Compare commits

..

10 Commits

Author SHA1 Message Date
nixpkgs-ci[bot]
d51c455eef [Backport release-26.05] blackfire: 2026.9.0 -> 2026.9.1 (#567854) 2026-09-29 07:39:21 +00:00
nixpkgs-ci[bot]
d1e40b6809 [Backport release-26.05] phpExtensions.blackfire: 2026.9.0 -> 2026.9.2 (#567851) 2026-09-29 07:39:20 +00:00
Ulrik Strid
b04bfda2b2 [Backport release-26.05] microsoft-edge, msedgedriver: refactor, add darwin support (#568025) 2026-09-29 07:02:20 +00:00
Yohann Boniface
53cdf9f164 [Backport release-26.05] rustormy: init at 0.5.2 (#567716) 2026-09-29 06:17:04 +00:00
Rafael Ieda
9f09524e2c microsoft-edge: refactor, add darwin support
(cherry picked from commit 143592c313)
2026-09-28 18:47:40 -03:00
Rafael Ieda
964766c315 msedgedriver: refactor, add darwin support
(cherry picked from commit 670ddeed25)
2026-09-28 17:58:45 -03:00
R. Ryantm
2885d378fe blackfire: 2026.9.0 -> 2026.9.1
(cherry picked from commit 833acbe176)
2026-09-28 12:18:00 +00:00
R. Ryantm
f3baa3f684 phpExtensions.blackfire: 2026.9.0 -> 2026.9.2
(cherry picked from commit fb9f61bf1d)
2026-09-28 12:17:36 +00:00
Jose Garcia
f7fd04296d rustormy: init at 0.5.2
(cherry picked from commit 44c43afccc)
2026-09-28 01:42:18 +00:00
Jose Garcia
2aba6ffa6a maintainers: add joseg313
(cherry picked from commit e08a226805)
2026-09-28 01:42:17 +00:00
65 changed files with 1324 additions and 2374 deletions

View File

@@ -13361,6 +13361,12 @@
github = "jooooscha";
githubId = 57965027;
};
joseg313 = {
name = "Jose Garcia";
email = "501jag3@gmail.com";
github = "joseg313";
githubId = 215610619;
};
josephschmitt = {
name = "Joseph Schmitt";
email = "dev@joe.sh";

View File

@@ -244,7 +244,21 @@ in
options.systemd = {
package = mkPackageOption pkgs "systemd" { };
package = mkPackageOption pkgs "systemd" { } // {
apply =
pkg:
pkg.overrideAttrs (prevAttrs: {
patches = prevAttrs.patches or [ ] ++ [
# Remove this with v261.5; it fixes an issue with switch-to-configuration
# https://github.com/NixOS/nixpkgs/pull/558350#issuecomment-5740583354
(pkgs.fetchpatch {
name = "postpone-d-bus-queue-dispatch.patch";
url = "https://github.com/systemd/systemd/commit/266b3e50218e2b27cd67d2371c165bf53ad3bf00.patch";
hash = "sha256-dEEzZUqicnmgDuXVBV1y0BxzgKbb6Q47Dmxj+O71bFE=";
})
];
});
};
enableStrictShellChecks = mkEnableOption "" // {
description = ''

View File

@@ -29,7 +29,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "at-spi2-core";
version = "2.60.7";
version = "2.60.6";
outputs = [
"out"
@@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/at-spi2-core/${lib.versions.majorMinor finalAttrs.version}/at-spi2-core-${finalAttrs.version}.tar.xz";
hash = "sha256-kok8gYg1UmS6Y5yj0nlDQ3sm7waZceqfqksg3kBZW5o=";
hash = "sha256-qJtkqLIXqAQr3w41y/q2Kc7uNWQNunXfV4r96ap4nVc=";
};
nativeBuildInputs = [

View File

@@ -11,7 +11,7 @@
stdenv.mkDerivation rec {
pname = "blackfire";
version = "2026.9.0";
version = "2026.9.1";
src =
passthru.sources.${stdenv.hostPlatform.system}
@@ -60,19 +60,19 @@ stdenv.mkDerivation rec {
sources = {
"x86_64-linux" = fetchurl {
url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_amd64.deb";
hash = "sha256-mm93TmfrSMP5+hVtWQ2CkUqmDqYraL4H7NVLXZ7xDqs=";
hash = "sha256-ElktV5SSt4zhvVnQS8qljbPDGH0qM85i7WztyoDyvcM=";
};
"i686-linux" = fetchurl {
url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_i386.deb";
hash = "sha256-nz0YYTdH0Rcs4f0aJu8Bkg/NwLNxiFwSq8kkRoa+VEA=";
hash = "sha256-vl6PvMsqc3GyIsrYl1WpV1psxuuszSfN1TdRH5FW9qE=";
};
"aarch64-linux" = fetchurl {
url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_arm64.deb";
hash = "sha256-RTTNU3c9gJQRh8vjrCnhPh/mKWKs9jHUd3gund3UZWM=";
hash = "sha256-fjcp+gOHna7grTl972jslY8hYdjWhfxbA4ncHfCAkGw=";
};
"aarch64-darwin" = fetchurl {
url = "https://packages.blackfire.io/blackfire/${version}/blackfire-darwin_arm64.pkg.tar.gz";
hash = "sha256-xa9lqDOVS0uPLeAyQ3fvkp3SNN8Hhv66gitjgKk/p6M=";
hash = "sha256-xNn78U4jdABzWrSKMSSZXE5tuf/SRK8OwdhldKBBKk0=";
};
"x86_64-darwin" = fetchurl {
url = "https://packages.blackfire.io/blackfire/${version}/blackfire-darwin_amd64.pkg.tar.gz";

View File

@@ -16,47 +16,47 @@ let
phpMajor = lib.versions.majorMinor php.version;
inherit (stdenv.hostPlatform) system;
version = "2026.9.0";
version = "2026.9.2";
hashes = {
"x86_64-linux" = {
system = "amd64";
hash = {
"8.1" = "sha256-0AAgiBdiIQOxSSttD2ERzSTqPM1rLwlQFHZ6ARRSgmI=";
"8.2" = "sha256-usSNoM1XeVWKuHLlSMvONAucVa1ZEAb3+I66oOnzGB0=";
"8.3" = "sha256-65GoEhgFsQbQleSVuRnHPSZAiCfEUmyVWWhnybnrgaA=";
"8.4" = "sha256-0if1fQa7b41TjC3d1ck65cJP7lKdoL670V9t+PLL+qk=";
"8.5" = "sha256-3k5jQ+vbxLGp78MRzjiw7uP+tCcEs5gAYM2MEoiYdtk=";
"8.1" = "sha256-Rh26CehFWvZbri+wE+NOit6Mc6LB55IVZ0FT63/GBew=";
"8.2" = "sha256-HoaC8XAGxqPvQPkpsqTjBxd6Z8FnB/cjk5uC9ogNMAs=";
"8.3" = "sha256-nRwvQYootheK0qEWbEJoC82butcJRFz65zhxey56/Bk=";
"8.4" = "sha256-rqo9U0S2Cuhy+CiILeXo2DW22y9xb/7QB3l7Et0IbTM=";
"8.5" = "sha256-hf/pe+Go8qhHxqAodbLyn60t1FJGZtQ965pMFCJ4t0M=";
};
};
"i686-linux" = {
system = "i386";
hash = {
"8.1" = "sha256-fmmbY4ecnE05XNxGKq11HcYhs9z7SggLx9iXICHE6DQ=";
"8.2" = "sha256-9WP+FpULl0PQJ+0qxxZfm5xJS/A6N137yGk9gv4cYvI=";
"8.3" = "sha256-Io2gGAhXLAVdHoaKwKvJWA1N71IJAKeJkudLs8DZUl8=";
"8.4" = "sha256-JoGiB8ew3D/qSi7Pg/q67mXLsUy4UDVsazgxgb5BJTM=";
"8.5" = "sha256-bSfbhFHV8Zs4cpOfDnKItNlF9++0opUtosTpnosacdU=";
"8.1" = "sha256-BgOAsLqMqsyXfEIgx/Buaz4jjU1TN8lxVPTSvQzCn7M=";
"8.2" = "sha256-D1FiwfYF8tRM1uMEWPauY+SzQNyL9kszVb5pD5vOBwA=";
"8.3" = "sha256-SZ9KFC+ISp5LgElLeQTOInlgoSqWV9+oRdC6yJ5P3WA=";
"8.4" = "sha256-x4ZTJs1VLipdEEAhjb+pG4Q25a2czBkEPtucHGdZINw=";
"8.5" = "sha256-zzSZsGu2POr97O5fwKRCwJqs6+lO1HqfG6o5HKL4zVQ=";
};
};
"aarch64-linux" = {
system = "arm64";
hash = {
"8.1" = "sha256-7/2Q9Kx3ZEpI0Inj88CfTDzr0sjVpws3DH8KTP26PR0=";
"8.2" = "sha256-suFGyE94wY4xHfPk77OXzkqU+Ulb+f42drDZY/M9ZNs=";
"8.3" = "sha256-z5IfXX7DElerdRTnq3R95t8IvG0Hl9EKXBw1QbRlDkY=";
"8.4" = "sha256-ceTjQ6gtiWJEte5WuVuyc+eTEb3khobYoCWNGP+Vkeo=";
"8.5" = "sha256-1jX564B/tLBgb7jN6MB5DfpRgYy0xxmtAaAv768FQqo=";
"8.1" = "sha256-QGe/XJt2N7UFpW0ahKo+hCZO7X80L31hAp0D6oreGt4=";
"8.2" = "sha256-QyhbXXlhBdoNUYJcPOt4w4sA45ELtY4IERD8GUS3I4c=";
"8.3" = "sha256-+l9RGCmhQsdtqntfUk22d1zVIcAxuLw4mHpe4WcfGr8=";
"8.4" = "sha256-hUI/z+PNAj7gl9UCGes/TnhV6zK82LMfhEfi72gsy7c=";
"8.5" = "sha256-MaqGbXacLeDUPlskuETtzv1cXZTO0/EF0IW49N6eZMY=";
};
};
"aarch64-darwin" = {
system = "arm64";
hash = {
"8.1" = "sha256-JQZKX8qChvBS3S8cqtxmooZMsFlFqfffnQbNldYNR+M=";
"8.2" = "sha256-nGQdweskEw9tiK51IGcu7cGKJJwtmNBL9fZLMUCuiB8=";
"8.3" = "sha256-sHQOg6QC+Mm5KwQVwKmeOVR3fUkN2NH9utHs667Oipw=";
"8.4" = "sha256-Btrz+U9ejW/Jl1cWBRt5XGV1IzjxK+FJaQwXIgYR/NI=";
"8.5" = "sha256-zSQeBioU/3c7HrqEz+9z8vam3EHkR0KbC80/mIuTAFE=";
"8.1" = "sha256-oG7Doie9hoieBM649S1XlagBaYAWAjJu2PrzYSDLKL0=";
"8.2" = "sha256-MJi0cve8+eItBcC6UkuxYTzclB3OMC+Hhlmd++xD1MU=";
"8.3" = "sha256-3oJtMuVKGUgpduMp7snSdGE/BH764EA7yz+N70+qFNg=";
"8.4" = "sha256-0HOCBB9dgU9Vq5/F0iKCzumjwT81qxHElPsLGKgVhr0=";
"8.5" = "sha256-Hi9bC/CigkA3VWFTqfE7JzBcGGJAhUwnmMndHgbFIW4=";
};
};
"x86_64-darwin" = {

View File

@@ -2,7 +2,6 @@
lib,
stdenv,
fetchurl,
fetchpatch,
pkg-config,
removeReferencesTo,
zlib,
@@ -43,29 +42,6 @@ stdenv.mkDerivation (finalAttrs: {
"man"
];
patches = [
(fetchpatch {
name = "CVE-2026-87875.patch";
url = "https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4.patch";
excludes = [ "CHANGES.md" ];
hash = "sha256-WHw/UWyUuYEBC6TRADpw+BBCaCts9Nd0jS9qsQHTBMo=";
})
(fetchpatch {
url = "https://github.com/OpenPrinting/cups/commit/76b515154ce6264dae6d7cc44915d85e0e5fa0f4.patch";
hash = "sha256-KtwcB4KrFmsLbtAz6u593qxbnozW2Vb/I9yX36gZTd0=";
})
(fetchpatch {
url = "https://github.com/OpenPrinting/cups/commit/526adb34fe87f7f0cf5f63ae26751c1afa36a5d6.patch";
hash = "sha256-Pg2xbCXalbvDvv5iI19MrjpOTW03XLKfEHN+lhImG1U=";
})
(fetchpatch {
name = "CVE-2026-87876.patch";
url = "https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8.patch";
excludes = [ "CHANGES.md" ];
hash = "sha256-gohcRO93JE2ldF5uPbR0re9NYxb13AeVn4b/qYsQGaE=";
})
];
postPatch = ''
substituteInPlace cups/testfile.c \
--replace 'cupsFileFind("cat", "/bin' 'cupsFileFind("cat", "${coreutils}/bin'

View File

@@ -18,18 +18,18 @@
# files.
let
tagFor = version: "R_${lib.replaceStrings [ "." ] [ "_" ] version}";
version = "2.8.4";
tag = "R_${lib.replaceStrings [ "." ] [ "_" ] version}";
in
stdenv.mkDerivation (finalAttrs: {
pname = "expat";
version = "2.8.5";
inherit version;
src = fetchurl {
url =
with finalAttrs;
"https://github.com/libexpat/libexpat/releases/download/${tagFor version}/${pname}-${version}.tar.xz";
hash = "sha256-HnJ7iTPsUad6mp2a/PjmiLzkXZB8E+Nqtzk/425wMYI=";
"https://github.com/libexpat/libexpat/releases/download/${tag}/${pname}-${version}.tar.xz";
hash = "sha256-ZWrhzI2jtOpRO7TiVPM+YkOTgITA7GI52oczdrCZhac=";
};
strictDeps = true;
@@ -73,7 +73,7 @@ stdenv.mkDerivation (finalAttrs: {
};
meta = {
changelog = "https://github.com/libexpat/libexpat/blob/${tagFor finalAttrs.version}/expat/Changes";
changelog = "https://github.com/libexpat/libexpat/blob/${tag}/expat/Changes";
homepage = "https://libexpat.github.io/";
description = "Stream-oriented XML parser library written in C";
mainProgram = "xmlwf";

View File

@@ -9,18 +9,11 @@
fixDarwinDylibNames,
python3,
testers,
# for passthru.tests
pango,
libass,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "fribidi";
version = "1.0.17";
__structuredAttrs = true;
strictDeps = true;
version = "1.0.16";
outputs = [
"out"
@@ -33,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: {
url =
with finalAttrs;
"https://github.com/fribidi/fribidi/releases/download/v${version}/${pname}-${version}.tar.xz";
sha256 = "sha256-aUnc3ifUHOutH9dB/K/DbVWhAg0thy1KbrORTKq7raI=";
sha256 = "sha256-GxzeWyNdQEeekb4vDoijCeMhTIq0cOyKJ0TYKlqeoFw=";
};
postPatch = ''
@@ -47,17 +40,8 @@ stdenv.mkDerivation (finalAttrs: {
]
++ lib.optional stdenv.hostPlatform.isDarwin fixDarwinDylibNames;
# necessary to compile helper which runs during build to generate tables
# see gen.tab/meson.build for details
depsBuildBuild = [ buildPackages.stdenv.cc ];
mesonFlags = lib.mapAttrsToList lib.mesonBool {
tests = finalAttrs.finalPackage.doCheck;
docs = true;
bin = true;
deprecated = true;
};
doCheck = true;
nativeCheckInputs = [ python3 ];
@@ -65,18 +49,14 @@ stdenv.mkDerivation (finalAttrs: {
pkg-config = testers.hasPkgConfigModules {
package = finalAttrs.finalPackage;
};
inherit pango libass;
};
meta = {
homepage = "https://github.com/fribidi/fribidi";
changelog = "https://github.com/fribidi/fribidi/releases/tag/v${finalAttrs.version}";
description = "GNU implementation of the Unicode Bidirectional Algorithm (bidi)";
mainProgram = "fribidi";
license = lib.licenses.lgpl21;
platforms = lib.platforms.unix;
pkgConfigModules = [ "fribidi" ];
maintainers = with lib.maintainers; [ tmarkus ];
identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "gnu" finalAttrs.version;
};
})

View File

@@ -28,7 +28,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "gdk-pixbuf";
version = "2.44.8";
version = "2.44.7";
outputs = [
"out"
@@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/gdk-pixbuf/${lib.versions.majorMinor finalAttrs.version}/gdk-pixbuf-${finalAttrs.version}.tar.xz";
hash = "sha256-kZ9SlRKWGhLoHNS0tGakjDkzRp5/mjEMZRPNT7JSujw=";
hash = "sha256-Fy+A42JuwxUgqXBADxo2lOBHGPbCzSiF91JQ+1pplaQ=";
};
patches = [

View File

@@ -67,13 +67,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "ghostscript${lib.optionalString x11Support "-with-X"}";
version = "10.08.0";
version = "10.07.1";
src = fetchurl {
url = "https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/download/gs${
lib.replaceStrings [ "." ] [ "" ] finalAttrs.version
}/ghostscript-${finalAttrs.version}.tar.xz";
hash = "sha256-wgSSvI67lsh/ouUqCSbhzajN6V1mFF4BiscT/tXaOM8=";
hash = "sha256-HNt2bejbjx5YnIF/CcWFXqX2XfyFQORlpprBTBhBYCU=";
};
patches = [

View File

@@ -85,11 +85,6 @@ let
AuthenSASL
DigestHMAC
];
gitJumpBinPath = lib.makeBinPath [
"$out"
perlPackages.perl
coreutils
];
in
stdenv.mkDerivation (finalAttrs: {
@@ -212,7 +207,6 @@ stdenv.mkDerivation (finalAttrs: {
(if stdenv.hostPlatform.isFreeBSD then libiconvReal else libiconv)
bash
]
++ lib.optionals pythonSupport [ python3 ]
++ lib.optionals perlSupport [ perlPackages.perl ]
++ lib.optionals guiSupport [
tcl
@@ -399,11 +393,9 @@ stdenv.mkDerivation (finalAttrs: {
# Also put git-http-backend into $PATH, so that we can use smart
# HTTP(s) transports for pushing
ln -s $out/libexec/git-core/git-http-backend${stdenv.hostPlatform.extensions.executable} $out/bin/git-http-backend
ln -s $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump
''
+ lib.optionalString perlSupport ''
makeWrapper $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump \
--prefix PATH : "${gitJumpBinPath}"
# wrap perl commands
makeWrapper "$out/share/git/contrib/credential/netrc/git-credential-netrc.perl" $out/libexec/git-core/git-credential-netrc \
--set PERL5LIB "$out/${perlPackages.perl.libPrefix}:${perlPackages.makePerlPath perlLibs}"
@@ -430,10 +422,6 @@ stdenv.mkDerivation (finalAttrs: {
done
''
+ lib.optionalString pythonSupport ''
patchShebangs $out/share/git/contrib/fast-import/import-zips.py
''
+ (
if svnSupport then
''

View File

@@ -41,11 +41,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "groff";
version = "1.24.2";
version = "1.24.1";
src = fetchurl {
url = "mirror://gnu/groff/groff-${finalAttrs.version}.tar.gz";
hash = "sha256-+cHv1b6743/G4QY9t0c86N8ePgvk/w9DzgT85X6cXdk=";
hash = "sha256-dOKBl5W2r/QxrqyYPWOpyJaO6roqLrp9+LpMe0Hnz9g=";
};
patches = [

View File

@@ -4,6 +4,7 @@
buildPackages,
replaceVars,
fetchurl,
fetchpatch,
pkg-config,
docutils,
gettext,
@@ -75,7 +76,7 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "gtk4";
version = "4.22.5";
version = "4.22.4";
outputs = [
"out"
@@ -91,9 +92,17 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/gtk/${lib.versions.majorMinor finalAttrs.version}/gtk-${finalAttrs.version}.tar.xz";
hash = "sha256-f9cl3rLLP43CGK2GLFBW/4VI9J07DkCBeW5ETCLRloY=";
hash = "sha256-Ub2fYMfSOmZaVWxzZMIfsuTiglZrPn4JJFXo+RAzCJM=";
};
patches = [
(fetchpatch {
name = "fix-32bit-VkImage-null.patch";
url = "https://gitlab.gnome.org/GNOME/gtk/-/commit/10d43de8f4f942cb591ada3103474bd7213425f1.patch";
hash = "sha256-DJIL6M3XcsjBoMO77OxNi84d1DxAphAfot3N7Nq1QqQ=";
})
];
depsBuildBuild = [
pkg-config
];

View File

@@ -3,7 +3,6 @@
stdenv,
replaceVars,
fetchFromGitHub,
fetchpatch,
autoreconfHook,
gettext,
makeWrapper,
@@ -91,15 +90,6 @@ stdenv.mkDerivation (finalAttrs: {
./build-without-dbus-launch.patch
# https://github.com/NixOS/nixpkgs/issues/230290
./vala-parallelism.patch
# Fix crashes in `gtk_im_multicontext_set_delegate` with latest GTK
# GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341
# Upstream PR: https://github.com/ibus/ibus/pull/2929
(fetchpatch {
name = "fix-gtk-crashes.patch";
url = "https://github.com/ibus/ibus/commit/c534999a9dbea2666864250d74e058ecfb46e76f.patch";
hash = "sha256-1h48hvdrDh2Qh4+SufL147CxlfiwvP/Jv509X0WnbrA=";
})
];
outputs = [

View File

@@ -88,13 +88,13 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "imagemagick";
version = "7.1.2-32";
version = "7.1.2-31";
src = fetchFromGitHub {
owner = "ImageMagick";
repo = "ImageMagick";
tag = finalAttrs.version;
hash = "sha256-/8U47oVkzU6VeYec6ZND+wAAJonsmwlcgeBvQ+M7hk8=";
hash = "sha256-RQpvpWSEMIIGIDLk5X9BwsWgD0AKPBgJ2m9dSipq8Lc=";
};
outputs = [

View File

@@ -23,7 +23,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libadwaita";
version = "1.9.4";
version = "1.9.3";
outputs = [
"out"
@@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "GNOME";
repo = "libadwaita";
tag = finalAttrs.version;
hash = "sha256-EhMwaZe+nzHNNakVKKXCBbFScavOb6c6anmVIvvjUvg=";
hash = "sha256-1V3L10YgRnOoJud/lybfSj2AYOY0kRAJdfamJg+S1fo=";
};
depsBuildBuild = [

View File

@@ -1,8 +1,8 @@
diff --git a/cmake/aom_install.cmake b/cmake/aom_install.cmake
index a8f6d64361..c5223462ed 100644
--- a/cmake/aom_install.cmake
+++ b/cmake/aom_install.cmake
@@ -45,8 +45,8 @@ macro(setup_aom_install_targets)
diff --git a/build/cmake/aom_install.cmake b/build/cmake/aom_install.cmake
index 0bd2bf035..5cf5acea8 100644
--- a/build/cmake/aom_install.cmake
+++ b/build/cmake/aom_install.cmake
@@ -42,8 +42,8 @@ macro(setup_aom_install_targets)
-DAOM_ROOT=${AOM_ROOT}
-DCMAKE_INSTALL_PREFIX=${CMAKE_INSTALL_PREFIX}
-DCMAKE_INSTALL_BINDIR=${CMAKE_INSTALL_BINDIR}
@@ -11,9 +11,9 @@ index a8f6d64361..c5223462ed 100644
+ -DCMAKE_INSTALL_FULL_INCLUDEDIR=${CMAKE_INSTALL_FULL_INCLUDEDIR}
+ -DCMAKE_INSTALL_FULL_LIBDIR=${CMAKE_INSTALL_FULL_LIBDIR}
-DCMAKE_PROJECT_NAME=${CMAKE_PROJECT_NAME}
-DCMAKE_THREAD_LIBS_INIT=${CMAKE_THREAD_LIBS_INIT}
-DCONFIG_MULTITHREAD=${CONFIG_MULTITHREAD}
@@ -115,13 +115,13 @@ macro(setup_aom_install_targets)
-DCONFIG_TUNE_VMAF=${CONFIG_TUNE_VMAF}
@@ -84,12 +84,12 @@ macro(setup_aom_install_targets)
# Setup the install rules. install() will automatically prepend
# CMAKE_INSTALL_PREFIX to relative paths
install(FILES ${AOM_INSTALL_INCS}
@@ -23,7 +23,6 @@ index a8f6d64361..c5223462ed 100644
- DESTINATION "${CMAKE_INSTALL_LIBDIR}/pkgconfig")
+ DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}/pkgconfig")
install(TARGETS ${AOM_INSTALL_LIBS};${AOM_INSTALL_BINS}
EXPORT "${AOM_TARGETS_EXPORT_NAME}"
- RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}"
- LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}"
- ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}")
@@ -32,12 +31,12 @@ index a8f6d64361..c5223462ed 100644
+ ARCHIVE DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}")
endif()
endmacro()
diff --git a/cmake/pkg_config.cmake b/cmake/pkg_config.cmake
index ad3cf77009..1b46040cd1 100644
--- a/cmake/pkg_config.cmake
+++ b/cmake/pkg_config.cmake
diff --git a/build/cmake/pkg_config.cmake b/build/cmake/pkg_config.cmake
index e8fff2e77..b8a73aad4 100644
--- a/build/cmake/pkg_config.cmake
+++ b/build/cmake/pkg_config.cmake
@@ -11,8 +11,8 @@
cmake_minimum_required(VERSION 3.16)
cmake_minimum_required(VERSION 3.5)
set(REQUIRED_ARGS "AOM_ROOT" "AOM_CONFIG_DIR" "CMAKE_INSTALL_PREFIX"
- "CMAKE_INSTALL_BINDIR" "CMAKE_INSTALL_INCLUDEDIR"

View File

@@ -23,16 +23,25 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "libaom";
version = "3.15.0";
version = "3.12.1";
src = fetchzip {
url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz";
hash = "sha256-TixZQP06TEZPtpHvWVOEagzHtXW9hqXWweO2yimBDG4=";
hash = "sha256-AAS6wfq4rZ4frm6+gwKoIS3+NVzPhhfW428WXJQ2tQ8=";
stripRoot = false;
};
patches = [
./outputs.patch
]
++ lib.optionals (!stdenv.hostPlatform.isDarwin) [
# This patch defines `_POSIX_C_SOURCE`, which breaks system headers
# on Darwin.
(fetchurl {
name = "musl.patch";
url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-libs/libaom/files/libaom-3.4.0-posix-c-source-ftello.patch?id=50c7c4021e347ee549164595280cf8a23c960959";
hash = "sha256-6+u7GTxZcSNJgN7D+s+XAVwbMnULufkTcQ0s7l+Ydl0=";
})
];
nativeBuildInputs = [
@@ -45,16 +54,11 @@ stdenv.mkDerivation (finalAttrs: {
propagatedBuildInputs = lib.optional enableVmaf libvmaf;
env =
lib.optionalAttrs stdenv.hostPlatform.isFreeBSD {
# This can be removed when we switch to libcxx from llvm 20
# https://github.com/llvm/llvm-project/pull/122361
NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700";
}
// lib.optionalAttrs stdenv.hostPlatform.isLinux {
# _POSIX_C_SOURCE breaks system headers on Darwin; it's required on musl
NIX_CFLAGS_COMPILE = "-D_POSIX_C_SOURCE=200112L";
};
env = lib.optionalAttrs stdenv.hostPlatform.isFreeBSD {
# This can be removed when we switch to libcxx from llvm 20
# https://github.com/llvm/llvm-project/pull/122361
NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700";
};
preConfigure = ''
# build uses `git describe` to set the build version
@@ -87,17 +91,11 @@ stdenv.mkDerivation (finalAttrs: {
postFixup = ''
moveToOutput lib/libaom.a "$static"
substituteInPlace "$dev"/lib/cmake/*/*.cmake \
--replace-quiet "$out/lib/libaom.a" "$static/lib/libaom.a" \
--replace-quiet "$"'{_IMPORT_PREFIX}/include' "$dev/include"
''
+ lib.optionalString stdenv.hostPlatform.isStatic ''
ln -s $static $out
'';
__structuredAttrs = true;
strictDeps = true;
outputs = [
"out"
"bin"

View File

@@ -31,7 +31,7 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "libavif";
version = "1.4.2";
version = "1.4.1";
outputs = [
"out"
@@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "AOMediaCodec";
repo = "libavif";
rev = "v${finalAttrs.version}";
hash = "sha256-AMQ1TRPGpuBBW7tJ8xuLEVTAeOsLWTHuE0dFJjI7+W4=";
hash = "sha256-035SoxHfN121mp3LGwGykReCi1WJbl2/nZH8c/VwABU=";
};
postPatch = ''

View File

@@ -2,6 +2,7 @@
lib,
stdenv,
fetchurl,
fetchpatch,
gettext,
libgpg-error,
enableCapabilities ? false,
@@ -17,13 +18,23 @@ assert enableCapabilities -> stdenv.hostPlatform.isLinux;
stdenv.mkDerivation rec {
pname = "libgcrypt";
version = "1.12.4";
version = "1.12.2";
src = fetchurl {
url = "mirror://gnupg/libgcrypt/${pname}-${version}.tar.bz2";
hash = "sha256-139o9Ih5UQ55ovZZd8zGiYF4HqCSPlvf+sKhk+o9Zg4=";
hash = "sha256-fOM8JJIiGgQ2+WqFACFenz49y1/SanV81BXnqEO6vV4=";
};
patches = lib.optionals stdenv.hostPlatform.isRiscV64 [
# Remove in next release
# https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5
# zvkned AES corrupts CBC/CFB/CTR/OCB/XTS output on VLEN>128 hardware
(fetchpatch {
url = "https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5.patch";
hash = "sha256-1LSrIwsN0n5IBRDZ+9MJTEjzY+/T6LQO6hX1ke8hSuc=";
})
];
outputs = [
"bin"
"lib"

View File

@@ -24,7 +24,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libheif";
version = "1.23.5";
version = "1.23.4";
outputs = [
"bin"
@@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "strukturag";
repo = "libheif";
rev = "v${finalAttrs.version}";
hash = "sha256-+nrUIAclVgkj4N5U3wQ1L6qpZuF3fuzHFDUT+X39h04=";
hash = "sha256-bxN3YB/nKjrsHa/dM3sTAnWR+wOHk5a6ku6NF+8moQ0=";
};
nativeBuildInputs = [

View File

@@ -28,13 +28,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libpcap";
version = "1.10.7";
version = "1.10.6";
__structuredAttrs = true;
src = fetchurl {
url = "https://www.tcpdump.org/release/libpcap-${finalAttrs.version}.tar.gz";
hash = "sha256-CzlKyQ28Cpg4/5dGjgXJyaPoc97CUUzVjbZdhZ0pbjE=";
hash = "sha256-hy3REzf+GrAq2dT+4EfJ2iRNaVxt3zTi67cz79Ttiqk=";
};
outputs = [

View File

@@ -50,7 +50,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "librsvg";
version = "2.62.4";
version = "2.62.3";
outputs = [
"out"
@@ -62,13 +62,13 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/librsvg/${lib.versions.majorMinor finalAttrs.version}/librsvg-${finalAttrs.version}.tar.xz";
hash = "sha256-yYK4FXoFS4A0k7+ZTTHlAQXrlI3Y2mtKuXNOjTknEqM=";
hash = "sha256-frRJsnIqdoAhNW9m3+4yAsIptU7U5qcM5AwJDpf/FvI=";
};
cargoDeps = rustPlatform.fetchCargoVendor {
inherit (finalAttrs) src;
name = "librsvg-deps-${finalAttrs.version}";
hash = "sha256-8kFJQD3QQRFoQ1L+/pWwA0Tb8TQ4Zar2uvKrXywuW8E=";
hash = "sha256-9ubfIl9R2BdcAWn7i050KBbb4cMdlakvrKdnjpZCQjA=";
dontConfigure = true;
};

View File

@@ -71,7 +71,7 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "libsecret";
version = "0.21.8.2";
version = "0.21.7";
outputs = [
"out"
@@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/libsecret/${lib.versions.majorMinor finalAttrs.version}/libsecret-${finalAttrs.version}.tar.xz";
hash = "sha256-FClIM5xblx2PaoxwmVIfb9MZtv5z0mlLTm0zEO0otuY=";
hash = "sha256-a0UuR1BZCitWF63EACbyjS9JA94V8SUOHRxAv9aO1V4=";
};
depsBuildBuild = [

View File

@@ -8,12 +8,12 @@
}:
stdenv.mkDerivation (finalAttrs: {
version = "1.6.45";
version = "1.6.42";
pname = "memcached";
src = fetchurl {
url = "https://memcached.org/files/memcached-${finalAttrs.version}.tar.gz";
sha256 = "sha256-02LGTm2NUocVNQHqv3yFtKdhQy+/U/XXsIXQuxZTwd0=";
sha256 = "sha256-UPCLh51PnTbeqdkF6eqt4Vxwjjjbfppz/CHci0U5Xec=";
};
configureFlags = [

View File

@@ -1,11 +1,13 @@
{
lib,
stdenvNoCC,
bintools,
fetchurl,
lib,
makeWrapper,
patchelf,
bintools,
stdenvNoCC,
testers,
dpkg,
# Linked dynamic libraries
alsa-lib,
at-spi2-atk,
@@ -46,15 +48,20 @@
pipewire,
vulkan-loader,
wayland, # ozone/wayland
# Command line programs
coreutils,
# command line arguments which are always set e.g "--disable-gpu"
commandLineArgs ? "",
# Will crash without.
systemd,
# Loaded at runtime.
libexif,
pciutils,
# Additional dependencies according to other distros
## Ubuntu
curl,
@@ -73,27 +80,38 @@
## Gentoo
bzip2,
libcap,
# Necessary for USB audio devices.
libpulseaudio,
pulseSupport ? true,
adwaita-icon-theme,
gsettings-desktop-schemas,
# For video acceleration via VA-API (--enable-features=VaapiVideoDecoder)
libva,
libvaSupport ? true,
# For Vulkan support (--enable-features=Vulkan)
addDriverRunpath,
# For QT support
undmg,
# Enables Edge's "Use QT" appearance to introspect the user's Plasma theme
plasmaSupport ? false,
qt6,
# Edge AAD sync
kdePackages,
# Edge Specific and AAD sync
cacert,
libsecret,
# Edge Specific
libuuid,
# Create a symlink at $out/bin/microsoft-edge-stable
withSymlink ? true,
}:
let
pname = "microsoft-edge";
opusWithCustomModes = libopus.override { withCustomModes = true; };
deps = [
@@ -115,15 +133,20 @@ let
gcc-unwrapped.lib
gdk-pixbuf
glib
gtk3
gtk4
harfbuzz
icu
libcap
libdrm
liberation_ttf
libexif
libgbm
libglvnd
libkrb5
libpng
libsecret
libuuid
libx11
libxcb
libxcomposite
@@ -138,7 +161,6 @@ let
libxscrnsaver
libxshmfence
libxtst
libgbm
nspr
nss
opusWithCustomModes
@@ -152,124 +174,178 @@ let
vulkan-loader
wayland
wget
libsecret
libuuid
gtk3
gtk4
]
++ lib.optional pulseSupport libpulseaudio
++ lib.optional libvaSupport libva
++ lib.optionals plasmaSupport [
qt6.qtbase
qt6.qtwayland
]
++ lib.optionals pulseSupport [ libpulseaudio ]
++ lib.optionals libvaSupport [ libva ];
in
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "microsoft-edge";
version = "154.0.4258.37";
src = fetchurl {
url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb";
hash = "sha256-xvopdHM5kTIbRsQGS3hc3sWhTYzd0YK8X9oFfjfnYD0=";
};
# With strictDeps on, some shebangs were not being patched correctly
# ie, $out/share/microsoft/msedge/microsoft-edge
strictDeps = false;
nativeBuildInputs = [
makeWrapper
patchelf
dpkg
kdePackages.plasma-integration
kdePackages.breeze
];
buildInputs = [
# needed for XDG_ICON_DIRS
adwaita-icon-theme
glib
gtk3
gtk4
# needed for GSETTINGS_SCHEMAS_PATH
gsettings-desktop-schemas
];
linux = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "154.0.4258.37";
rpath = lib.makeLibraryPath deps + ":" + lib.makeSearchPathOutput "lib" "lib64" deps;
binpath = lib.makeBinPath deps;
src = fetchurl {
url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb";
hash = "sha256-xvopdHM5kTIbRsQGS3hc3sWhTYzd0YK8X9oFfjfnYD0=";
};
installPhase = ''
runHook preInstall
# With strictDeps on, some shebangs were not being patched correctly
# ie, $out/share/microsoft/msedge/microsoft-edge
strictDeps = false;
appname=msedge
dist=stable
nativeBuildInputs = [
makeWrapper
patchelf
dpkg
];
exe=$out/bin/microsoft-edge
buildInputs = [
# needed for XDG_ICON_DIRS
adwaita-icon-theme
glib
gtk3
gtk4
# needed for GSETTINGS_SCHEMAS_PATH
gsettings-desktop-schemas
];
mkdir -p $out/bin
cp -v -a usr/share $out/share
cp -v -a opt/microsoft $out/share/microsoft
rpath = lib.makeLibraryPath deps + ":" + lib.makeSearchPathOutput "lib" "lib64" deps;
binpath = lib.makeBinPath deps;
# replace bundled vulkan-loader
rm -v $out/share/microsoft/$appname/libvulkan.so.1
ln -v -s -t "$out/share/microsoft/$appname" "${lib.getLib vulkan-loader}/lib/libvulkan.so.1"
installPhase = ''
runHook preInstall
substituteInPlace $out/share/microsoft/$appname/microsoft-edge \
--replace-fail 'CHROME_WRAPPER' 'WRAPPER'
substituteInPlace $out/share/applications/microsoft-edge.desktop \
--replace-fail /usr/bin/microsoft-edge-$dist $exe
substituteInPlace $out/share/applications/com.microsoft.Edge.desktop \
--replace-fail /usr/bin/microsoft-edge-$dist $exe
substituteInPlace $out/share/gnome-control-center/default-apps/microsoft-edge.xml \
--replace-fail /opt/microsoft/msedge $exe
appname=msedge
dist=stable
for icon_file in $out/share/microsoft/msedge/product_logo_[0-9]*.png; do
num_and_suffix="''${icon_file##*logo_}"
if [ $dist = "stable" ]; then
icon_size="''${num_and_suffix%.*}"
else
icon_size="''${num_and_suffix%_*}"
fi
logo_output_prefix="$out/share/icons/hicolor"
logo_output_path="$logo_output_prefix/''${icon_size}x''${icon_size}/apps"
mkdir -p "$logo_output_path"
mv "$icon_file" "$logo_output_path/microsoft-edge.png"
done
exe=$out/bin/microsoft-edge-$dist
# "--simulate-outdated-no-au" disables auto updates and browser outdated popup
makeWrapper "$out/share/microsoft/$appname/microsoft-edge" "$exe" \
--prefix QT_PLUGIN_PATH : "${qt6.qtbase}/lib/qt-6/plugins" \
--prefix QT_PLUGIN_PATH : "${qt6.qtwayland}/lib/qt-6/plugins" \
--prefix NIXPKGS_QT6_QML_IMPORT_PATH : "${qt6.qtwayland}/lib/qt-6/qml" \
--prefix LD_LIBRARY_PATH : "$rpath" \
--prefix PATH : "$binpath" \
--suffix PATH : "${lib.makeBinPath [ xdg-utils ]}" \
--prefix XDG_DATA_DIRS : "$XDG_ICON_DIRS:$GSETTINGS_SCHEMAS_PATH:${addDriverRunpath.driverLink}/share" \
--set SSL_CERT_FILE "${cacert}/etc/ssl/certs/ca-bundle.crt" \
--set CHROME_WRAPPER "microsoft-edge-$dist" \
--add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--ozone-platform-hint=auto --enable-features=WaylandWindowDecorations --enable-wayland-ime=true --wayland-text-input-version=3}}" \
--add-flags "--simulate-outdated-no-au='Tue, 31 Dec 2099 23:59:59 GMT'" \
--add-flags ${lib.escapeShellArg commandLineArgs}
mkdir -p $out/bin $out/share
cp -v -a opt/* $out/share
cp -v -a usr/share/* $out/share
# Edge specific set liboneauth
patchelf --set-rpath $rpath $out/share/microsoft/$appname/liboneauth.so
# replace bundled vulkan-loader
rm -v $out/share/microsoft/$appname/libvulkan.so.1
ln -v -s -t "$out/share/microsoft/$appname" "${lib.getLib vulkan-loader}/lib/libvulkan.so.1"
for elf in $out/share/microsoft/$appname/{msedge,msedge-sandbox,msedge_crashpad_handler}; do
patchelf --set-rpath $rpath $elf
patchelf --set-interpreter ${bintools.dynamicLinker} $elf
done
substituteInPlace $out/share/microsoft/$appname/microsoft-edge \
--replace-fail 'CHROME_WRAPPER' 'WRAPPER'
substituteInPlace $out/share/applications/microsoft-edge.desktop \
--replace-fail /usr/bin/microsoft-edge-$dist $exe
substituteInPlace $out/share/applications/com.microsoft.Edge.desktop \
--replace-fail /usr/bin/microsoft-edge-$dist $exe
substituteInPlace $out/share/gnome-control-center/default-apps/microsoft-edge.xml \
--replace-fail /opt/microsoft/$appname $exe
${lib.optionalString withSymlink ''
ln -s $out/bin/microsoft-edge $out/bin/microsoft-edge-stable
''}
for icon_file in $out/share/microsoft/msedge/product_logo_[0-9]*.png; do
num_and_suffix="''${icon_file##*logo_}"
if [ $dist = "stable" ]; then
icon_size="''${num_and_suffix%.*}"
else
icon_size="''${num_and_suffix%_*}"
fi
logo_output_prefix="$out/share/icons/hicolor"
logo_output_path="$logo_output_prefix/''${icon_size}x''${icon_size}/apps"
mkdir -p "$logo_output_path"
mv "$icon_file" "$logo_output_path/microsoft-edge.png"
done
runHook postInstall
'';
# "--simulate-outdated-no-au" disables auto updates and browser outdated popup
makeWrapper "$out/share/microsoft/$appname/microsoft-edge" "$exe" \
${lib.optionalString plasmaSupport ''
--prefix QT_PLUGIN_PATH : "${qt6.qtbase}/lib/qt-6/plugins" \
--prefix QT_PLUGIN_PATH : "${qt6.qtwayland}/lib/qt-6/plugins" \
--prefix QT_PLUGIN_PATH : "${kdePackages.plasma-integration}/lib/qt-6/plugins" \
--prefix QT_PLUGIN_PATH : "${kdePackages.breeze}/lib/qt-6/plugins" \
--prefix NIXPKGS_QT6_QML_IMPORT_PATH : "${qt6.qtwayland}/lib/qt-6/qml" \
''} \
--prefix LD_LIBRARY_PATH : "$rpath" \
--prefix PATH : "$binpath" \
--suffix PATH : "${lib.makeBinPath [ xdg-utils ]}" \
--prefix XDG_DATA_DIRS : "$XDG_ICON_DIRS:$GSETTINGS_SCHEMAS_PATH:${addDriverRunpath.driverLink}/share" \
--set SSL_CERT_FILE "${cacert}/etc/ssl/certs/ca-bundle.crt" \
--set CHROME_WRAPPER "microsoft-edge-$dist" \
--add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--ozone-platform-hint=auto --enable-features=WaylandWindowDecorations --enable-wayland-ime=true --wayland-text-input-version=3}}" \
--add-flags "--simulate-outdated-no-au='Tue, 31 Dec 2099 23:59:59 GMT'" \
--add-flags ${lib.escapeShellArg commandLineArgs}
passthru.updateScript = ./update.py;
# Edge specific set liboneauth
patchelf --set-rpath $rpath $out/share/microsoft/$appname/liboneauth.so
for elf in $out/share/microsoft/$appname/{msedge,msedge-sandbox,msedge_crashpad_handler}; do
patchelf --set-rpath $rpath $elf
patchelf --set-interpreter ${bintools.dynamicLinker} $elf
done
runHook postInstall
'';
postInstall = lib.optionalString withSymlink ''
ln -s $out/bin/microsoft-edge-stable $out/bin/microsoft-edge
'';
passthru = {
updateScript = ./update.sh;
tests.version = testers.testVersion { package = finalAttrs.finalPackage; };
};
});
darwin = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "154.0.4258.37";
uuid = "f7dec597-801d-4c4b-ae51-c8a53c78925c";
src = fetchurl {
url = "https://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/${finalAttrs.uuid}/MicrosoftEdge-${finalAttrs.version}.dmg";
hash = "sha256-R385aGFby0WK64wxHGCbKnDymsUIG+lzTpQfVO2NBgA=";
};
dontPatch = true;
dontConfigure = true;
dontBuild = true;
dontFixup = true;
nativeBuildInputs = [
makeWrapper
undmg
];
sourceRoot = ".";
installPhase = ''
runHook preInstall
mkdir -p $out/Applications
cp -r *.app $out/Applications
mkdir -p $out/bin
# "--simulate-outdated-no-au" disables auto updates and browser outdated popup
makeWrapper $out/Applications/Microsoft\ Edge.app/Contents/MacOS/Microsoft\ Edge $out/bin/microsoft-edge-stable \
--add-flags "--simulate-outdated-no-au='Tue, 31 Dec 2099 23:59:59 GMT'" \
--add-flags ${lib.escapeShellArg commandLineArgs}
runHook postInstall
'';
postInstall = lib.optionalString withSymlink ''
ln -s $out/bin/microsoft-edge-stable $out/bin/microsoft-edge
'';
passthru = {
updateScript = ./update.sh;
tests.version = testers.testVersion { package = finalAttrs.finalPackage; };
};
});
meta = {
changelog = "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel";
description = "Web browser from Microsoft";
homepage = "https://www.microsoft.com/en-us/edge";
changelog = "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel";
license = lib.licenses.unfree;
mainProgram = "microsoft-edge";
maintainers = with lib.maintainers; [
cholli
ulrikstrid
@@ -278,7 +354,17 @@ stdenvNoCC.mkDerivation (finalAttrs: {
jonhermansen
iedame
];
platforms = [ "x86_64-linux" ];
platforms = lib.platforms.darwin ++ [
"x86_64-linux"
];
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
mainProgram = "microsoft-edge-stable";
};
})
in
if stdenvNoCC.hostPlatform.isDarwin then
darwin
else if stdenvNoCC.hostPlatform.isLinux then
linux
else
throw "Unsupported platform ${stdenvNoCC.hostPlatform.system}"

View File

@@ -1,46 +0,0 @@
#! /usr/bin/env nix-shell
#! nix-shell -i python3 -p python3Packages.packaging python3Packages.python-debian common-updater-scripts
import os
from collections import OrderedDict
from os.path import abspath, dirname
from urllib import request
from debian.deb822 import Packages
from debian.debian_support import Version
PIN_PATH = dirname(abspath(__file__)) + "/default.nix"
def packages():
packages_url = "https://packages.microsoft.com/repos/edge/dists/stable/main/binary-amd64/Packages"
handle = request.urlopen(packages_url)
return handle
def latest_packages(packages: bytes):
latest_packages: OrderedDict[str, Packages] = {}
for package in Packages.iter_paragraphs(packages, use_apt_pkg=False):
name: str = package["Package"]
if not name.startswith("microsoft-edge-stable"):
continue
channel = name.replace("microsoft-edge-", "")
if channel not in latest_packages:
latest_packages[channel] = package
else:
old_package = latest_packages[channel]
if old_package.get_version() < package.get_version(): # type: ignore
latest_packages[channel] = package
return OrderedDict(sorted(latest_packages.items(), key=lambda x: x[0]))
def write_expression():
latest = latest_packages(packages())
version = Version.re_valid_version.match(latest["stable"]["Version"]).group(
"upstream_version"
)
os.system(f'update-source-version microsoft-edge "{version}"')
os.system(f'update-source-version msedgedriver "{version}"')
write_expression()

View File

@@ -0,0 +1,258 @@
#!/usr/bin/env nix-shell
#!nix-shell -I nixpkgs=./. -i bash -p curl gawk nix common-updater-scripts python3Packages.python-debian
# shellcheck shell=bash
set -euo pipefail
DEFAULT_NIX="$(realpath "./pkgs/by-name/mi/microsoft-edge/package.nix")"
DRIVER_NIX="$(realpath "./pkgs/by-name/ms/msedgedriver/package.nix")"
get_linux_version_info() {
local packages_url
local response
local version
local current_version
local download_url
packages_url="https://packages.microsoft.com/repos/edge/dists/stable/main/binary-amd64/Packages"
response="$(curl --silent --fail "$packages_url")"
read -r version download_url <<< "$(
python3 -c '
import sys
from debian.deb822 import Packages
from debian.debian_support import Version
latest = None
for package in Packages.iter_paragraphs(sys.stdin, use_apt_pkg=False):
if package["Package"] != "microsoft-edge-stable":
continue
if latest is None or latest.get_version() < package.get_version():
latest = package
if latest is None:
raise SystemExit("microsoft-edge-stable not found")
version = Version.re_valid_version.match(
latest["Version"]
).group("upstream_version")
url = (
"https://packages.microsoft.com/repos/edge/"
+ latest["Filename"]
)
print(version, url)
' <<< "$response"
)"
current_version="$(
awk '
/^ linux = stdenvNoCC.mkDerivation/ { in_block=1 }
in_block && /version = "/ {
match($0, /version = "([^"]+)"/, arr)
print arr[1]
exit
}
in_block && /^ \};/ { exit }
' "$DEFAULT_NIX"
)"
echo "$version" "$current_version" "$download_url"
}
get_darwin_version_info() {
local redirect_url
local final_url
local version
local current_version
local uuid
redirect_url="https://go.microsoft.com/fwlink/?linkid=2192091"
final_url="$(
curl \
--silent \
--show-error \
--fail \
--location \
--output /dev/null \
--write-out '%{url_effective}' \
"$redirect_url"
)"
if [[ "$final_url" =~ /files/([^/]+)/MicrosoftEdge-([0-9.]+)\.dmg$ ]]; then
uuid="${BASH_REMATCH[1]}"
version="${BASH_REMATCH[2]}"
else
echo "Could not parse Darwin URL: $final_url" >&2
exit 1
fi
current_version="$(
awk '
/^ darwin = stdenvNoCC.mkDerivation/ { in_block=1 }
in_block && /version = "/ {
match($0, /version = "([^"]+)"/, arr)
print arr[1]
exit
}
in_block && /^ \};/ { exit }
' "$DEFAULT_NIX"
)"
echo "$version" "$current_version" "$uuid" "$final_url"
}
update_linux() {
local version_info
local version
local current_version
local download_url
local new_hash
read -ra version_info <<< "$(get_linux_version_info)"
version="${version_info[0]}"
current_version="${version_info[1]}"
download_url="${version_info[2]}"
if [[ "$current_version" = "$version" ]]; then
echo "[Nix] Linux microsoft-edge: same version"
return 0
fi
new_hash="$(
nix --extra-experimental-features nix-command \
hash convert \
--hash-algo sha256 \
--to sri \
"$(nix-prefetch-url "$download_url" 2>/dev/null)"
)"
sed -i \
"/^ linux = stdenvNoCC.mkDerivation/,/^ });/s/version = \".*\"/version = \"$version\"/" \
"$DEFAULT_NIX"
sed -i \
"/^ linux = stdenvNoCC.mkDerivation/,/^ });/s|hash = \".*\"|hash = \"$new_hash\"|" \
"$DEFAULT_NIX"
echo "[Nix] Linux microsoft-edge: $current_version -> $version with hash $new_hash"
}
update_darwin() {
local version_info
local version
local current_version
local uuid
local url
local new_hash
read -ra version_info <<< "$(get_darwin_version_info)"
version="${version_info[0]}"
current_version="${version_info[1]}"
uuid="${version_info[2]}"
url="${version_info[3]}"
if [[ "$current_version" = "$version" ]]; then
echo "[Nix] Darwin microsoft-edge: same version"
return 0
fi
new_hash="$(
nix --extra-experimental-features nix-command \
hash convert \
--hash-algo sha256 \
--to sri \
"$(nix-prefetch-url "$url" 2>/dev/null)"
)"
sed -i \
"/^ darwin = stdenvNoCC.mkDerivation/,/^ });/s/version = \".*\"/version = \"$version\"/" \
"$DEFAULT_NIX"
sed -i \
"/^ darwin = stdenvNoCC.mkDerivation/,/^ });/s|uuid = \".*\"|uuid = \"$uuid\"|" \
"$DEFAULT_NIX"
sed -i \
"/^ darwin = stdenvNoCC.mkDerivation/,/^ });/s|hash = \".*\"|hash = \"$new_hash\"|" \
"$DEFAULT_NIX"
echo "[Nix] Darwin microsoft-edge: $current_version -> $version with hash $new_hash"
}
update_msedgedriver() {
local version="$1"
local current_version
local new_hash
local driver_arch
local url
current_version="$(
awk '
/pname = "msedgedriver";/ { in_block=1 }
in_block && /version = "/ {
match($0, /version = "([^"]+)"/, arr)
print arr[1]
exit
}
' "$DRIVER_NIX"
)"
if [[ "$current_version" = "$version" ]]; then
echo "[Nix] msedgedriver: same version"
return 0
fi
# All supported driver archives use the Linux Edge version.
# The archive names correspond to the driverArch mapping in
# msedgedriver/package.nix
declare -A hashes=(
[mac64_m1]=""
[mac64]=""
[linux64]=""
)
for driver_arch in mac64_m1 mac64 linux64; do
url="https://msedgedriver.microsoft.com/${version}/edgedriver_${driver_arch}.zip"
new_hash="$(
nix --extra-experimental-features nix-command \
hash convert \
--hash-algo sha256 \
--to sri \
"$(nix-prefetch-url --unpack "$url" 2>/dev/null)"
)"
hashes["$driver_arch"]="$new_hash"
echo "[Nix] msedgedriver ${driver_arch}: $new_hash"
done
sed -i \
"/pname = \"msedgedriver\";/,/^ meta = {/s/version = \".*\"/version = \"$version\"/" \
"$DRIVER_NIX"
for driver_arch in mac64_m1 mac64 linux64; do
sed -i \
"/pname = \"msedgedriver\";/,/^ meta = {/s|${driver_arch} = \".*\"|${driver_arch} = \"${hashes[$driver_arch]}\"|" \
"$DRIVER_NIX"
done
echo "[Nix] msedgedriver: $current_version -> $version"
}
update_linux
update_darwin
# Linux is the canonical platform for the shared msedgedriver version
linux_version_info="$(get_linux_version_info)"
read -r linux_version _ _ <<< "$linux_version_info"
update_msedgedriver "$linux_version"

View File

@@ -14,39 +14,46 @@ stdenvNoCC.mkDerivation (finalAttrs: {
pname = "msedgedriver";
version = "154.0.4258.37";
src = fetchzip {
url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_linux64.zip";
hash = "sha256-XbOQl9FyckF3Qybb+40474ImJDKahBkekPoydf/TxV0=";
stripRoot = false;
};
src =
let
driverArch =
{
aarch64-darwin = "mac64_m1";
x86_64-darwin = "mac64";
x86_64-linux = "linux64";
}
.${stdenvNoCC.hostPlatform.system};
in
fetchzip {
url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_${driverArch}.zip";
hash =
{
mac64_m1 = "sha256-6nwe/vRPh5MkQLTiZNXepfFsLtILwoK925mgLCUUVNg=";
mac64 = "sha256-p/cnNKQub6sSEWPz2fJ+FoU7rgzeoZQMkv3PphvvHLw=";
linux64 = "sha256-XbOQl9FyckF3Qybb+40474ImJDKahBkekPoydf/TxV0=";
}
.${driverArch};
stripRoot = false;
};
buildInputs = [
buildInputs = lib.optionals stdenvNoCC.hostPlatform.isLinux [
glib
libxcb
nspr
nss
];
nativeBuildInputs = [ autoPatchelfHook ];
nativeBuildInputs = lib.optionals stdenvNoCC.hostPlatform.isLinux [
autoPatchelfHook
];
installPhase =
if stdenvNoCC.hostPlatform.isDarwin then
''
runHook preInstall
installPhase = ''
runHook preInstall
mkdir -p $out/{Applications/msedgedriver,bin}
cp -R . $out/Applications/msedgedriver
install -D msedgedriver $out/bin/msedgedriver
runHook postInstall
''
else
''
runHook preInstall
install -m777 -D "msedgedriver" $out/bin/msedgedriver
runHook postInstall
'';
runHook postInstall
'';
meta = {
homepage = "https://developer.microsoft.com/en-us/microsoft-edge/tools/webdriver";
@@ -54,7 +61,7 @@ stdenvNoCC.mkDerivation (finalAttrs: {
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
license = lib.licenses.unfree;
maintainers = microsoft-edge.meta.maintainers;
platforms = [
platforms = lib.platforms.darwin ++ [
"x86_64-linux"
];
mainProgram = "msedgedriver";

View File

@@ -10,11 +10,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "pcre2";
version = "10.49";
version = "10.48";
src = fetchurl {
url = "https://github.com/PCRE2Project/pcre2/releases/download/pcre2-${finalAttrs.version}/pcre2-${finalAttrs.version}.tar.bz2";
hash = "sha256-U8FW4bpBaiDajmU5XaoTLaDYDnaRBCTKyj/Nrngx04Q=";
hash = "sha256-tsaP3286wxOItQqon/D8ScAMmHwW57UUZJHRIAPyyO0=";
};
nativeBuildInputs = [ updateAutotoolsGnuConfigScriptsHook ];

View File

@@ -0,0 +1,51 @@
{
lib,
rustPlatform,
fetchFromGitHub,
versionCheckHook,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "rustormy";
version = "0.5.2";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "tairesh";
repo = "rustormy";
tag = "v${finalAttrs.version}";
hash = "sha256-LC6hHxCG9TnXcRIxg2jAt6+r8Rm6Iu/TiX/neW5d4fk=";
};
cargoHash = "sha256-cvL+OAiGidQEltM/cgjzjeEFbM7IZvhIG5Q3Nxybb1w=";
checkFlags = [
"--skip=tests::test_different_units"
"--skip=tests::test_empty_city"
"--skip=tests::test_no_location_provided"
"--skip=tests::test_nonexistent_city"
"--skip=tests::test_valid_city_lookup"
"--skip=tests::test_valid_coordinates"
"--skip=weather::enrich::tests::does_not_overwrite_false_is_day_when_set"
"--skip=weather::enrich::tests::does_not_overwrite_true_is_day_when_set"
"--skip=weather::enrich::tests::does_not_overwrite_uv_when_set"
"--skip=weather::enrich::tests::fills_is_day_when_none"
"--skip=weather::enrich::tests::openuv_failure_does_not_break_enrich"
"--skip=weather::enrich::tests::skips_uv_when_openuv_key_empty"
];
nativeInstallCheckInputs = [
versionCheckHook
];
doInstallCheck = true;
meta = {
description = "Minimal neofetch-like weather CLI";
homepage = "https://github.com/tairesh/rustormy";
license = lib.licenses.mit;
mainProgram = "rustormy";
maintainers = with lib.maintainers; [ joseg313 ];
};
})

View File

@@ -1,7 +1,6 @@
{
lib,
stdenv,
fetchpatch2,
fetchurl,
buildPackages,
coreutils,
@@ -32,22 +31,9 @@ stdenv.mkDerivation (finalAttrs: {
prePatch = ''
# do not set sticky bit in nix store
substituteInPlace src/Makefile.in --replace-fail 04755 0755
substituteInPlace src/Makefile.in --replace 04755 0755
'';
patches = [
(fetchpatch2 {
name = "CVE-2026-96512_1.patch";
url = "https://github.com/sudo-project/sudo/commit/db669167ca599f2a94cd8a4c5fae9e473c81a2fd.patch?full_index=1";
hash = "sha256-VqfWo/z7CQCtgefzE8xAehjgKn2h1It6GkEt5BUn/OQ=";
})
(fetchpatch2 {
name = "CVE-2026-96512_2.patch";
url = "https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c.patch?full_index=1";
hash = "sha256-guOdOaIqmXAftpj9gpsRFaAS5g2cS4j7o5DQFqyLZv8=";
})
];
configureFlags = [
"--with-env-editor"
"--with-editor=/run/current-system/sw/bin/nano"

View File

@@ -17,13 +17,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "thrift";
version = "0.24.0";
version = "0.22.0";
src = fetchFromGitHub {
owner = "apache";
repo = "thrift";
tag = "v${finalAttrs.version}";
hash = "sha256-+o/2exHsunjQBGjXrNQ1pQ5TKV53++qCxIMeVyOh5QY=";
hash = "sha256-gGAO+D0A/hEoHMm6OvRBc1Mks9y52kfd0q/Sg96pdW4=";
};
# Workaround to make the Python wrapper not drop this package:
@@ -103,7 +103,7 @@ stdenv.mkDerivation (finalAttrs: {
"StressTestNonBlocking"
];
doCheck = !static && !stdenv.hostPlatform.isDarwin; # FIXME darwin?
doCheck = !static;
enableParallelChecking = false;

View File

@@ -63,13 +63,13 @@ assert lib.assertMsg (
) "unbound: withDoQ requires OpenSSL with QUIC support (OpenSSL >= 3.5)";
stdenv.mkDerivation (finalAttrs: {
pname = "unbound";
version = "1.26.1";
version = "1.26.0";
src = fetchFromGitHub {
owner = "NLnetLabs";
repo = "unbound";
tag = "release-${finalAttrs.version}";
hash = "sha256-gf4vASdB6XzSGhJ2GKbUhgs0wpR32Du2ARx4bBQ+vJA=";
hash = "sha256-ESRboc5vwsNZ/Yynl2JGRWhH1QEYZumoTzgSvN3NbSU=";
};
outputs = [

View File

@@ -14,11 +14,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "xdg-dbus-proxy";
version = "0.1.8";
version = "0.1.7";
src = fetchurl {
url = "https://github.com/flatpak/xdg-dbus-proxy/releases/download/${finalAttrs.version}/xdg-dbus-proxy-${finalAttrs.version}.tar.xz";
hash = "sha256-tmML0k+BYbDiVG0qy7AUo7Mkn1wNdfKoY63omLkDTT0=";
hash = "sha256-OtPSe6V04XisteTUOLo2rOJeNWT4mcNvMcVvgsetu+c=";
};
nativeBuildInputs = [

View File

@@ -25,11 +25,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "go";
version = "1.26.8";
version = "1.26.7";
src = fetchurl {
url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz";
hash = "sha256-Tjm5jkL5RvoFrIvFtxh335fb23y7Gnd7VBZnrXEX/S4=";
hash = "sha256-DtJOrHVRBQhbif6cq8J0K5GgrXuUtZ0602SRjryJVq0=";
};
strictDeps = true;

View File

@@ -1,124 +0,0 @@
diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp
index 2c7005449f..e0c426afa0 100644
--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp
+++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp
@@ -137,6 +137,14 @@
using namespace lldb_private;
using namespace llvm::MachO;
+/// Upper bound on the length of a symbol name assembled from export-trie edge
+/// labels. A corrupt trie can encode an edge label whose terminator is far
+/// away in the trie data, so a single label is many megabytes long; appending
+/// it to the running name would otherwise request an unbounded allocation. No
+/// legitimate symbol name comes close to this size. Also 1 MiB is the
+/// symbol length limit in ld.
+static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB
+
LLDB_PLUGIN_DEFINE(ObjectFileMachO)
static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name,
@@ -2050,15 +2058,21 @@
}
};
-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset,
- const bool is_arm, addr_t text_seg_base_addr,
- std::vector<llvm::StringRef> &nameSlices,
- std::set<lldb::addr_t> &resolver_addresses,
- std::vector<TrieEntryWithOffset> &reexports,
- std::vector<TrieEntryWithOffset> &ext_symbols) {
+static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset,
+ const bool is_arm, addr_t text_seg_base_addr,
+ std::string &prefix,
+ std::set<lldb::addr_t> &resolver_addresses,
+ std::vector<TrieEntryWithOffset> &reexports,
+ std::vector<TrieEntryWithOffset> &ext_symbols,
+ std::set<lldb::offset_t> &visited_nodes) {
if (!data.ValidOffset(offset))
return true;
+ // Every node in a well-formed trie is reached by exactly one path, so a node
+ // offset seen twice means the trie is corrupt.
+ if (!visited_nodes.insert(offset).second)
+ return false;
+
// Terminal node -- end of a branch, possibly add this to
// the symbol table or resolver table.
const uint64_t terminalSize = data.GetULEB128(&offset);
@@ -2098,14 +2112,9 @@
add_this_entry = true;
}
if (add_this_entry) {
- std::string name;
- if (!nameSlices.empty()) {
- for (auto name_slice : nameSlices)
- name.append(name_slice.data(), name_slice.size());
- }
- if (name.size() > 1) {
+ if (prefix.size() > 1) {
// Skip the leading '_'
- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1);
+ e.entry.name.SetString(llvm::StringRef(prefix).drop_front());
}
if (import_name) {
// Skip the leading '_'
@@ -2126,23 +2135,36 @@
const uint8_t childrenCount = data.GetU8(&children_offset);
for (uint8_t i = 0; i < childrenCount; ++i) {
const char *cstr = data.GetCStr(&children_offset);
- if (cstr)
- nameSlices.push_back(llvm::StringRef(cstr));
- else
+ if (!cstr)
return false; // Corrupt data
+ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength)
+ return false; // Corrupt data: implausibly long symbol name.
+ const size_t prevSize = prefix.size();
+ prefix.append(cstr);
lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset);
- if (childNodeOffset) {
- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr,
- nameSlices, resolver_addresses, reexports,
- ext_symbols)) {
- return false;
- }
- }
- nameSlices.pop_back();
+ // A child offset of 0 points back at the root; like any other repeated
+ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt.
+ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr,
+ prefix, resolver_addresses, reexports,
+ ext_symbols, visited_nodes))
+ return false;
+ prefix.resize(prevSize);
}
return true;
}
+static bool ParseTrieEntries(
+ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr,
+ std::set<lldb::addr_t> &resolver_addresses,
+ std::vector<TrieEntryWithOffset> &reexports,
+ std::vector<TrieEntryWithOffset> &ext_symbols) {
+ lldb::offset_t offset = 0;
+ std::set<lldb::offset_t> visited_nodes;
+ std::string prefix;
+ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix,
+ resolver_addresses, reexports, ext_symbols,
+ visited_nodes);
+}
static SymbolType GetSymbolType(const char *&symbol_name,
bool &demangled_is_synthesized,
const SectionSP &text_section_sp,
@@ -2666,9 +2688,8 @@
lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS;
if (text_segment_sp)
text_segment_file_addr = text_segment_sp->GetFileAddress();
- std::vector<llvm::StringRef> nameSlices;
- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr,
- nameSlices, resolver_addresses, reexport_trie_entries,
+ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr,
+ resolver_addresses, reexport_trie_entries,
external_sym_trie_entries);
}

View File

@@ -1,34 +0,0 @@
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
From: Randy Eckenrode <randy@largeandhighquality.com>
Date: Tue, 11 Aug 2026 20:12:42 -0400
Subject: [PATCH] backport-darwin-triple-parsing
---
lib/TargetParser/Triple.cpp | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp
index 0bbe8a3cedfd..4143c3eac05d 100644
--- a/lib/TargetParser/Triple.cpp
+++ b/lib/TargetParser/Triple.cpp
@@ -1253,9 +1253,15 @@ bool Triple::getMacOSXVersion(VersionTuple &Version) const {
}
if (Version.getMajor() <= 19) {
Version = VersionTuple(10, Version.getMajor() - 4);
- } else {
- // darwin20+ corresponds to macOS 11+.
+ } else if (Version.getMajor() < 25) {
+ // darwin20-24 corresponds to macOS 11-15.
Version = VersionTuple(11 + Version.getMajor() - 20);
+ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) {
+ // darwin25-26 corresponds to macOS 26-27.
+ Version = VersionTuple(Version.getMajor() + 1);
+ } else {
+ // Starting with darwin27, it naturally corresponds to the same macOS
+ // version.
}
break;
case MacOSX:
--
2.54.0

View File

@@ -1,31 +0,0 @@
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
From: Randy Eckenrode <randy@largeandhighquality.com>
Date: Tue, 11 Aug 2026 20:19:29 -0400
Subject: [PATCH] backport-darwin-triple-parsing
---
lib/TargetParser/Triple.cpp | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp
index 0584c941d2e6..30cf78dbaabc 100644
--- a/lib/TargetParser/Triple.cpp
+++ b/lib/TargetParser/Triple.cpp
@@ -1449,9 +1449,12 @@ bool Triple::getMacOSXVersion(VersionTuple &Version) const {
} else if (Version.getMajor() < 25) {
// darwin20-24 corresponds to macOS 11-15.
Version = VersionTuple(11 + Version.getMajor() - 20);
- } else {
- // darwin25 corresponds with macOS26+.
+ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) {
+ // darwin25-26 corresponds to macOS 26-27.
Version = VersionTuple(Version.getMajor() + 1);
+ } else {
+ // Starting with darwin27, it naturally corresponds to the same macOS
+ // version.
}
break;
case MacOSX:
--
2.54.0

View File

@@ -1,125 +0,0 @@
diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp
index 0be7b4c6f8..f9d9a05920 100644
--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp
+++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp
@@ -137,6 +137,14 @@
static constexpr llvm::StringLiteral g_loader_path = "@loader_path";
static constexpr llvm::StringLiteral g_executable_path = "@executable_path";
+/// Upper bound on the length of a symbol name assembled from export-trie edge
+/// labels. A corrupt trie can encode an edge label whose terminator is far
+/// away in the trie data, so a single label is many megabytes long; appending
+/// it to the running name would otherwise request an unbounded allocation. No
+/// legitimate symbol name comes close to this size. Also 1 MiB is the
+/// symbol length limit in ld.
+static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB
+
LLDB_PLUGIN_DEFINE(ObjectFileMachO)
static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name,
@@ -1994,15 +2002,21 @@
}
};
-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset,
- const bool is_arm, addr_t text_seg_base_addr,
- std::vector<llvm::StringRef> &nameSlices,
- std::set<lldb::addr_t> &resolver_addresses,
- std::vector<TrieEntryWithOffset> &reexports,
- std::vector<TrieEntryWithOffset> &ext_symbols) {
+static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset,
+ const bool is_arm, addr_t text_seg_base_addr,
+ std::string &prefix,
+ std::set<lldb::addr_t> &resolver_addresses,
+ std::vector<TrieEntryWithOffset> &reexports,
+ std::vector<TrieEntryWithOffset> &ext_symbols,
+ std::set<lldb::offset_t> &visited_nodes) {
if (!data.ValidOffset(offset))
return true;
+ // Every node in a well-formed trie is reached by exactly one path, so a node
+ // offset seen twice means the trie is corrupt.
+ if (!visited_nodes.insert(offset).second)
+ return false;
+
// Terminal node -- end of a branch, possibly add this to
// the symbol table or resolver table.
const uint64_t terminalSize = data.GetULEB128(&offset);
@@ -2042,14 +2056,9 @@
add_this_entry = true;
}
if (add_this_entry) {
- std::string name;
- if (!nameSlices.empty()) {
- for (auto name_slice : nameSlices)
- name.append(name_slice.data(), name_slice.size());
- }
- if (name.size() > 1) {
+ if (prefix.size() > 1) {
// Skip the leading '_'
- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1);
+ e.entry.name.SetString(llvm::StringRef(prefix).drop_front());
}
if (import_name) {
// Skip the leading '_'
@@ -2070,23 +2079,37 @@
const uint8_t childrenCount = data.GetU8(&children_offset);
for (uint8_t i = 0; i < childrenCount; ++i) {
const char *cstr = data.GetCStr(&children_offset);
- if (cstr)
- nameSlices.push_back(llvm::StringRef(cstr));
- else
+ if (!cstr)
return false; // Corrupt data
+ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength)
+ return false; // Corrupt data: implausibly long symbol name.
+ const size_t prevSize = prefix.size();
+ prefix.append(cstr);
lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset);
- if (childNodeOffset) {
- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr,
- nameSlices, resolver_addresses, reexports,
- ext_symbols)) {
- return false;
- }
- }
- nameSlices.pop_back();
+ // A child offset of 0 points back at the root; like any other repeated
+ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt.
+ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr,
+ prefix, resolver_addresses, reexports,
+ ext_symbols, visited_nodes))
+ return false;
+ prefix.resize(prevSize);
}
return true;
}
+static bool ParseTrieEntries(
+ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr,
+ std::set<lldb::addr_t> &resolver_addresses,
+ std::vector<TrieEntryWithOffset> &reexports,
+ std::vector<TrieEntryWithOffset> &ext_symbols) {
+ lldb::offset_t offset = 0;
+ std::set<lldb::offset_t> visited_nodes;
+ std::string prefix;
+ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix,
+ resolver_addresses, reexports, ext_symbols,
+ visited_nodes);
+}
+
static bool
TryParseV2ObjCMetadataSymbol(const char *&symbol_name,
const char *&symbol_name_non_abi_mangled,
@@ -2659,9 +2682,8 @@
lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS;
if (text_segment_sp)
text_segment_file_addr = text_segment_sp->GetFileAddress();
- std::vector<llvm::StringRef> nameSlices;
- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr,
- nameSlices, resolver_addresses, reexport_trie_entries,
+ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr,
+ resolver_addresses, reexport_trie_entries,
external_sym_trie_entries);
}

View File

@@ -77,10 +77,6 @@ stdenv.mkDerivation (
# Fix build with gcc15
# https://github.com/llvm/llvm-project/commit/bb59f04e7e75dcbe39f1bf952304a157f0035314
./lldb-add-include-cstdint.patch
]
++ lib.optionals (lib.versionOlder (lib.versions.major release_version) "23") [
# Backports several fixes to export trie parsing. Otherwise, LLDB crashes when starting a debugging session on macOS 27.
(getVersionFile "lldb/backport-ParseTrieEntries-fixes.patch")
];
nativeBuildInputs = [

View File

@@ -222,14 +222,7 @@ stdenv.mkDerivation (
hash = "sha256-3hkbYPUVRAtWpo5qBmc2jLZLivURMx8T0GQomvNZesc=";
stripLen = 1;
}
)
++ lib.optionals (lib.versionOlder release_version "23") [
# As of macOS 27 (and iOS 27, etc), the Darwin version number is the same as the OS version number.
# This change breaks target parsing because `darwin27` is incorrectly interpreted as macOS 28.
# This patch is a backport of the target parsing changes in LLVM 23, which fixes the problem.
# Hopefully, Apple does not change the version number scheme again any time soon.
(getVersionFile "llvm/backport-darwin-triple-parsing.patch")
];
);
nativeBuildInputs = [
cmake
@@ -304,6 +297,16 @@ stdenv.mkDerivation (
substituteInPlace unittests/Support/VirtualFileSystemTest.cpp \
--replace-fail "PhysicalFileSystemWorkingDirFailure" "DISABLED_PhysicalFileSystemWorkingDirFailure"
''
+
# Fails on macOS ≥ 26 due to the changed OS version scheme.
#
# This was fixed upstream in LLVM 21 with
# 88f041f3e05e26617856cc096d2e2864dfaa1c7b, but it’s too
# painful to backport all the way.
lib.optionalString (lib.versionOlder release_version "21") ''
substituteInPlace unittests/TargetParser/Host.cpp \
--replace-fail "getMacOSHostVersion" "DISABLED_getMacOSHostVersion"
''
+
# This test fails with a `dysmutil` crash; have not yet dug into what's
# going on here (TODO(@rrbutani)).

View File

@@ -20,28 +20,6 @@
path = ../18;
}
];
"lldb/backport-ParseTrieEntries-fixes.patch" = [
{
before = "22";
path = ../18;
}
{
after = "22";
before = "23";
path = ../22;
}
];
"llvm/backport-darwin-triple-parsing.patch" = [
{
after = "18";
before = "21";
path = ../18;
}
{
after = "21";
path = ../21;
}
];
"llvm/gnu-install-dirs.patch" = [
{
after = "23";

View File

@@ -1,39 +0,0 @@
CVE-2026-15534, upstream commit
568e6fd238867bb9e99fa3f47cba3169009239e0.
diff --git a/regexec.c b/regexec.c
index 35a727459c4a..29aa73c13cb9 100644
--- a/regexec.c
+++ b/regexec.c
@@ -9211,7 +9211,8 @@ NULL
reginfo->poscache_iter = reginfo->poscache_maxiter;
}
- if (reginfo->poscache_iter-- == 0) {
+ if (reginfo->poscache_iter == 1) {
+ reginfo->poscache_iter--;
/* initialise cache */
const SSize_t size = (reginfo->poscache_maxiter + 7)/8;
regmatch_info_aux *const aux = reginfo->info_aux;
@@ -9232,11 +9233,10 @@ NULL
);
}
- if (reginfo->poscache_iter < 0) {
+ if (reginfo->poscache_iter == 0) {
/* have we already failed at this position? */
SSize_t offset, mask;
- reginfo->poscache_iter = -1; /* stop eventual underflow */
offset = (FLAGS(scan) & 0xf) - 1
+ (locinput - reginfo->strbeg)
* (FLAGS(scan)>>4);
@@ -9252,6 +9252,8 @@ NULL
ST.cache_offset = offset;
ST.cache_mask = mask;
}
+ else
+ reginfo->poscache_iter--;
}
/* Prefer B over A for minimal matching. */

View File

@@ -1,59 +0,0 @@
CVE-2026-15534, upstream commit
54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.
diff --git a/regexec.c b/regexec.c
index 29aa73c13cb9..66e0c0924059 100644
--- a/regexec.c
+++ b/regexec.c
@@ -9202,22 +9202,27 @@ NULL
if (!reginfo->poscache_maxiter) {
/* start the countdown: Postpone detection until we
* know the match is not *that* much linear. */
- reginfo->poscache_maxiter
- = (reginfo->strend - reginfo->strbeg + 1)
- * (FLAGS(scan)>>4);
- /* possible overflow for long strings and many CURLYX's */
- if (reginfo->poscache_maxiter < 0)
- reginfo->poscache_maxiter = I32_MAX;
- reginfo->poscache_iter = reginfo->poscache_maxiter;
+ STRLEN len = reginfo->strend - reginfo->strbeg;
+ /* number of participating WHILEMs */
+ U8 n = (FLAGS(scan)>>4);
+
+ /* Only do the calculations and enable the cache if it
+ * won't overflow. This test is equivalent to:
+ * ((len + 1) * n + 7) <= max(STRLEN)
+ */
+ if (len < ((~(STRLEN)0) - 7)/n) {
+ reginfo->poscache_maxiter = (len + 1) * n;
+ reginfo->poscache_iter = reginfo->poscache_maxiter;
+ }
}
if (reginfo->poscache_iter == 1) {
reginfo->poscache_iter--;
/* initialise cache */
- const SSize_t size = (reginfo->poscache_maxiter + 7)/8;
+ const STRLEN size = (reginfo->poscache_maxiter + 7)/8;
regmatch_info_aux *const aux = reginfo->info_aux;
if (aux->poscache) {
- if ((SSize_t)reginfo->poscache_size < size) {
+ if (reginfo->poscache_size < size) {
Renew(aux->poscache, size, char);
reginfo->poscache_size = size;
}
diff --git a/regexp.h b/regexp.h
index 057d9ac5011b..d5d40e0a5618 100644
--- a/regexp.h
+++ b/regexp.h
@@ -839,8 +839,8 @@ typedef struct {
char *cutpoint; /* (*COMMIT) position (if any) */
regmatch_info_aux *info_aux; /* extra fields that need cleanup */
regmatch_info_aux_eval *info_aux_eval; /* extra saved state for (?{}) */
- I32 poscache_maxiter; /* how many whilems todo before S-L cache kicks in */
- I32 poscache_iter; /* current countdown from _maxiter to zero */
+ STRLEN poscache_maxiter; /* how many whilems todo before S-L cache kicks in */
+ STRLEN poscache_iter; /* current countdown from _maxiter to zero */
STRLEN poscache_size; /* size of regmatch_info_aux.poscache */
bool intuit; /* re_intuit_start() is the top-level caller */
bool is_utf8_pat; /* regex is utf8 */

View File

@@ -0,0 +1,20 @@
Targeted patch for CVE-2026-8376, based on 5e7f119eb2bb1181be908701f22bf7068e722f1c but avoids changes to t/re/pat_psycho.t as they do not apply cleanly.
diff --git a/regcomp_study.c b/regcomp_study.c
index b513454a4258..1602663f4b26 100644
--- a/regcomp_study.c
+++ b/regcomp_study.c
@@ -2784,6 +2784,13 @@ Perl_study_chunk(pTHX_
(U8 *) SvEND(data->last_found))
- (U8*)s;
l -= old;
+
+ if (l > 0 &&
+ (mincount >= SSize_t_MAX / (SSize_t)l
+ || old > SSize_t_MAX - mincount * (SSize_t)l)) {
+ FAIL("Regexp out of space");
+ }
+
/* Get the added string: */
last_str = newSVpvn_utf8(s + old, l, UTF);
last_chrs = UTF ? utf8_length((U8*)(s + old),

View File

@@ -73,8 +73,8 @@ in
rec {
perl5 = callPackage ./interpreter.nix {
self = perl5;
version = "5.42.3";
sha256 = "sha256-ETd0CYWDe1zfFfDPq5Miedy0NS+RL+1vwUTotPCCNic=";
version = "5.42.0";
sha256 = "sha256-4JPvGE1/mhuXl+JGUpb1VRCtttq4hCsMPtUzKWYwltw=";
inherit passthruFun;
};
}

View File

@@ -37,8 +37,7 @@ let
# Do not look in /usr etc. for dependencies.
./no-sys-dirs.patch
./CVE-2026-15534-1.patch
./CVE-2026-15534-2.patch
./CVE-2026-8376.patch
]
# Fix build on Solaris on x86_64
@@ -84,7 +83,48 @@ let
# Inject fixed CPAN releases for bundled dual-life distributions until the
# next perl maintenance release includes them.
vendoredPerlDistributions = [ ];
vendoredPerlDistributions = [
{
# CVE-2026-7010
path = "cpan/HTTP-Tiny";
src = fetchurl {
url = "mirror://cpan/authors/id/H/HA/HAARG/HTTP-Tiny-0.094.tar.gz";
hash = "sha256-poQemfwbVdFd6VlHzL17dnvsxRxxAhl/qPBE333cB0M=";
};
}
{
# CVE-2026-3381, CVE-2026-4176
path = "cpan/Compress-Raw-Zlib";
src = fetchurl {
url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Zlib-2.222.tar.gz";
hash = "sha256-Hf19URplVifIGBXTDTurwo+luIRV/wP4sECZ3LUShrg=";
};
}
{
# Runtime dependency of IO-Compress 2.220.
path = "cpan/Compress-Raw-Bzip2";
src = fetchurl {
url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Bzip2-2.218.tar.gz";
hash = "sha256-iRU+ai69pSNJSTsHT6S3VJ/x+QU952E8GKXgXFtBX6g=";
};
}
{
# CVE-2026-48962, CVE-2026-48961, CVE-2026-48959
path = "cpan/IO-Compress";
src = fetchurl {
url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz";
hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic=";
};
}
{
# CVE-2026-42496, CVE-2026-42497, CVE-2026-9538
path = "cpan/Archive-Tar";
src = fetchurl {
url = "mirror://cpan/authors/id/B/BI/BINGOS/Archive-Tar-3.12.tar.gz";
hash = "sha256-ARTvObZfSfiWgoOrR3Gdfoj5jXNg/jZJvjMcf1PVgyw=";
};
}
];
replaceVendoredPerlDistributions = lib.concatMapStringsSep "\n" (d: ''
rm -rf ${d.path}
@@ -400,8 +440,6 @@ stdenv.mkDerivation (
# fixes build failure due to missing d_fdopendir/HAS_FDOPENDIR configure option
# https://github.com/arsv/perl-cross/pull/159
./cross-fdopendir.patch
./perl-cross-1.6.4--5.42.3.patch
];
depsBuildBuild = [

View File

@@ -1,86 +0,0 @@
perl-cross 1.6.4 ships no patch set for perl 5.42.3. The perl5-5.42.0 set
applies unchanged, so link it under the name perl-cross looks for. The
links are per-file because `find cnf/diffs/perl5-$version`, which
perl-cross uses to collect them, does not descend into a symlinked
directory.
diff --git a/cnf/diffs/perl5-5.42.3/constant.patch b/cnf/diffs/perl5-5.42.3/constant.patch
new file mode 120000
index 0000000..61f792a
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/constant.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/constant.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/dynaloader.patch b/cnf/diffs/perl5-5.42.3/dynaloader.patch
new file mode 120000
index 0000000..543415e
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/dynaloader.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/dynaloader.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/findext.patch b/cnf/diffs/perl5-5.42.3/findext.patch
new file mode 120000
index 0000000..94ed668
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/findext.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/findext.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/installscripts.patch b/cnf/diffs/perl5-5.42.3/installscripts.patch
new file mode 120000
index 0000000..6f715b4
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/installscripts.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/installscripts.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/liblist.patch b/cnf/diffs/perl5-5.42.3/liblist.patch
new file mode 120000
index 0000000..5037380
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/liblist.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/liblist.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/makemaker.patch b/cnf/diffs/perl5-5.42.3/makemaker.patch
new file mode 120000
index 0000000..cf9fc6c
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/makemaker.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/makemaker.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/posix-makefile.patch b/cnf/diffs/perl5-5.42.3/posix-makefile.patch
new file mode 120000
index 0000000..072ba89
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/posix-makefile.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/posix-makefile.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/test-checkcase.patch b/cnf/diffs/perl5-5.42.3/test-checkcase.patch
new file mode 120000
index 0000000..6ecc9bc
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/test-checkcase.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/test-checkcase.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/test-makemaker.patch b/cnf/diffs/perl5-5.42.3/test-makemaker.patch
new file mode 120000
index 0000000..fc6bcda
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/test-makemaker.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/test-makemaker.patch
\ No newline at end of file
diff --git a/cnf/diffs/perl5-5.42.3/xconfig.patch b/cnf/diffs/perl5-5.42.3/xconfig.patch
new file mode 120000
index 0000000..87ac501
--- /dev/null
+++ b/cnf/diffs/perl5-5.42.3/xconfig.patch
@@ -0,0 +1 @@
+../perl5-5.42.0/xconfig.patch
\ No newline at end of file

File diff suppressed because it is too large Load Diff

View File

@@ -51,7 +51,7 @@
let
version = "2.42";
patchSuffix = "-100";
patchSuffix = "-84";
sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8=";
in
@@ -69,7 +69,7 @@ stdenv.mkDerivation (
/*
No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping.
$ git fetch --all -p && git checkout origin/release/2.42/master && git describe
glibc-2.42-100-gc7169c0684
glibc-2.42-67-g4ebd33dd77
$ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch
To compare the archive contents zdiff can be used.

View File

@@ -1,10 +1,10 @@
{ callPackage, fetchurl }:
callPackage ./generic.nix rec {
version = "1.0.10";
version = "1.0.2";
src = fetchurl {
url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz";
hash = "sha256-BL/o73XbfWKaM952dZl2XOytxWJ0o5gi1dCBAw1XdoU=";
hash = "sha256-3zJPzQg0F12rB0gxM5Atl3SmBb+imAJfaYgyiP0gqMc=";
};
}

View File

@@ -506,8 +506,8 @@ in
};
openssl_3_6 = common {
version = "3.6.5";
hash = "sha256-ohV8KDDv3sN4iTmwDJsGODBtPwu7dtxIMu5QO7OX35g=";
version = "3.6.4";
hash = "sha256-m/+qGtHgezVMIb0zJOwC+hVXn0Wn0ElLPnS8RJtzM+8=";
patches = [
# Support for NIX_SSL_CERT_FILE, motivation:

View File

@@ -0,0 +1,47 @@
From 5592bfb58eb8d1c8a644e67c9bba795d1384a995 Mon Sep 17 00:00:00 2001
From: Marc Lehmann <schmorp@schmorp.de>
Date: Sat, 6 Sep 2025 11:31:36 +0200
Subject: [PATCH 1/2] fix json_atof_scan1 overflows
with fuzzed overlong numbers. CVE-2025-40928
Really the comparisons were wrong.
---
XS.xs | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/XS.xs b/XS.xs
index 9b1ce2b..94ab0d6 100755
--- a/XS.xs
+++ b/XS.xs
@@ -710,16 +710,16 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth)
/* if we recurse too deep, skip all remaining digits */
/* to avoid a stack overflow attack */
if (UNLIKELY(--maxdepth <= 0))
- while (((U8)*s - '0') < 10)
+ while ((U8)(*s - '0') < 10)
++s;
for (;;)
{
- U8 dig = (U8)*s - '0';
+ U8 dig = (U8)(*s - '0');
if (UNLIKELY(dig >= 10))
{
- if (dig == (U8)((U8)'.' - (U8)'0'))
+ if (dig == (U8)('.' - '0'))
{
++s;
json_atof_scan1 (s, accum, expo, 1, maxdepth);
@@ -739,7 +739,7 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth)
else if (*s == '+')
++s;
- while ((dig = (U8)*s - '0') < 10)
+ while ((dig = (U8)(*s - '0')) < 10)
exp2 = exp2 * 10 + *s++ - '0';
*expo += neg ? -exp2 : exp2;
--
2.50.1

View File

@@ -0,0 +1,25 @@
From ca70a73bb147549e62e74751d924b1dbb59d1707 Mon Sep 17 00:00:00 2001
From: Stig Palmquist <stig@stig.io>
Date: Thu, 5 Jun 2025 03:45:50 +0200
Subject: [PATCH] Fix CVE-2011-10007
---
lib/File/Find/Rule.pm | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/lib/File/Find/Rule.pm b/lib/File/Find/Rule.pm
index feccc76..d4dc475 100644
--- a/lib/File/Find/Rule.pm
+++ b/lib/File/Find/Rule.pm
@@ -420,7 +420,7 @@ sub grep {
$self->exec( sub {
local *FILE;
- open FILE, $_ or return;
+ open FILE, '<', $_ or return;
local ($_, $.);
while (<FILE>) {
for my $p (@pattern) {
--
2.49.0

View File

@@ -0,0 +1,31 @@
--- a/XS.xs 2025-09-06 08:34:51.376455632 -0300
+++ b/XS.xs 2025-09-06 08:35:30.725873619 -0300
@@ -253,16 +253,16 @@
// if we recurse too deep, skip all remaining digits
// to avoid a stack overflow attack
if (expect_false (--maxdepth <= 0))
- while (((U8)*s - '0') < 10)
+ while ((U8)(*s - '0') < 10)
++s;
for (;;)
{
- U8 dig = (U8)*s - '0';
+ U8 dig = *s - '0';
if (expect_false (dig >= 10))
{
- if (dig == (U8)((U8)'.' - (U8)'0'))
+ if (dig == (U8)('.' - '0'))
{
++s;
json_atof_scan1 (s, accum, expo, 1, maxdepth);
@@ -282,7 +282,7 @@
else if (*s == '+')
++s;
- while ((dig = (U8)*s - '0') < 10)
+ while ((dig = (U8)(*s - '0')) < 10)
exp2 = exp2 * 10 + *s++ - '0';
*expo += neg ? -exp2 : exp2;

View File

@@ -0,0 +1,242 @@
From bee8338fd1cbd7aad4bf60c2965833343b6ead6f Mon Sep 17 00:00:00 2001
From: Nick Wellnhofer <wellnhofer@aevum.de>
Date: Tue, 21 May 2024 15:17:30 +0200
Subject: [PATCH 1/3] Fix test suite with libxml2 2.13.0
---
t/02parse.t | 7 ++++++-
t/08findnodes.t | 8 +++++++-
t/19die_on_invalid_utf8_rt_58848.t | 2 +-
t/25relaxng.t | 4 ++--
t/26schema.t | 4 ++--
t/60error_prev_chain.t | 8 ++++----
6 files changed, 22 insertions(+), 11 deletions(-)
diff --git a/t/02parse.t b/t/02parse.t
index b111507b..40aa5f13 100644
--- a/t/02parse.t
+++ b/t/02parse.t
@@ -884,7 +884,12 @@ EOXML
eval {
$doc2 = $parser->parse_string( $xmldoc );
};
- isnt($@, '', "error parsing $xmldoc");
+ # https://gitlab.gnome.org/GNOME/libxml2/-/commit/b717abdd
+ if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) {
+ isnt($@, '', "error parsing $xmldoc");
+ } else {
+ is( $doc2->documentElement()->firstChild()->nodeName(), "foo" );
+ }
$parser->validation(1);
diff --git a/t/08findnodes.t b/t/08findnodes.t
index 016c85a1..e9417bc5 100644
--- a/t/08findnodes.t
+++ b/t/08findnodes.t
@@ -123,7 +123,13 @@ my $docstring = q{
my @ns = $root->findnodes('namespace::*');
# TEST
-is(scalar(@ns), 2, ' TODO : Add test name' );
+# https://gitlab.gnome.org/GNOME/libxml2/-/commit/aca16fb3
+# fixed xmlCopyNamespace with XML namespace.
+if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) {
+ is(scalar(@ns), 2, ' TODO : Add test name' );
+} else {
+ is(scalar(@ns), 3, ' TODO : Add test name' );
+}
# bad xpaths
# TEST:$badxpath=4;
diff --git a/t/19die_on_invalid_utf8_rt_58848.t b/t/19die_on_invalid_utf8_rt_58848.t
index aa8ad105..4160cb27 100644
--- a/t/19die_on_invalid_utf8_rt_58848.t
+++ b/t/19die_on_invalid_utf8_rt_58848.t
@@ -16,7 +16,7 @@ use XML::LibXML;
my $err = $@;
# TEST
- like ("$err", qr{parser error : Input is not proper UTF-8},
+ like ("$err", qr{not proper UTF-8|Invalid bytes in character encoding},
'Parser error.',
);
}
diff --git a/t/25relaxng.t b/t/25relaxng.t
index 93e61883..71383b2a 100644
--- a/t/25relaxng.t
+++ b/t/25relaxng.t
@@ -132,7 +132,7 @@ print "# 6 check that no_network => 1 works\n";
{
my $rng = eval { XML::LibXML::RelaxNG->new( location => $netfile, no_network => 1 ) };
# TEST
- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' );
+ like( $@, qr{Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' );
# TEST
ok( !defined $rng, 'RNG from file location with external import and no_network => 1 is not loaded.' );
}
@@ -152,7 +152,7 @@ print "# 6 check that no_network => 1 works\n";
</grammar>
EOF
# TEST
- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' );
+ like( $@, qr{Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' );
# TEST
ok( !defined $rng, 'RNG from buffer with external import and no_network => 1 is not loaded.' );
}
diff --git a/t/26schema.t b/t/26schema.t
index 17f641e4..c404cedd 100644
--- a/t/26schema.t
+++ b/t/26schema.t
@@ -117,7 +117,7 @@ EOF
{
my $schema = eval { XML::LibXML::Schema->new( location => $netfile, no_network => 1 ) };
# TEST
- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' );
+ like( $@, qr{Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' );
# TEST
ok( !defined $schema, 'Schema from file location with external import and no_network => 1 is not loaded.' );
}
@@ -129,7 +129,7 @@ EOF
</xsd:schema>
EOF
# TEST
- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' );
+ like( $@, qr{Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' );
# TEST
ok( !defined $schema, 'Schema from buffer with external import and no_network => 1 is not loaded.' );
}
diff --git a/t/60error_prev_chain.t b/t/60error_prev_chain.t
index e48215c4..55ac0b2e 100644
--- a/t/60error_prev_chain.t
+++ b/t/60error_prev_chain.t
@@ -16,13 +16,11 @@ use XML::LibXML;
{
my $parser = XML::LibXML->new();
- $parser->validation(0);
- $parser->load_ext_dtd(0);
eval
{
local $^W = 0;
- $parser->parse_file('example/JBR-ALLENtrees.htm');
+ $parser->parse_string('<doc>&ldquo;&nbsp;&rdquo;</doc>');
};
my $err = $@;
@@ -31,7 +29,7 @@ use XML::LibXML;
if( $err && !ref($err) ) {
plan skip_all => 'The local libxml library does not support errors as objects to $@';
}
- plan tests => 1;
+ plan tests => 2;
while (defined($err) && $count < 200)
{
@@ -44,6 +42,8 @@ use XML::LibXML;
# TEST
ok ((!$err), "Reached the end of the chain.");
+ # TEST
+ is ($count, 3, "Correct number of errors reported")
}
=head1 COPYRIGHT & LICENSE
From c9f9c2fe51173b0a00969f01b577399f1098aa47 Mon Sep 17 00:00:00 2001
From: Nick Wellnhofer <wellnhofer@aevum.de>
Date: Thu, 13 Feb 2025 19:50:35 +0100
Subject: [PATCH 2/3] Fix test suite with libxml2 2.14.0
---
t/16docnodes.t | 7 ++++++-
t/49_load_html.t | 8 +++++++-
2 files changed, 13 insertions(+), 2 deletions(-)
diff --git a/t/16docnodes.t b/t/16docnodes.t
index db7bc1fc..0b0ae005 100644
--- a/t/16docnodes.t
+++ b/t/16docnodes.t
@@ -60,7 +60,12 @@ for my $time (0 .. 2) {
$doc->setDocumentElement($node);
# TEST
- is( $node->serialize(), '<test contents="&#xE4;"/>', 'Node serialise works.' );
+ # libxml2 2.14 avoids unnecessary escaping of attribute values.
+ if (XML::LibXML::LIBXML_VERSION() >= 21400) {
+ is( $node->serialize(), "<test contents=\"\xE4\"/>", 'Node serialise works.' );
+ } else {
+ is( $node->serialize(), '<test contents="&#xE4;"/>', 'Node serialise works.' );
+ }
$doc->setEncoding('utf-8');
# Second output
diff --git a/t/49_load_html.t b/t/49_load_html.t
index 70d26607..3861edf8 100644
--- a/t/49_load_html.t
+++ b/t/49_load_html.t
@@ -52,7 +52,13 @@ use XML::LibXML;
</div>
EOS
- {
+ SKIP: {
+ # libxml2 2.14 tokenizes HTML according to HTML5 where
+ # this isn't an error, see "13.2.5.73 Named character
+ # reference state".
+ skip("libxml2 version >= 21400", 1)
+ if XML::LibXML::LIBXML_VERSION >= 21400;
+
my $buf = '';
open my $fh, '>', \$buf;
# redirect STDERR there
From ecbebc2f33fecb66b3d5487c6e48bea353e374f9 Mon Sep 17 00:00:00 2001
From: Nick Wellnhofer <wellnhofer@aevum.de>
Date: Fri, 16 May 2025 19:11:12 +0200
Subject: [PATCH 3/3] Remove tests that disable line numbers
Line numbers are always enabled since libxml2 2.15.0.
---
t/02parse.t | 13 ++-----------
1 file changed, 2 insertions(+), 11 deletions(-)
diff --git a/t/02parse.t b/t/02parse.t
index 40aa5f13..17419f8f 100644
--- a/t/02parse.t
+++ b/t/02parse.t
@@ -14,7 +14,7 @@ use locale;
POSIX::setlocale(LC_ALL, "C");
-use Test::More tests => 533;
+use Test::More tests => 531;
use IO::File;
use XML::LibXML::Common qw(:libxml);
@@ -25,7 +25,7 @@ use constant XML_DECL => "<?xml version=\"1.0\"?>\n";
use Errno qw(ENOENT);
-# TEST*533
+# TEST*531
##
# test values
@@ -773,15 +773,6 @@ EOXML
my $newkid = $root->appendChild( $doc->createElement( "bar" ) );
is( $newkid->line_number(), 0, "line number is 0");
-
- $parser->line_numbers(0);
- eval { $doc = $parser->parse_string( $goodxml ); };
-
- $root = $doc->documentElement();
- is( $root->line_number(), 0, "line number is 0");
-
- @kids = $root->childNodes();
- is( $kids[1]->line_number(), 0, "line number is 0");
}
SKIP: {

View File

@@ -1,19 +1,36 @@
Send an ETag header, and honour the If-None-Match request header
--- a/lib/Catalyst/Plugin/Static/Simple.pm
+++ b/lib/Catalyst/Plugin/Static/Simple.pm
@@ -223,6 +223,15 @@
diff -ru -x '*~' Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm
--- Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm 2012-05-04 18:49:30.000000000 +0200
+++ Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm 2013-02-25 22:57:18.667150181 +0100
@@ -187,16 +187,27 @@
my $type = $c->_ext_to_type( $full_path );
my $stat = stat $full_path;
$c->res->headers->header('Cache-Control' => $cache_control);
- $c->res->headers->content_type( $type );
- $c->res->headers->content_length( $stat->size );
- $c->res->headers->last_modified( $stat->mtime );
# Tell Firefox & friends its OK to cache, even over SSL:
- $c->res->headers->header('Cache-control' => 'public');
+ #$c->res->headers->header('Cache-control' => 'public');
+
+ $c->res->headers->last_modified( $stat->mtime );
# Optionally, set a fixed expiry time:
if ($config->{expires}) {
$c->res->headers->expires(time() + $config->{expires});
}
+ if ($config->{send_etag}) {
+ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-' . $stat->size . '"';
+ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-'. $stat->size . '"';
+ $c->res->headers->header('ETag' => $etag);
+ if (($c->req->header('If-None-Match') // "") eq $etag) {
+ $c->res->status(304);
+ return 1;
+ }
+ }
+
+ $c->res->headers->content_type( $type );
+ $c->res->headers->content_length( $stat->size );
+
my $fh = IO::File->new( $full_path, 'r' );
if ( defined $fh ) {

View File

@@ -10,14 +10,14 @@
buildPythonPackage (finalAttrs: {
pname = "gitpython";
version = "3.1.62";
version = "3.1.58";
pyproject = true;
src = fetchFromGitHub {
owner = "gitpython-developers";
repo = "GitPython";
tag = finalAttrs.version;
hash = "sha256-g7qZSFFWAa7iJSn+HAxCTfNZfrYZsZRJGUIZGYQjoUI=";
hash = "sha256-C6hrN7SRWngwkD/NYvsoEVQUagdurkxzWbnn42EJOHE=";
};
postPatch = ''

View File

@@ -11,16 +11,16 @@
oauthlib,
}:
buildPythonPackage (finalAttrs: {
buildPythonPackage rec {
pname = "pyjwt";
version = "2.14.0";
version = "2.13.0";
pyproject = true;
src = fetchFromGitHub {
owner = "jpadilla";
repo = "pyjwt";
tag = finalAttrs.version;
hash = "sha256-SxJ2GQt1pfm8iAeTB2RmH2kliGeQ6whkM5nuesI1s/U=";
tag = version;
hash = "sha256-q4ynXCJVDsyZh70439dloyWgRTLVm+elDOahUVOT5vA=";
};
outputs = [
@@ -38,10 +38,7 @@ buildPythonPackage (finalAttrs: {
optional-dependencies.crypto = [ cryptography ];
nativeCheckInputs = [
pytestCheckHook
]
++ (lib.concatAttrValues finalAttrs.passthru.optional-dependencies);
nativeCheckInputs = [ pytestCheckHook ] ++ (lib.concatAttrValues optional-dependencies);
disabledTests = [
# requires internet connection
@@ -55,10 +52,10 @@ buildPythonPackage (finalAttrs: {
};
meta = {
changelog = "https://github.com/jpadilla/pyjwt/blob/${finalAttrs.src.tag}/CHANGELOG.rst";
changelog = "https://github.com/jpadilla/pyjwt/blob/${version}/CHANGELOG.rst";
description = "JSON Web Token implementation in Python";
homepage = "https://github.com/jpadilla/pyjwt";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ prikhi ];
};
})
}

View File

@@ -14,7 +14,7 @@ Original-Author: Eelco Dolstra <eelco.dolstra@logicblox.com>
2 files changed, 6 insertions(+), 2 deletions(-)
diff --git a/src/shared/fstab-util.c b/src/shared/fstab-util.c
index a4f5e348ab..d506b5598e 100644
index 25e229bf3e..b9af1c3b13 100644
--- a/src/shared/fstab-util.c
+++ b/src/shared/fstab-util.c
@@ -76,6 +76,8 @@ bool fstab_is_extrinsic(const char *mount, const char *opts) {

View File

@@ -35,10 +35,10 @@ index 3a13e04a27..4fd58068a1 100644
<literal>Etc/UTC</literal>. The resulting link should lead to the
corresponding binary
diff --git a/src/basic/time-util.c b/src/basic/time-util.c
index 6873017bf5..7455aa30ae 100644
index 5dd00af952..b97a41f6ac 100644
--- a/src/basic/time-util.c
+++ b/src/basic/time-util.c
@@ -1446,7 +1446,7 @@ static int get_timezones_from_zone1970_tab(char ***ret) {
@@ -1443,7 +1443,7 @@ static int get_timezones_from_zone1970_tab(char ***ret) {
assert(ret);
@@ -47,7 +47,7 @@ index 6873017bf5..7455aa30ae 100644
if (!f)
return -errno;
@@ -1491,7 +1491,7 @@ static int get_timezones_from_tzdata_zi(char ***ret) {
@@ -1488,7 +1488,7 @@ static int get_timezones_from_tzdata_zi(char ***ret) {
assert(ret);
@@ -56,7 +56,7 @@ index 6873017bf5..7455aa30ae 100644
if (!f)
return -errno;
@@ -1606,7 +1606,7 @@ int verify_timezone(const char *name, int log_level) {
@@ -1603,7 +1603,7 @@ int verify_timezone(const char *name, int log_level) {
if (p - name >= PATH_MAX)
return -ENAMETOOLONG;
@@ -65,7 +65,7 @@ index 6873017bf5..7455aa30ae 100644
fd = open(t, O_RDONLY|O_CLOEXEC);
if (fd < 0)
@@ -1678,7 +1678,7 @@ int get_timezone(char **ret) {
@@ -1675,7 +1675,7 @@ int get_timezone(char **ret) {
if (r < 0)
return r; /* Return EINVAL if not a symlink */
@@ -75,7 +75,7 @@ index 6873017bf5..7455aa30ae 100644
return -EINVAL;
if (!timezone_is_valid(e, LOG_DEBUG))
diff --git a/src/firstboot/firstboot.c b/src/firstboot/firstboot.c
index ba96a749c6..f64e22faf1 100644
index ae1899593c..20d3071114 100644
--- a/src/firstboot/firstboot.c
+++ b/src/firstboot/firstboot.c
@@ -584,7 +584,7 @@ static int prompt_timezone(int rfd, sd_varlink **mute_console_link) {
@@ -103,7 +103,7 @@ index ba96a749c6..f64e22faf1 100644
return log_error_errno(r, "Failed to create /etc/localtime symlink: %m");
diff --git a/src/nspawn/nspawn.c b/src/nspawn/nspawn.c
index d9bde47c8e..8c32e3ae99 100644
index 84e94e845a..8e1f1a6ea2 100644
--- a/src/nspawn/nspawn.c
+++ b/src/nspawn/nspawn.c
@@ -1856,8 +1856,8 @@ int userns_mkdir(const char *root, const char *path, mode_t mode, uid_t uid, gid
@@ -118,7 +118,7 @@ index d9bde47c8e..8c32e3ae99 100644
static bool etc_writable(void) {
diff --git a/src/timedate/timedated.c b/src/timedate/timedated.c
index 5478666ca0..7e2ea196f5 100644
index 43cf3fddb9..dc23550500 100644
--- a/src/timedate/timedated.c
+++ b/src/timedate/timedated.c
@@ -268,7 +268,7 @@ static int context_read_data(Context *c) {

View File

@@ -201,13 +201,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
inherit pname;
version = "260.5";
version = "260.4";
src = fetchFromGitHub {
owner = "systemd";
repo = "systemd";
rev = "v${finalAttrs.version}";
hash = "sha256-QLQad4pKkaf99k+ABOaooKi5TSX0iHH9XtMn/fy1rfE=";
hash = "sha256-n+wzn+1W82YooRxzIEJHm4CsVPFBGlQUIy9TatxlbaU=";
};
# PATCH POLICY

View File

@@ -86,8 +86,8 @@ stdenv.mkDerivation rec {
freepgPatches = fetchFromGitLab {
owner = "freepg";
repo = "gnupg";
tag = "source-2.4.9-freepg-1";
hash = "sha256-hoSuIrq7Epco1LLlc77tGr/YZdp2w04Eq0rGbBCurWU=";
tag = "source-2.4.9-freepg";
hash = "sha256-wF+iR0OgnU8VI90NlFOXtN5aCRC0YY/X7sPiDXjJm5M=";
};
patches = [
@@ -128,15 +128,6 @@ stdenv.mkDerivation rec {
"0033-Support-large-RSA-keygen-in-non-batch-mode.patch"
"0034-gpg-Verify-Text-mode-Signatures-over-binary-Literal-.patch"
"0039-gpg-Do-not-use-a-default-when-asking-for-another-out.patch"
"0040-Add-missing-test-files-to-EXTRA_DIST.patch"
"0045-gpg-Fix-edge-case-in-refresh-keys.patch"
"0046-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch"
"0047-gpg-Fix-handling-with-no-CRC-armor.patch"
"0048-gpg-Fix-armored-input-parsing.patch"
"0049-gpg-Fix-armor-parsing-when-no-CRC-is-found.patch"
"0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch"
"0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch"
"0052-dirmngr-Fix-a-call-of-calloc.patch"
];
postPatch =

View File

@@ -116,11 +116,11 @@ with self;
ack = buildPerlPackage rec {
pname = "ack";
version = "3.10.0";
version = "3.9.0";
src = fetchurl {
url = "mirror://cpan/authors/id/P/PE/PETDANCE/ack-v${version}.tar.gz";
hash = "sha256-Zeg8+zinH8pyXpoUqCAe6HHmKfxrECMeEwPdNQG6Vjo=";
hash = "sha256-lO1Hfjs/lNEmzscynw6DmfHQzoLHxNiCqUrbFQ5//JA=";
};
outputs = [
@@ -2096,10 +2096,10 @@ with self;
AuthenSASL = buildPerlPackage {
pname = "Authen-SASL";
version = "2.2100";
version = "2.1900";
src = fetchurl {
url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.2100.tar.gz";
hash = "sha256-Tw8QCu7TS1KXepS335c+fwuPktFnsJ8rJJurgehZDlc=";
url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.1900.tar.gz";
hash = "sha256-vjUzpokbLmdxULR5waDUvxHIu+6+0+e466NAU+k5I7A=";
};
propagatedBuildInputs = [
CryptURandom
@@ -3352,11 +3352,18 @@ with self;
CatalystAuthenticationCredentialHTTP = buildPerlModule {
pname = "Catalyst-Authentication-Credential-HTTP";
version = "1.019";
version = "1.018";
src = fetchurl {
url = "mirror://cpan/authors/id/A/AB/ABRAXXA/Catalyst-Authentication-Credential-HTTP-1.019.tar.gz";
hash = "sha256-7IHpbCo/ZYbqQdCI6o6AGx80ABqxnMmmXe+KOMOaW9o=";
url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Authentication-Credential-HTTP-1.018.tar.gz";
hash = "sha256-b6GBbe5kSw216gzBXF5xHcLO0gg2JavOcJZSHx1lpSk=";
};
patches = [
(fetchpatch {
name = "CVE-2025-40920.patch";
url = "https://github.com/perl-catalyst/Catalyst-Authentication-Credential-HTTP/commit/ad2c03aad95406db4ce35dfb670664ebde004c18.patch";
hash = "sha256-WI6JwvY6i3KkQO9HbbSvHPX8mgM8I2cF0UTjF1D14T4=";
})
];
buildInputs = [
ModuleBuildTiny
TestException
@@ -3367,6 +3374,7 @@ with self;
CatalystPluginAuthentication
ClassAccessor
CryptSysRandom
DataUUID
StringEscape
];
meta = {
@@ -4108,19 +4116,12 @@ with self;
CatalystPluginStaticSimple = buildPerlPackage {
pname = "Catalyst-Plugin-Static-Simple";
version = "0.38";
version = "0.37";
src = fetchurl {
url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Plugin-Static-Simple-0.38.tar.gz";
hash = "sha256-BOtn69x4cyf3fvLHOXar7Pk/mu/KCnGFIv6YuMpSOLA=";
url = "mirror://cpan/authors/id/I/IL/ILMARI/Catalyst-Plugin-Static-Simple-0.37.tar.gz";
hash = "sha256-Wk2Fo1iM1Og/GwAlgUEufXG31X9mBW5dh6Nvk9icnnw=";
};
patches = [
(fetchpatch {
url = "https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch";
hash = "sha256-dNJOz7X7i03kisrf+lhqAaL6lYeTlt1NJZnJWNM7bgQ=";
})
../development/perl-modules/catalyst-plugin-static-simple-etag.patch
];
postPatch = "rm -f lib/Catalyst/Plugin/Static/Simple.pm.orig";
patches = [ ../development/perl-modules/catalyst-plugin-static-simple-etag.patch ];
propagatedBuildInputs = [
CatalystRuntime
MIMETypes
@@ -4626,15 +4627,12 @@ with self;
CGISession = buildPerlModule {
pname = "CGI-Session";
version = "4.49";
version = "4.48";
src = fetchurl {
url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.49.tar.gz";
hash = "sha256-X9iKgwo19UUmeH8DauXkp9FLYcQUzSmthjG/RuaXEgc=";
url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.48.tar.gz";
hash = "sha256-RnVkYcJM52ZrgQjduW26thJpnfMBLIDvEQFmGf4VVPc=";
};
propagatedBuildInputs = [
CGI
CryptSysRandom
];
propagatedBuildInputs = [ CGI ];
meta = {
description = "Persistent session data in CGI applications";
license = with lib.licenses; [ artistic1 ];
@@ -5094,22 +5092,6 @@ with self;
};
};
ClassErrorHandler = buildPerlPackage {
pname = "Class-ErrorHandler";
version = "0.04";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TO/TOKUHIROM/Class-ErrorHandler-0.04.tar.gz";
hash = "sha256-NC0tz8eXogvugXmxuWuFwK56W0iCc1lSPNjHTD5wRQI=";
};
meta = {
description = "Base class for error handling";
license = with lib.licenses; [
artistic1
gpl1Plus
];
};
};
ClassInspector = buildPerlPackage {
pname = "Class-Inspector";
version = "1.36";
@@ -6063,10 +6045,10 @@ with self;
ConfigIniFiles = buildPerlPackage {
pname = "Config-IniFiles";
version = "3.002000";
version = "3.000003";
src = fetchurl {
url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.002000.tar.gz";
hash = "sha256-Bmke17QZl+hQxOfGs05cOWFF4M0FCvGUSiDQaMOlpAs=";
url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.000003.tar.gz";
hash = "sha256-PEV7ZdmOX/QL25z4FLDVmD6wxT+4aWvaO6A1rSrNaAI=";
};
propagatedBuildInputs = [ IOStringy ];
meta = {
@@ -6415,29 +6397,6 @@ with self;
};
};
ConvertPEM = buildPerlPackage {
pname = "Convert-PEM";
version = "0.13";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Convert-PEM-0.13.tar.gz";
hash = "sha256-eZ+jLCcAgfTmKSsN31GAlScQqKS+Ey6Qe9oxdqe9HCM=";
};
buildInputs = [ TestException ];
propagatedBuildInputs = [
ClassErrorHandler
ConvertASN1
CryptDESEDE3
CryptX
];
meta = {
description = "Read/write encrypted ASN.1 PEM files";
license = with lib.licenses; [
artistic1
gpl1Plus
];
};
};
ConvertUU = buildPerlPackage {
pname = "Convert-UU";
version = "0.5201";
@@ -6521,10 +6480,10 @@ with self;
CookieBaker = buildPerlModule {
pname = "Cookie-Baker";
version = "0.12";
version = "0.11";
src = fetchurl {
url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.12.tar.gz";
hash = "sha256-mwTfXUfc1FrEKZYmoQ7JkPtAyU7lpjAMOoi9+zV17Ck=";
url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.11.tar.gz";
hash = "sha256-WSdfR04HwKo2EePmhLiU59uRMzPYIUQgvmPxLsGM16s=";
};
buildInputs = [
ModuleBuildTiny
@@ -6732,11 +6691,12 @@ with self;
CpanelJSONXS = buildPerlPackage {
pname = "Cpanel-JSON-XS";
version = "4.42";
version = "4.37";
src = fetchurl {
url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.42.tar.gz";
hash = "sha256-4awvqx46bS2ZjTRAxgAGc2W9x9vwyPKyBZy85LTIMXM=";
url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.37.tar.gz";
hash = "sha256-wkFhWg4X/3Raqoa79Gam4pzSQFFeZfBqegUBe2GebUs=";
};
patches = [ ../development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch ];
meta = {
description = "CPanel fork of JSON::XS, fast and correct serializing";
license = with lib.licenses; [
@@ -6930,15 +6890,13 @@ with self;
CryptArgon2 = buildPerlModule {
pname = "Crypt-Argon2";
version = "0.031";
version = "0.019";
src = fetchurl {
url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.031.tar.gz";
hash = "sha256-1l5RoZQ+6AglEkUNw1KuUpUQZswJI/u38uYK+l8WTi0=";
url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.019.tar.gz";
hash = "sha256-+Fm+6NL2tAf11EZFwiOu4hL+AFkd/YLlBlrhvnio5Dg=";
};
nativeBuildInputs = [ pkgs.ld-is-cc-hook ];
buildInputs = [ DistBuild ];
meta = {
changelog = "https://github.com/Leont/crypt-argon2/blob/v0.031/Changes";
description = "Perl interface to the Argon2 key derivation functions";
license = with lib.licenses; [ cc0 ];
};
@@ -6992,16 +6950,11 @@ with self;
CryptCBC = buildPerlPackage {
pname = "Crypt-CBC";
version = "3.07";
version = "2.33";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-CBC-3.07.tar.gz";
hash = "sha256-9N37TdasUBPfg0G/pzTZye4PEOLnEhXsj+W/eAt8kSc=";
url = "mirror://cpan/authors/id/L/LD/LDS/Crypt-CBC-2.33.tar.gz";
hash = "sha256-anDeIbbMfysQAGfo4Yjblm6agAG122+pdufLWylK5kU=";
};
propagatedBuildInputs = [
CryptPBKDF2
CryptURandom
CryptX
];
meta = {
description = "Encrypt Data with Cipher Block Chaining Mode";
license = with lib.licenses; [
@@ -7064,23 +7017,6 @@ with self;
};
};
CryptDESEDE3 = buildPerlPackage {
pname = "Crypt-DES_EDE3";
version = "0.03";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DES_EDE3-0.03.tar.gz";
hash = "sha256-KFktt7njR0WqkfPhnl27uDqvRyop5we5eR0NArPiJ/U=";
};
propagatedBuildInputs = [ CryptDES ];
meta = {
description = "Triple-DES EDE encryption/decryption";
license = with lib.licenses; [
artistic1
gpl1Plus
];
};
};
CryptDH = buildPerlPackage {
pname = "Crypt-DH";
version = "0.07";
@@ -7123,16 +7059,14 @@ with self;
CryptDSA = buildPerlPackage {
pname = "Crypt-DSA";
version = "1.24";
version = "1.17";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DSA-1.24.tar.gz";
hash = "sha256-ChY4tvK07+ktbuL0kBzKAtenBWf2uw9Iapu19pvnZ2Y=";
url = "mirror://cpan/authors/id/A/AD/ADAMK/Crypt-DSA-1.17.tar.gz";
hash = "sha256-0bhYX2v3RvduXcXaNkHTJe1la8Ll80S1RRS1XDEAmgM=";
};
propagatedBuildInputs = [
ConvertASN1
ConvertPEM
CryptSysRandom
DataBuffer
DigestSHA1
FileWhich
];
meta = {
@@ -7326,12 +7260,11 @@ with self;
CryptPasswdMD5 = buildPerlPackage {
pname = "Crypt-PasswdMD5";
version = "1.43";
version = "1.42";
src = fetchurl {
url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.43.tgz";
hash = "sha256-Qr+Sk0UQlYXUlWkCVX7ONdBh7aQ454lPhucHV0EoB1k=";
url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.42.tgz";
hash = "sha256-/Tlubn9E7rkj6TyZOUC49nqa7Vb8dKrK8Dj8QFPvO1k=";
};
propagatedBuildInputs = [ CryptURandom ];
meta = {
description = "Provide interoperable MD5-based crypt() functions";
license = with lib.licenses; [
@@ -7562,32 +7495,14 @@ with self;
};
};
CryptURandomMonkeyPatch = buildPerlPackage {
pname = "Crypt-URandom-MonkeyPatch";
version = "0.1.4";
src = fetchurl {
url = "mirror://cpan/authors/id/R/RR/RRWO/Crypt-URandom-MonkeyPatch-v0.1.4.tar.gz";
hash = "sha256-eydufcxL7TnZW/+dnTemlTkycVaPTarMrFBowLQcKsk=";
};
buildInputs = [ TestOutput ];
propagatedBuildInputs = [ CryptURandom ];
meta = {
description = "Override core rand function to use system random sources";
license = lib.licenses.artistic2;
};
};
CryptScryptKDF = buildPerlModule {
pname = "Crypt-ScryptKDF";
version = "0.011";
version = "0.010";
src = fetchurl {
url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.011.tar.gz";
hash = "sha256-IZLJ8E8rX/cHN/XNrz9PZ6VXE8MeoIVAOMvzXjttFrQ=";
url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.010.tar.gz";
hash = "sha256-fRbulczj61TBdGc6cpn0wIb7o6yF+EfQ4TT+7V93YBc=";
};
propagatedBuildInputs = [
CryptOpenSSLRandom
CryptX
];
propagatedBuildInputs = [ CryptOpenSSLRandom ];
meta = {
description = "Scrypt password based key derivation function";
homepage = "https://github.com/DCIT/perl-Crypt-ScryptKDF";
@@ -7833,19 +7748,15 @@ with self;
};
};
CryptPBKDF2 = buildPerlModule {
CryptPBKDF2 = buildPerlPackage {
pname = "Crypt-PBKDF2";
version = "0.261630";
version = "0.161520";
src = fetchurl {
url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.261630.tar.gz";
hash = "sha256-GHVxiWOJMrMJs0xFu4EKo+SFbj7VgBAAF9reZXk/RsA=";
url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.161520.tar.gz";
hash = "sha256-l9+nmjCaCG4YSk5hBH+KEP+z2wUQJefSIqJfGRMLpBc=";
};
buildInputs = [
ModuleBuildTiny
TestFatal
];
buildInputs = [ TestFatal ];
propagatedBuildInputs = [
CryptURandom
DigestHMAC
DigestSHA3
Moo
@@ -7985,10 +7896,10 @@ with self;
CSSMinifierXS = buildPerlPackage {
pname = "CSS-Minifier-XS";
version = "0.15";
version = "0.13";
src = fetchurl {
url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.15.tar.gz";
hash = "sha256-iprSIxYtpGceP4EsSlXyl3OUg70xar2kH0wn6K3XhVM=";
url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.13.tar.gz";
hash = "sha256-xBnjCM3IKvHCXWuNB7L/JjR6Yit6Y+wghWq+jbQFH4I=";
};
buildInputs = [ TestDiagINC ];
meta = {
@@ -8246,16 +8157,16 @@ with self;
DataEntropy = buildPerlPackage {
pname = "Data-Entropy";
version = "0.010";
version = "0.008";
src = fetchurl {
url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.010.tar.gz";
hash = "sha256-0M8s2wKCAuidw2K42Qtw00WFApOwGQDZoYgqDG8g+Dc=";
url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.008.tar.gz";
hash = "sha256-GKUrE4boLGuM2zhKOYYdYCIKRCp5DgdwEL5y3YU7Z7M=";
};
propagatedBuildInputs = [
CryptRijndael
CryptURandom
DataFloat
DevelDeprecate
HTTPLite
ParamsClassify
];
meta = {
@@ -9693,24 +9604,6 @@ with self;
};
};
DevelDeprecate = buildPerlPackage {
pname = "Devel-Deprecate";
version = "0.01";
src = fetchurl {
url = "mirror://cpan/authors/id/O/OV/OVID/Devel-Deprecate-0.01.tar.gz";
hash = "sha256-xQLEGoL+JU6XFRJ3ytOk8KQHrTydP2I9J3sDA6PhoS8=";
};
buildInputs = [ SubOverride ];
propagatedBuildInputs = [ DateTime ];
meta = {
description = "Create deprecation schedules in your code";
license = with lib.licenses; [
artistic1
gpl1Plus
];
};
};
DevelDeprecationsEnvironmental = buildPerlPackage {
pname = "Devel-Deprecations-Environmental";
version = "1.101";
@@ -10151,11 +10044,11 @@ with self;
DBI = buildPerlPackage {
pname = "DBI";
version = "1.653";
version = "1.648";
src = fetchurl {
url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.653.tgz";
hash = "sha256-qYwh/Tfu2PhBFyh10XXZcv6H8GPX0NKjt3ZZCLsl61g=";
url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.648.tgz";
hash = "sha256-7yZqrWAQzi6rt+Rl69c8owILxYFQ9pib2Jwrj5usaoY=";
};
env = lib.optionalAttrs stdenv.cc.isGNU {
@@ -11143,31 +11036,6 @@ with self;
};
};
DistBuild = buildPerlModule {
pname = "Dist-Build";
version = "0.028";
src = fetchurl {
url = "mirror://cpan/authors/id/L/LE/LEONT/Dist-Build-0.028.tar.gz";
hash = "sha256-JPFLFA4Tq3x1PU25bI0zbQnepcb1H+1IvA92Khyhgx8=";
};
propagatedBuildInputs = [
ExtUtilsBuilder
ExtUtilsBuilderCompiler
ExtUtilsConfig
ExtUtilsHelpers
ExtUtilsInstallPaths
];
meta = {
changelog = "https://github.com/Leont/dist-build/blob/v0.028/Changes";
description = "Modern module builder, author tools not included";
homepage = "https://github.com/Leont/dist-build";
license = with lib.licenses; [
artistic1
gpl1Plus
];
};
};
DistributionMetadata = buildPerlModule {
pname = "Distribution-Metadata";
version = "0.10";
@@ -12716,48 +12584,6 @@ with self;
};
};
ExtUtilsBuilder = buildPerlPackage {
pname = "ExtUtils-Builder";
version = "0.020";
src = fetchurl {
url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-0.020.tar.gz";
hash = "sha256-UtZR46oDJyUOR5h9Rf9I6cyQtbe9L7D/P3h4PlMq/8w=";
};
propagatedBuildInputs = [
ExtUtilsConfig
ExtUtilsHelpers
];
meta = {
description = "Abstract representation of build processes";
homepage = "https://github.com/Leont/extutils-builder-plan";
license = with lib.licenses; [
artistic1
gpl1Plus
];
};
};
ExtUtilsBuilderCompiler = buildPerlPackage {
pname = "ExtUtils-Builder-Compiler";
version = "0.037";
src = fetchurl {
url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-Compiler-0.037.tar.gz";
hash = "sha256-s5VNaI45gDkoUnkWfG6+7nVX8Q6VYBzj/baBkyY2h7g=";
};
propagatedBuildInputs = [
ExtUtilsBuilder
ExtUtilsConfig
];
meta = {
description = "Interface around different compilers";
homepage = "https://github.com/Leont/extutils-builder-compiler";
license = with lib.licenses; [
artistic1
gpl1Plus
];
};
};
ExtUtilsCChecker = buildPerlModule {
pname = "ExtUtils-CChecker";
version = "0.11";
@@ -12777,10 +12603,10 @@ with self;
ExtUtilsConfig = buildPerlPackage {
pname = "ExtUtils-Config";
version = "0.010";
version = "0.008";
src = fetchurl {
url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.010.tar.gz";
hash = "sha256-gufk6Qy+OA4VL13m4+QDdGmC1QLdMBl6EjZS5GYQxm0=";
url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.008.tar.gz";
hash = "sha256-rlEE9jRlDc6KebftE/tZ1no5whOmd2z9qj7nSeYvGow=";
};
meta = {
description = "Wrapper for perl's configuration";
@@ -12868,10 +12694,10 @@ with self;
ExtUtilsHelpers = buildPerlPackage {
pname = "ExtUtils-Helpers";
version = "0.028";
version = "0.026";
src = fetchurl {
url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.028.tar.gz";
hash = "sha256-yFdIdczgc+fcU0WnsG1QLlIETWiJT5FgID/KqzeVFP4=";
url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.026.tar.gz";
hash = "sha256-3pAbZ5CkVXz07JCBSeA1eDsSW/EV65ZA/rG8HCTDNBY=";
};
meta = {
description = "Various portability utilities for module builders";
@@ -13652,11 +13478,14 @@ with self;
FileFindRule = buildPerlPackage {
pname = "File-Find-Rule";
version = "0.35";
version = "0.34";
src = fetchurl {
url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.35.tar.gz";
hash = "sha256-K9VWKJptRK0u50gDJYuwsAUNJG8egcqrCyY8MDrPDII=";
url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.34.tar.gz";
hash = "sha256-fm8WzDPrHyn/Jb7lHVE/S4qElHu/oY7bLTzECi1kyv4=";
};
patches = [
../development/perl-modules/FileFindRule-CVE-2011-10007.patch
];
propagatedBuildInputs = [
NumberCompare
TextGlob
@@ -14838,10 +14667,10 @@ with self;
GD = buildPerlPackage {
pname = "GD";
version = "2.86";
version = "2.78";
src = fetchurl {
url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.86.tar.gz";
hash = "sha256-bWTTvhQpzB606IqPICL+yRDqPgeS2k/ljT7fdpXEbKI=";
url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.78.tar.gz";
hash = "sha256-aDEFS/VCS09cI9NifT0UhEgPb5wsZmMiIpFfKFG+buQ=";
};
nativeBuildInputs = [
@@ -14856,7 +14685,6 @@ with self;
pkgs.fontconfig
pkgs.libxpm
ExtUtilsPkgConfig
FileWhich
TestFork
TestNoWarnings
];
@@ -14911,16 +14739,7 @@ with self;
url = "mirror://cpan/authors/id/B/BU/BURAK/GD-SecurityImage-1.75.tar.gz";
hash = "sha256-Pd4k2ay6lRzd5bVp0eQsrZRs/bUSgORGnzNv1f4MjqY=";
};
patches = [
(fetchpatch {
url = "https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch";
hash = "sha256-xIMPQD2JYuHdsYnW1ojqG3xgV7VWEKyJ6sEqNRUdNdQ=";
})
];
propagatedBuildInputs = [
CryptURandomMonkeyPatch
GD
];
propagatedBuildInputs = [ GD ];
meta = {
description = "Security image (captcha) generator";
license = with lib.licenses; [
@@ -16320,12 +16139,6 @@ with self;
url = "mirror://cpan/authors/id/C/CF/CFRANKS/HTML-FormFu-2.07.tar.gz";
hash = "sha256-Ty8Bf3qHVPu26RIGyI7RPHVqFOO+oXgYjDuXdGNm6zI=";
};
patches = [
(fetchpatch {
url = "https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch";
hash = "sha256-1QquxDl/NuNJe6MFbeEH49hYA8agXXeWm1Q23fOM+Nc=";
})
];
buildInputs = [
CGI
FileShareDirInstall
@@ -16387,18 +16200,19 @@ with self;
HTMLFormHandler = buildPerlPackage {
pname = "HTML-FormHandler";
version = "0.410002";
version = "0.40068";
src = fetchurl {
url = "mirror://cpan/authors/id/A/AB/ABRAXXA/HTML-FormHandler-0.410002.tar.gz";
hash = "sha256-wT3n5PLDmV5QR1xilSm2VM+eLGJ73WLifqSMfG1jqeU=";
url = "mirror://cpan/authors/id/G/GS/GSHANK/HTML-FormHandler-0.40068.tar.gz";
hash = "sha256-63t43aMSV1LMi8wDltOXf70o2jPS1ExQQq1tNdbN6Cc=";
};
# a single test is failing on perl 5.20
doCheck = false;
buildInputs = [
FileShareDirInstall
PadWalker
TestDifferences
TestException
TestMemoryCycle
TestNeeds
TestWarn
];
propagatedBuildInputs = [
@@ -16425,10 +16239,10 @@ with self;
HTMLGumbo = buildPerlModule {
pname = "HTML-Gumbo";
version = "0.20";
version = "0.18";
src = fetchurl {
url = "mirror://cpan/authors/id/B/BP/BPS/HTML-Gumbo-0.20.tar.gz";
hash = "sha256-ImEK+8bIfgZ92E9/EZo9J4Ie1kEwNFU8Ga694iEdiDU=";
url = "mirror://cpan/authors/id/R/RU/RUZ/HTML-Gumbo-0.18.tar.gz";
hash = "sha256-v1C2HCRlbMP8lYYC2AqcfQFyR6842Nv6Dp3sW3VCXV8=";
};
propagatedBuildInputs = [ AlienLibGumbo ];
meta = {
@@ -16489,10 +16303,10 @@ with self;
HTMLParser = buildPerlPackage {
pname = "HTML-Parser";
version = "3.85";
version = "3.81";
src = fetchurl {
url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.85.tar.gz";
hash = "sha256-/UK6ar4HJBzwrVe+JGw5gAZfaD5EZeWbRq+e/ryODHE=";
url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.81.tar.gz";
hash = "sha256-wJEKXI+S+IF+3QbM/SJLocLr6MEPVR8DJYeh/IPWL/I=";
};
propagatedBuildInputs = [
HTMLTagset
@@ -16957,10 +16771,10 @@ with self;
HTTPDate = buildPerlPackage {
pname = "HTTP-Date";
version = "6.08";
version = "6.06";
src = fetchurl {
url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.08.tar.gz";
hash = "sha256-tX2Aym2CHGlJykiydGfUWrp6nHc0ZWIwb6zKeBoAPkQ=";
url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.06.tar.gz";
hash = "sha256-e2hRkcasw+dz0fwCyV7h+frpT3d4MXX154wYHMktK1I=";
};
propagatedBuildInputs = [ TimeDate ];
meta = {
@@ -17087,10 +16901,10 @@ with self;
HTTPMessage = buildPerlPackage {
pname = "HTTP-Message";
version = "7.02";
version = "6.45";
src = fetchurl {
url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-7.02.tar.gz";
hash = "sha256-eKvvHYMxRrSNF9shmxsD1Ty743oozNrQ79zFgzylxgw=";
url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-6.45.tar.gz";
hash = "sha256-AcuEBmEqP3OIQtHpcxOuTYdIcNG41tZjMfFgAJQ9TL4=";
};
buildInputs = [
TestNeeds
@@ -17098,11 +16912,8 @@ with self;
];
propagatedBuildInputs = [
Clone
CompressRawBzip2
CompressRawZlib
EncodeLocale
HTTPDate
IOCompress
IOHTML
LWPMediaTypes
URI
@@ -17387,11 +17198,26 @@ with self;
Imager = buildPerlPackage rec {
pname = "Imager";
version = "1.035";
version = "1.034";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TO/TONYC/Imager-${version}.tar.gz";
hash = "sha256-W6BYrMmLtb+QK6/XTNKwepS7GVrmYWxEC1RwFIBv6xc=";
hash = "sha256-hrWizXGna4QJJJFSGl1WI4Qo8sN1AYMsmVxaMxJg+AM=";
};
# Remove when updating to the first release containing both fixes.
patches = [
(fetchpatch2 {
name = "fix-32-bit-exif-ifd-offset-checks.patch";
url = "https://github.com/tonycoz/imager/commit/48ba8ac0749f89466b6e6681fb88cbdb51086ebd.patch?full_index=1";
includes = [ "imexif.c" ];
hash = "sha256-rpUeTsgSkCdzJsy3Ny0rU+KNL6xkSosfkDqzFb813Wo=";
})
(fetchpatch2 {
name = "fix-32-bit-exif-limit-checks.patch";
url = "https://github.com/tonycoz/imager/commit/6f1fd003a8e48c7e6e58b7019a04cc71bbfec2c3.patch?full_index=1";
includes = [ "imexif.c" ];
hash = "sha256-Ct7T/JHuxAIAjjuzoUhdAPlp0qPYKRQQqejsrcGXPko=";
})
];
buildInputs = [
pkgs.freetype
pkgs.fontconfig
@@ -17753,10 +17579,10 @@ with self;
IOCompress = buildPerlPackage {
pname = "IO-Compress";
version = "2.221";
version = "2.220";
src = fetchurl {
url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.221.tar.gz";
hash = "sha256-r0LJyRBK3313LSVcDZpASjRi6kXnvELQbaCgtR3j0K4=";
url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz";
hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic=";
};
propagatedBuildInputs = [
CompressRawBzip2
@@ -18678,11 +18504,12 @@ with self;
JSONXS = buildPerlPackage {
pname = "JSON-XS";
version = "4.04";
version = "4.03";
src = fetchurl {
url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.04.tar.gz";
hash = "sha256-jv8enzBMViW1mre0IlhBX20+NoHB3atrclUYoBin9eA=";
url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.03.tar.gz";
hash = "sha256-UVU29F8voafojIgkUzdY0BIdJnq5y0U6G1iHyKVrkGg=";
};
patches = [ ../development/perl-modules/JSON-XS-CVE-2025-40928.patch ];
propagatedBuildInputs = [ TypesSerialiser ];
buildInputs = [ CanaryStability ];
meta = {
@@ -18990,10 +18817,10 @@ with self;
libwwwperl = buildPerlPackage {
pname = "libwww-perl";
version = "6.83";
version = "6.72";
src = fetchurl {
url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz";
hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU=";
url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz";
hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0=";
};
buildInputs = [
HTTPDaemon
@@ -20247,10 +20074,10 @@ with self;
LWP = buildPerlPackage {
pname = "libwww-perl";
version = "6.83";
version = "6.72";
src = fetchurl {
url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz";
hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU=";
url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz";
hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0=";
};
propagatedBuildInputs = [
FileListing
@@ -22878,10 +22705,10 @@ with self;
Mojolicious = buildPerlPackage {
pname = "Mojolicious";
version = "9.48";
version = "9.39";
src = fetchurl {
url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.48.tar.gz";
hash = "sha256-Jv8EFSgR/VsaNrR9mewhnFiZW6jnsVugKzPQdwpe7pg=";
url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.39.tar.gz";
hash = "sha256-EwpJDXfXYTn3NM4biU1Fm64DgF+x89/dWPxE/oKvPP0=";
};
meta = {
description = "Real-time web framework";
@@ -23243,16 +23070,13 @@ with self;
MojoJWT = buildPerlModule {
pname = "Mojo-JWT";
version = "1.02";
version = "0.09";
src = fetchurl {
url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-1.02.tar.gz";
hash = "sha256-yBHXkoWMJBFQNyDxJDbjNDZ0k2dUO/vCqV1PgDzmCHQ=";
url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-0.09.tar.gz";
hash = "sha256-wE4DmD4MbyvORdCOoucph5yWee+mNLDmjLa4t7SoWIY=";
};
buildInputs = [ ModuleBuildTiny ];
propagatedBuildInputs = [
CryptX
Mojolicious
];
propagatedBuildInputs = [ Mojolicious ];
meta = {
description = "JSON Web Token the Mojo way";
homepage = "https://github.com/jberger/Mojo-JWT";
@@ -25705,10 +25529,10 @@ with self;
NetDNS = buildPerlPackage {
pname = "Net-DNS";
version = "1.57";
version = "1.56";
src = fetchurl {
url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.57.tar.gz";
hash = "sha256-fJjeMpy11qmau7A6qtKGbLBBCS7Zk2pyRpCOFwAFsFg=";
url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.56.tar.gz";
hash = "sha256-WTDjn3aJWzgMfKEfwINS0VrXHEH+hMEt+2oyLRf2aUY=";
};
propagatedBuildInputs = [ DigestHMAC ];
makeMakerFlags = [ "--noonline-tests" ];
@@ -26580,10 +26404,10 @@ with self;
NetStatsd = buildPerlPackage {
pname = "Net-Statsd";
version = "0.13";
version = "0.12";
src = fetchurl {
url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.13.tar.gz";
hash = "sha256-xKYP9dP002ompqR3YxGI7HnNzp4wUMZ6NOm1rikgoQA=";
url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.12.tar.gz";
hash = "sha256-Y+RTYD2hZbxtHEygtV7aPSIE8EDFkwSkd4LFqniGVlw=";
};
meta = {
description = "Perl client for Etsy's statsd daemon";
@@ -28753,13 +28577,12 @@ with self;
PlackMiddlewareSession = buildPerlModule {
pname = "Plack-Middleware-Session";
version = "0.36";
version = "0.33";
src = fetchurl {
url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.36.tar.gz";
hash = "sha256-kqWDFliBDSNzLm47rnpEofpafYpqbm3NdbkcapwktGY=";
url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.33.tar.gz";
hash = "sha256-T/miydGK2ASbRd/ze5vdQSIeLC8eFrr7gb/tyIxRpO4=";
};
propagatedBuildInputs = [
CryptSysRandom
DigestHMAC
Plack
];
@@ -29314,10 +29137,10 @@ with self;
ProtocolHTTP2 = buildPerlModule {
pname = "Protocol-HTTP2";
version = "1.14";
version = "1.11";
src = fetchurl {
url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.14.tar.gz";
hash = "sha256-pT8n6i+6wVakzUmB2O90nBvvNmwpCRNLTTHaIWRLSW4=";
url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.11.tar.gz";
hash = "sha256-Vp8Fsavpl7UHyCUVMMyB0e6WvZMsxoJTS2zkhlNQCRM=";
};
buildInputs = [
AnyEvent
@@ -30758,10 +30581,10 @@ with self;
SerealDecoder = buildPerlPackage {
pname = "Sereal-Decoder";
version = "5.006";
version = "5.004";
src = fetchurl {
url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.006.tar.gz";
hash = "sha256-eZGFXpGBo3nJsBIv6PwvaONEnJFhaow1eSbxFh9oR2g=";
url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.004.tar.gz";
hash = "sha256-aO8DFNh9Gm5guw9m/PQ+ssrN6xdUQy9eJeeE450+Z4Q=";
};
buildInputs = [
TestDeep
@@ -30783,10 +30606,10 @@ with self;
SerealEncoder = buildPerlPackage {
pname = "Sereal-Encoder";
version = "5.006";
version = "5.004";
src = fetchurl {
url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.006.tar.gz";
hash = "sha256-kLQsyHdZgq4MdJno9ZLOeu+ug0M1g+EKWtVxKBHRcK0=";
url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.004.tar.gz";
hash = "sha256-XlqGzNMtrjTtgJMuy+XGjil1K13g6bCnk6t+sspVyxs=";
};
buildInputs = [
SerealDecoder
@@ -30808,10 +30631,10 @@ with self;
Sereal = buildPerlPackage {
pname = "Sereal";
version = "5.006";
version = "5.004";
src = fetchurl {
url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.006.tar.gz";
hash = "sha256-uwXnY+1ry+pEx5IX/vCy05GKwVRxlHIwOMbER+5vWd4=";
url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.004.tar.gz";
hash = "sha256-nCW7euS9c20ksa0dk9dzlbDGXKh0HiZr/Ay+VCJh128=";
};
buildInputs = [
TestDeep
@@ -31585,10 +31408,10 @@ with self;
Starlet = buildPerlPackage {
pname = "Starlet";
version = "0.32";
version = "0.31";
src = fetchurl {
url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.32.tar.gz";
hash = "sha256-gZI9OmCX3YHH4Og9SBvuof89ZejgHY0f59yziFV1vY8=";
url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.31.tar.gz";
hash = "sha256-uWA7jmKIDLRYL2p5Oer+xl5u/T2QDyx900Ll9MaNYtg=";
};
buildInputs = [
LWP
@@ -32209,13 +32032,14 @@ with self;
};
};
StringUtil = buildPerlPackage {
StringUtil = buildPerlModule {
pname = "String-Util";
version = "1.36";
version = "1.34";
src = fetchurl {
url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.36.tar.gz";
hash = "sha256-UXsasyVm/U1ei+I9mTOc47/+4pEsX/KfXclYcP9Pyw4=";
url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.34.tar.gz";
hash = "sha256-MZzozWZTQeVlIfoVXZYqGTKOkNn3A2dlklzN4mclxGk=";
};
buildInputs = [ ModuleBuildTiny ];
meta = {
description = "String processing utility functions";
homepage = "https://github.com/scottchiefbaker/String-Util";
@@ -38968,10 +38792,10 @@ with self;
XMLLibXML = buildPerlPackage {
pname = "XML-LibXML";
version = "2.0213";
version = "2.0210";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TO/TODDR/XML-LibXML-2.0213.tar.gz";
hash = "sha256-KvIcXWGsNOompfq/FbpaWEHmSPcYnbPjO28otUiYAqs=";
url = "mirror://cpan/authors/id/S/SH/SHLOMIF/XML-LibXML-2.0210.tar.gz";
hash = "sha256-opvz8Aq5ye4EIYFU4K/I95m/I2dOuZwantTeH0BZpI0=";
};
env.SKIP_SAX_INSTALL = 1;
buildInputs = [
@@ -38985,6 +38809,10 @@ with self;
zlib
]
);
patches = [
# https://github.com/shlomif/perl-XML-LibXML/pull/87
../development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch
];
propagatedBuildInputs = [ XMLSAX ];
meta = {
description = "Perl Binding for libxml2";
@@ -39368,10 +39196,10 @@ with self;
XMLTwig = buildPerlPackage {
pname = "XML-Twig";
version = "3.54";
version = "3.52";
src = fetchurl {
url = "mirror://cpan/authors/id/M/MI/MIROD/XML-Twig-3.54.tar.gz";
hash = "sha256-C3RKlzegcPlcMhVK/VJr9evnaln+uLwfXbxs2qXg5Sk=";
url = "mirror://cpan/authors/id/M/MI/MIROD/XML-Twig-3.52.tar.gz";
hash = "sha256-/vdYJsJPK4d9Cg0mRSEvxPuXVu1NJxFhSsFcSX6GgK0=";
};
postInstall = ''
mkdir -p $out/bin
@@ -39579,12 +39407,11 @@ with self;
YAMLLibYAML = buildPerlPackage {
pname = "YAML-LibYAML";
version = "0.907.0";
version = "0.89";
src = fetchurl {
url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-v0.907.0.tar.gz";
hash = "sha256-a6CHIkkROJ52+hmLFJzsg/BlsKx13cUmGPNJCULNlQY=";
url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-0.89.tar.gz";
hash = "sha256-FVq4NnU0XFCt0DMRrPndkVlVcH+Qmiq9ixfXeShZsuw=";
};
buildInputs = [ TestWarnings ];
meta = {
description = "Perl YAML Serialization using XS and libyaml";
license = with lib.licenses; [
@@ -39630,11 +39457,6 @@ with self;
MojoliciousPluginOpenAPI
RoleTiny
];
# Mojolicious 9.48 enforces CSRF token validation (CVE-2026-15747); these
# tests drive forms without a token and fail with 400 "CSRF token failure".
preCheck = ''
rm t/plugin/auth/github.t t/plugin/form/bootstrap4.t
'';
meta = {
homepage = "http://preaction.me/yancy/";
description = "Best Web Framework Deserves the Best CMS";