026-04-07 22:33:13 +02:00
Jörg Thalheim
50eec35e48 nixComponents_git: add patches for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.

The second patch partially fixes the issue with cooperating processes being able
to communicate via abstract sockets. The fix is partial, because processes
outside the landlock domain of the sandboxed process can still connect to
a socket created by the FOD. There's no equivalent way of restricting inbound
connections. This closes the gap when there's no cooperating process on the host
(i.e. 2 separate FODs).

The patch applies landlock LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET on
kernels >= 6.12 (default on NixOS 25.11+) to deny abstract socket
connect from inside the build sandbox.
2026-04-07 20:52:46 +03:00
Jörg Thalheim
7ca89c4ab6 nixComponents_2_34: add patches for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.

The second patch partially fixes the issue with cooperating processes being able
to communicate via abstract sockets. The fix is partial, because processes
outside the landlock domain of the sandboxed process can still connect to
a socket created by the FOD. There's no equivalent way of restricting inbound
connections. This closes the gap when there's no cooperating process on the host
(i.e. 2 separate FODs).

The patch applies landlock LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET on
kernels >= 6.12 (default on NixOS 25.11+) to deny abstract socket
connect from inside the build sandbox.
2026-04-07 20:52:00 +03:00
Jörg Thalheim
be23129938 nixComponents_2_31: add patches for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.

The second patch partially fixes the issue with cooperating processes being able
to communicate via abstract sockets. The fix is partial, because processes
outside the landlock domain of the sandboxed process can still connect to
a socket created by the FOD. There's no equivalent way of restricting inbound
connections. This closes the gap when there's no cooperating process on the host
(i.e. 2 separate FODs).

The patch applies landlock LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET on
kernels >= 6.12 (default on NixOS 25.11+) to deny abstract socket
connect from inside the build sandbox.
2026-04-07 20:51:01 +03:00
Jörg Thalheim
69e8fef812 nixComponents_2_30: add patch for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.
2026-04-07 20:44:30 +03:00
Jörg Thalheim
128dad70c6 nix_2_28: add patch for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.
2026-04-07 20:44:23 +03:00
Guy Chronister
cb6caa4c64 spoof-mac: migrate to by-name 2026-04-06 18:27:57 -05:00
Guy Chronister
c27224dea8 graylogPlugins: remove unused maintainers and lib.platforms let binding 2026-04-06 09:28:43 -05:00
Morgan Jones
aa13fbfb81 openssh_gssapi: update patch to latest 2026-04-05 21:09:57 -07:00
Morgan Jones
625b040143 openssh: 10.2p1 -> 10.3p1 2026-04-05 21:09:56 -07:00
nixpkgs-ci[bot]
01f34771b4 Merge staging-next into staging 2026-04-06 00:28:40 +00:00
Sandro
3fa0b268ee nixos/collectd: allow accessing the final package with applied plugins and minimalPackage (#506074) 2026-04-06 00:14:55 +00:00
nixpkgs-ci[bot]
566141b86e Merge staging-next into staging 2026-04-05 18:11:22 +00:00
Aleksana
622163705c hdf5: fix patch url (#506859) 2026-04-05 14:06:54 +00:00
Emily Trau
9a46cd6c05 ghidra-extensions.ghidra-golanganalyzerextension: 1.2.4 -> 1.3.0 (#502791) 2026-04-05 13:19:31 +00:00
Emily Trau
a75c609d75 ghidra-extensions.kaiju: 260116 -> 260309 (#487746) 2026-04-05 13:18:44 +00:00
Guy Chronister
37bb196f05 rsyslog: migrate to by-name 2026-04-05 08:11:26 -05:00
qbisi
c7913241c2 hdf5: fix patch url 2026-04-05 12:03:45 +08:00
nixpkgs-ci[bot]
32933b021a Merge staging-next into staging 2026-04-05 00:28:24 +00:00
Sandro Jäckel
ce8b7f42d4 collectd: remove ... from inputs
This avoids that overrides accepts anything silently.
2026-04-04 21:18:49 +02:00
Sandro
d21acace02 uefitool: a72 -> a73 (#497856) 2026-04-04 18:57:01 +00:00
Martin Häcker
7128d7f1b9 lixPackageSets: add nixos-rebuild-ng 2026-04-04 17:14:52 +02:00
nixpkgs-ci[bot]
9b17ea8a06 Merge staging-next into staging 2026-04-04 12:11:47 +00:00
Vladimír Čunát
36e12b6d18 openvpn: 2.6.14 -> 2.6.19 (#489016) 2026-04-04 08:00:08 +00:00
Vladimír Čunát
0e3f0487b2 ghidra: 12.0.2 -> 12.0.4 (#502853) 2026-04-04 06:54:04 +00:00
Franz Pletz
d3e3667cdd sslscan: 2.2.1 -> 2.2.2 (#505077) 2026-04-04 06:19:07 +00:00
Franco Biasin
ff7a738c48 ghidra-bin: 12.0.2 -> 12.0.4 2026-04-03 17:23:22 -03:00
R. Ryantm
1bafbc011d bitwarden-directory-connector: 2026.2.0 -> 2026.3.0 2026-04-02 20:53:08 +00:00
Philip Taron
b32734f4ff buildEnv: use structured attributes and support <pkg>.overrideAttrs (#434815) 2026-04-02 18:17:03 +00:00
nixpkgs-ci[bot]
304c5f4649 Merge staging-next into staging 2026-04-02 18:19:01 +00:00
Ben Siraphob
8acc568b2d treewide: remove redundant name attrs and parseDrvName calls (#505899) 2026-04-02 16:52:42 +00:00
Yueh-Shun Li
ed96bfd307 buildEnv: construct with structured attributes and pass chosenOutputs directly 2026-04-02 07:31:12 -07:00
K900
7ca0184c7b Merge remote-tracking branch 'origin/master' into staging-nixos 2026-04-02 10:10:52 +03:00
Vladimír Čunát
b1e2802a93 xz: 5.8.2 -> 5.8.3 (#505802) 2026-04-02 05:07:24 +00:00
Mistyttm
f7ad9a49d3 tdarr: add missing packages to build and path 2026-04-02 14:45:18 +10:00
Ben Siraphob
59b52db759 treewide: remove redundant name attrs and parseDrvName calls 2026-04-01 21:04:20 -07:00
nixpkgs-ci[bot]
91a2bcd0df Merge staging-next into staging 2026-04-02 00:25:54 +00:00
Philip Taron
188aec52a6 Remove Profpatsch from most teams & maintainer fields (#505770) 2026-04-01 21:43:24 +00:00
Profpatsch
257f122e3d treewide: remove Profpatsch from most teams & maintainer fields 2026-04-01 14:34:59 -07:00
Philip Taron
8001332b4e prevail: rename from ebpf-verifier; unstable-2023-07-15 -> 0.2.0 (#505643) 2026-04-01 21:15:43 +00:00
Sergei Trofimovich
4c12e84d3f xz: 5.8.2 -> 5.8.3
Changes: https://github.com/tukaani-project/xz/releases/tag/v5.8.3
2026-04-01 21:18:41 +01:00
John Ericson
d01f32e3ad nix: Drop versions 2.32 and 2.33
This is per the usual Nix backporting / support policy: https://nix.dev/manual/nix/2.34/release-notes/

Nix 2.28 and 2.30 should also be dropped, but they are currently in use,
so that will be done separately.
2026-04-01 15:50:18 -04:00
Xiangyan Sun
cf18e132dc prevail: rename from ebpf-verifier; unstable-2023-07-15 -> 0.2.0 2026-04-01 02:02:39 -07:00
nixpkgs-ci[bot]
169e278f4c Merge master into staging-nixos 2026-03-31 18:21:45 +00:00
nixpkgs-ci[bot]
350adb370d Merge staging-next into staging 2026-03-31 18:20:54 +00:00
Sandro
98f82cfb5b tdarr: 2.58.02 -> 2.66.01 (#495458) 2026-03-31 15:21:59 +00:00
Marcin Serwin
ea5327286b fcitx5-array: init at 0.9.6 (#483067) 2026-03-31 15:01:53 +00:00
Antonio Yang
835922a4fb fcitx5-array: init at 0.9.6 2026-03-31 20:43:40 +08:00
nixpkgs-ci[bot]
f3a369cfbc Merge master into staging-nixos 2026-03-31 00:27:31 +00:00
nixpkgs-ci[bot]
b38fd402fb Merge staging-next into staging 2026-03-31 00:27:00 +00:00