From 66ceda2405a2d473840cd71b539d1a65b5c9aa91 Mon Sep 17 00:00:00 2001 From: Fernando Rodrigues Date: Mon, 12 May 2025 22:25:54 -0300 Subject: [PATCH] xen: remove now-unused secondary function header The old `buildXenPackage` builder was a curried function that had to be completed with a second call with attributes like `pname` and `version`. As it is no longer necessary to call a generic builder to build custom variants of Xen, the package must comply with the `by-name` checks, which include the requirement that all `package.nix` files in this directory hierarchy resolve to a derivation. (and not a function) Signed-off-by: Fernando Rodrigues --- pkgs/by-name/xe/xen/package.nix | 120 ++++++++++++++++++++------------ 1 file changed, 77 insertions(+), 43 deletions(-) diff --git a/pkgs/by-name/xe/xen/package.nix b/pkgs/by-name/xe/xen/package.nix index dd3a16de26ce..ff9e59346a5d 100644 --- a/pkgs/by-name/xe/xen/package.nix +++ b/pkgs/by-name/xe/xen/package.nix @@ -1,17 +1,17 @@ { lib, stdenv, - autoPatchelfHook, - cmake, - pkg-config, testers, - which, fetchgit, + fetchpatch, # Xen acpica-tools, + autoPatchelfHook, + binutils-unwrapped-all-targets, bison, bzip2, + cmake, dev86, e2fsprogs, flex, @@ -21,6 +21,7 @@ ncurses, ocamlPackages, perl, + pkg-config, python3Packages, systemdMinimal, xz, @@ -29,12 +30,14 @@ zstd, # Optional Components - seabios-qemu, - systemSeaBIOS ? seabios-qemu, - OVMF, - ipxe, + withFlask ? false, checkpolicy, - binutils-unwrapped-all-targets, + withIPXE ? true, + ipxe, + withOVMF ? true, + OVMF, + withSeaBIOS ? true, + seabios-qemu, # Documentation pandoc, @@ -53,22 +56,7 @@ nbd, openvswitch, util-linux, -}: - -{ - pname, - branch ? lib.versions.majorMinor version, - version, - vendor ? "nixos", - upstreamVersion ? version, - withFlask ? false, - withSeaBIOS ? true, - withOVMF ? true, - withIPXE ? true, - rev, - hash, - patches ? [ ], - meta ? { }, + which, }: let @@ -77,12 +65,12 @@ let getExe' licenses makeSearchPathOutput - optional optionalString optionals systems teams versionOlder + versions warn ; inherit (systems.inspect.patterns) isLinux isAarch64; @@ -117,7 +105,50 @@ let in stdenv.mkDerivation (finalAttrs: { - inherit pname version patches; + pname = "xen"; + version = "4.20.0"; + + # This attribute can be overriden to correct the file paths in + # `passthru` when building an unstable Xen. + upstreamVersion = finalAttrs.version; + # Useful for further identifying downstream Xen variants. (i.e. Qubes) + vendor = "nixos"; + + patches = [ + # XSA #469 + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-01.patch"; + hash = "sha256-go743oBhYDuxsK0Xc6nK/WxutQQwc2ERtLKhCU9Dnng="; + }) + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-02.patch"; + hash = "sha256-FTtEGAPFYxsun38hLhVMKJ1TFJOsTMK3WWPkO0R/OHg=sha256-FTtEGAPFYxsun38hLhVMKJ1TFJOsTMK3WWPkO0R/OHg="; + }) + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-03.patch"; + hash = "sha256-UkYMSpUgFvr4GJPXLgQsCyppGkNbeiFMyCZORK5tfmA="; + }) + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-04.patch"; + hash = "sha256-lpiDPSHi+v2VfaWE9kp4+hveZKTzojD1F+RHsOtKE3A="; + }) + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-05.patch"; + hash = "sha256-N+WR8S5w9dLISlOhMI71TOH8jvCgVAR8xm310k3ZA/M="; + }) + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-06.patch"; + hash = "sha256-ePuyB3VP9NfQbW36BP3jjMMHKJWFJGeTYUYZqy+IlHQ="; + }) + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-07.patch"; + hash = "sha256-+BsCJa01R2lrbu7tEluGrYSAqu2jJcrpFNUoLMY466c="; + }) + (fetchpatch { + url = "https://xenbits.xenproject.org/xsa/xsa470.patch"; + hash = "sha256-zhMZ6pCZtt0ocgsMFVqthMaof46lMMTaYmlepMXVJqM="; + }) + ]; outputs = [ "out" @@ -129,7 +160,8 @@ stdenv.mkDerivation (finalAttrs: { src = fetchgit { url = "https://xenbits.xenproject.org/git-http/xen.git"; - inherit rev hash; + rev = "3ad5d648cda5add395f49fc3704b2552aae734f7"; + hash = "sha256-v2DRJv+1bym8zAgU74lo1HQ/9rUcyK3qc4Eec4RpcEY="; }; nativeBuildInputs = [ @@ -166,14 +198,14 @@ stdenv.mkDerivation (finalAttrs: { # Python Fixes python3Packages.wrapPython ] - ++ optional withFlask checkpolicy - ++ optional (versionOlder version "4.19") systemdMinimal; + ++ optionals withFlask [ checkpolicy ] + ++ optionals (versionOlder finalAttrs.version "4.19") [ systemdMinimal ]; configureFlags = [ "--enable-systemd" "--disable-qemu-traditional" "--with-system-qemu" - (if withSeaBIOS then "--with-system-seabios=${systemSeaBIOS.firmware}" else "--disable-seabios") + (if withSeaBIOS then "--with-system-seabios=${seabios-qemu.firmware}" else "--disable-seabios") (if withOVMF then "--with-system-ovmf=${OVMF.mergedFirmware}" else "--disable-ovmf") (if withIPXE then "--with-system-ipxe=${ipxe.firmware}" else "--disable-ipxe") (enableFeature withFlask "xsmpolicy") @@ -186,12 +218,12 @@ stdenv.mkDerivation (finalAttrs: { "PREFIX=$(out)" "BASH_COMPLETION_DIR=$(PREFIX)/share/bash-completion/completions" - "XEN_WHOAMI=${pname}" - "XEN_DOMAIN=${vendor}" + "XEN_WHOAMI=${finalAttrs.pname}" + "XEN_DOMAIN=${finalAttrs.vendor}" "GIT=${coreutils}/bin/false" "WGET=${coreutils}/bin/false" - "EFI_VENDOR=${vendor}" + "EFI_VENDOR=${finalAttrs.vendor}" "INSTALL_EFI_STRIP=1" "LD=${getExe' binutils-unwrapped-all-targets "ld"}" ] @@ -295,10 +327,10 @@ stdenv.mkDerivation (finalAttrs: { ''; passthru = { - efi = "boot/xen-${upstreamVersion}.efi"; + efi = "boot/xen-${finalAttrs.upstreamVersion}.efi"; flaskPolicy = if withFlask then - warn "This Xen was compiled with FLASK support, but the FLASK file does not match the Xen version number. Please hardcode the path to the FLASK file instead." "boot/xenpolicy-${version}" + warn "This Xen was compiled with FLASK support, but the FLASK file may not match the Xen version number. Please hardcode the path to the FLASK file instead." "boot/xenpolicy-${finalAttrs.upstreamVersion}" else throw "This Xen was compiled without FLASK support."; # This test suite is very simple, as Xen's userspace @@ -328,7 +360,7 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { - inherit branch; + branch = versions.majorMinor finalAttrs.version; description = "Type-1 hypervisor intended for embedded and hyperscale use cases"; longDescription = @@ -342,15 +374,15 @@ stdenv.mkDerivation (finalAttrs: { Use with the `qemu_xen` package. '' - + "\nIncludes:\n* `xen.efi`: The Xen Project's [EFI binary](https://xenbits.xenproject.org/docs/${branch}-testing/misc/efi.html), available on the `boot` output of this package." - + optionalString withFlask "\n* `xsm-flask`: The [FLASK Xen Security Module](https://wiki.xenproject.org/wiki/Xen_Security_Modules_:_XSM-FLASK). The `xenpolicy-${upstreamVersion}` file is available on the `boot` output of this package." + + "\nIncludes:\n* `xen.efi`: The Xen Project's [EFI binary](https://xenbits.xenproject.org/docs/${finalAttrs.meta.branch}-testing/misc/efi.html), available on the `boot` output of this package." + + optionalString withFlask "\n* `xsm-flask`: The [FLASK Xen Security Module](https://wiki.xenproject.org/wiki/Xen_Security_Modules_:_XSM-FLASK). The `xenpolicy` file is available on the `boot` output of this package." + optionalString withSeaBIOS "\n* `seabios`: Support for the SeaBIOS boot firmware on HVM domains." + optionalString withOVMF "\n* `ovmf`: Support for the OVMF UEFI boot firmware on HVM domains." + optionalString withIPXE "\n* `ipxe`: Support for the iPXE boot firmware on HVM domains."; homepage = "https://xenproject.org/"; - downloadPage = "https://downloads.xenproject.org/release/xen/${version}/"; - changelog = "https://wiki.xenproject.org/wiki/Xen_Project_${branch}_Release_Notes"; + downloadPage = "https://downloads.xenproject.org/release/xen/${finalAttrs.version}/"; + changelog = "https://wiki.xenproject.org/wiki/Xen_Project_${finalAttrs.meta.branch}_Release_Notes"; license = [ # Documentation. @@ -364,11 +396,13 @@ stdenv.mkDerivation (finalAttrs: { ]; teams = [ teams.xen ]; - knownVulnerabilities = optional (versionOlder version minSupportedVersion) "The Xen Project Hypervisor version ${version} is no longer supported by the Xen Project Security Team. See https://xenbits.xenproject.org/docs/unstable/support-matrix.html"; + knownVulnerabilities = optionals (versionOlder finalAttrs.version minSupportedVersion) [ + "The Xen Project Hypervisor version ${finalAttrs.version} is no longer supported by the Xen Project Security Team. See https://xenbits.xenproject.org/docs/unstable/support-matrix.html" + ]; mainProgram = "xl"; platforms = [ isLinux ]; badPlatforms = [ isAarch64 ]; - } // meta; + }; })