mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-08-31 12:44:44 +00:00
Update discourse to latest(ish) ESR version from previous, soon-to-be unsupported, ESR version. Upstream changes: https://releases.discourse.org/changelog/custom?end=v2026.7.0&start=v2026.1.4 Changes: - simple version / dep updates of all plugins and discourse itself - updated the update script to correctly handle changes to discourses's architecture, and fixed a bug - the NamedTemporaryFiles were not flush()ed, which meant their content was not written - discourse now has dependencies under `migrations/` which are specified by path. this requires downloading the `migrations/` directory during the update so `bundle lock` / `bundix` run successfully. the logic for performing this was borrowed from the gitlab package. - the hashes for the newly added dart-sass download are automatically updated - updated some patches to match changes in the targeted code (notification_email, prebuild-asset-processor) - delete a no longer relevant patch (unicorn_logging_and_timeout) (discourse no longer uses unicorn internally, although the external interface is similar / pretends to still exist) - added two new patches, safe-exec-from-nix-store and sass_embedded_vendored_dart_sass - safe-exec-from-nix-store: add /nix/store to the list of executable paths for the container used to sandbox imagemagick, which by default only contains the standard FHS paths - sass_embedded_vendored_dart_sass: patch sass-embedded to use a version of dart-sass provided by the package instead of downloading it's own which would fail. this patch also involves code in default.nix which sets DART_SASS_VENDORED to the path of a downloaded dart-sass version - updated the comment on prebuild-asset-processor.patch to more accurately reflect what and why it exists
14 lines
485 B
Diff
14 lines
485 B
Diff
diff --git a/lib/discourse/safe_exec.rb b/lib/discourse/safe_exec.rb
|
|
index c4b8a5e3ecb..31d6f0d469d 100644
|
|
--- a/lib/discourse/safe_exec.rb
|
|
+++ b/lib/discourse/safe_exec.rb
|
|
@@ -5,7 +5,7 @@ require "landlock"
|
|
module Discourse
|
|
class SafeExec
|
|
DEFAULT_READ_PATHS = %w[/bin /etc /lib /lib64 /usr].freeze
|
|
- DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr].freeze
|
|
+ DEFAULT_EXECUTE_PATHS = %w[/bin /lib /lib64 /usr /nix/store].freeze
|
|
|
|
def self.capture(
|
|
*command,
|