From a25f777e1a81a3ba90c1152a79fc3f84b41a452e Mon Sep 17 00:00:00 2001 From: TomaSajt <62384384+TomaSajt@users.noreply.github.com> Date: Sun, 15 Sep 2024 23:49:23 +0200 Subject: [PATCH 01/49] ember-cli: remove mkYarnPackage usage --- pkgs/by-name/em/ember-cli/package.json | 182 ------------------------- pkgs/by-name/em/ember-cli/package.nix | 32 +++-- 2 files changed, 20 insertions(+), 194 deletions(-) delete mode 100644 pkgs/by-name/em/ember-cli/package.json diff --git a/pkgs/by-name/em/ember-cli/package.json b/pkgs/by-name/em/ember-cli/package.json deleted file mode 100644 index 48cd3aa8543b..000000000000 --- a/pkgs/by-name/em/ember-cli/package.json +++ /dev/null @@ -1,182 +0,0 @@ -{ - "name": "ember-cli", - "version": "5.3.0", - "description": "Command line tool for developing ambitious ember.js apps", - "keywords": [ - "app", - "app-kit", - "blockchain", - "cli", - "ember", - "ember-app-kit", - "ember.js", - "kit" - ], - "homepage": "https://cli.emberjs.com/release/", - "bugs": { - "url": "https://github.com/ember-cli/ember-cli/issues" - }, - "repository": { - "type": "git", - "url": "https://github.com/ember-cli/ember-cli.git" - }, - "license": "MIT", - "author": "Stefan Penner, Robert Jackson and ember-cli contributors", - "main": "lib/cli/index.js", - "bin": { - "ember": "./bin/ember" - }, - "scripts": { - "docs": "yuidoc", - "lint": "eslint . --cache", - "prepack": "yarn docs", - "test": "node --unhandled-rejections=strict tests/runner", - "test:all": "node --unhandled-rejections=strict tests/runner all", - "test:cover": "nyc --all --reporter=text --reporter=lcov node tests/runner all", - "test:debug": "node --unhandled-rejections=strict debug tests/runner", - "test:slow": "node --unhandled-rejections=strict tests/runner slow" - }, - "dependencies": { - "@babel/core": "^7.22.10", - "@pnpm/find-workspace-dir": "^6.0.2", - "broccoli": "^3.5.2", - "broccoli-builder": "^0.18.14", - "broccoli-concat": "^4.2.5", - "broccoli-config-loader": "^1.0.1", - "broccoli-config-replace": "^1.1.2", - "broccoli-debug": "^0.6.5", - "broccoli-funnel": "^3.0.8", - "broccoli-funnel-reducer": "^1.0.0", - "broccoli-merge-trees": "^4.2.0", - "broccoli-middleware": "^2.1.1", - "broccoli-slow-trees": "^3.1.0", - "broccoli-source": "^3.0.1", - "broccoli-stew": "^3.0.0", - "calculate-cache-key-for-tree": "^2.0.0", - "capture-exit": "^2.0.0", - "chalk": "^4.1.2", - "ci-info": "^3.8.0", - "clean-base-url": "^1.0.0", - "compression": "^1.7.4", - "configstore": "^5.0.1", - "console-ui": "^3.1.2", - "core-object": "^3.1.5", - "dag-map": "^2.0.2", - "diff": "^5.1.0", - "ember-cli-is-package-missing": "^1.0.0", - "ember-cli-lodash-subset": "^2.0.1", - "ember-cli-normalize-entity-name": "^1.0.0", - "ember-cli-preprocess-registry": "^5.0.1", - "ember-cli-string-utils": "^1.1.0", - "ensure-posix-path": "^1.1.1", - "execa": "^5.1.1", - "exit": "^0.1.2", - "express": "^4.18.1", - "filesize": "^10.0.8", - "find-up": "^5.0.0", - "find-yarn-workspace-root": "^2.0.0", - "fixturify-project": "^2.1.1", - "fs-extra": "^11.1.1", - "fs-tree-diff": "^2.0.1", - "get-caller-file": "^2.0.5", - "git-repo-info": "^2.1.1", - "glob": "^8.1.0", - "heimdalljs": "^0.2.6", - "heimdalljs-fs-monitor": "^1.1.1", - "heimdalljs-graph": "^1.0.0", - "heimdalljs-logger": "^0.1.10", - "http-proxy": "^1.18.1", - "inflection": "^2.0.1", - "inquirer": "^9.1.5", - "is-git-url": "^1.0.0", - "is-language-code": "^3.1.0", - "isbinaryfile": "^5.0.0", - "leek": "0.0.24", - "lodash.template": "^4.5.0", - "markdown-it": "^13.0.1", - "markdown-it-terminal": "^0.4.0", - "minimatch": "^7.4.3", - "morgan": "^1.10.0", - "nopt": "^3.0.6", - "npm-package-arg": "^10.1.0", - "os-locale": "^5.0.0", - "p-defer": "^3.0.0", - "portfinder": "^1.0.32", - "promise-map-series": "^0.3.0", - "promise.hash.helper": "^1.0.8", - "quick-temp": "^0.1.8", - "remove-types": "^1.0.0", - "resolve": "^1.22.1", - "resolve-package-path": "^4.0.3", - "safe-stable-stringify": "^2.4.3", - "sane": "^5.0.1", - "semver": "^7.3.5", - "silent-error": "^1.1.1", - "sort-package-json": "^1.57.0", - "symlink-or-copy": "^1.3.1", - "temp": "0.9.4", - "testem": "^3.10.1", - "tiny-lr": "^2.0.0", - "tree-sync": "^2.1.0", - "uuid": "^9.0.0", - "walk-sync": "^3.0.0", - "watch-detector": "^1.0.2", - "workerpool": "^6.4.0", - "yam": "^1.0.0" - }, - "devDependencies": { - "@octokit/rest": "^19.0.7", - "broccoli-plugin": "^4.0.3", - "broccoli-test-helper": "^2.0.0", - "chai": "^4.3.7", - "chai-as-promised": "^7.1.1", - "chai-files": "^1.4.0", - "chai-jest-snapshot": "^2.0.0", - "ember-cli-blueprint-test-helpers": "^0.19.2", - "ember-cli-internal-test-helpers": "^0.9.1", - "eslint": "^8.44.0", - "eslint-config-prettier": "^8.9.0", - "eslint-plugin-chai-expect": "^3.0.0", - "eslint-plugin-mocha": "^10.1.0", - "eslint-plugin-n": "^16.0.1", - "eslint-plugin-prettier": "^4.2.1", - "fixturify": "^3.0.0", - "jsdom": "^21.1.1", - "latest-version": "^5.1.0", - "mocha": "^10.0.0", - "nock": "^13.3.0", - "nyc": "^15.1.0", - "prettier": "2.8.7", - "release-it": "^15.10.0", - "rimraf": "^3.0.2", - "strip-ansi": "^6.0.0", - "supertest": "^6.3.1", - "testdouble": "^3.18.0", - "tmp": "^0.2.1", - "websocket": "^1.0.32", - "which": "3.0.1", - "yuidoc-ember-cli-theme": "^1.0.4", - "yuidocjs": "0.10.2" - }, - "engines": { - "node": ">= 16" - }, - "publishConfig": { - "registry": "https://registry.npmjs.org" - }, - "release-it": { - "git": { - "tagName": "v${version}" - }, - "github": { - "draft": true, - "release": true, - "tokenRef": "GITHUB_AUTH" - } - }, - "trackingCode": "UA-49225444-1", - "volta": { - "node": "16.19.1", - "yarn": "1.22.19" - } -} diff --git a/pkgs/by-name/em/ember-cli/package.nix b/pkgs/by-name/em/ember-cli/package.nix index 86f627be950e..a80a6e56ae78 100644 --- a/pkgs/by-name/em/ember-cli/package.nix +++ b/pkgs/by-name/em/ember-cli/package.nix @@ -1,28 +1,36 @@ -{ lib -, mkYarnPackage -, fetchFromGitHub -, fetchYarnDeps +{ + lib, + stdenvNoCC, + fetchFromGitHub, + fetchYarnDeps, + yarnConfigHook, + yarnInstallHook, + nodejs, }: -let +stdenvNoCC.mkDerivation (finalAttrs: { pname = "ember-cli"; version = "5.3.0"; + src = fetchFromGitHub { owner = "ember-cli"; repo = "ember-cli"; - rev = "v${version}"; + rev = "refs/tags/v${finalAttrs.version}"; hash = "sha256-xkMsPE+iweIV14m4kE4ytEp4uHMJW6gr+n9oJblr4VQ="; }; -in -mkYarnPackage { - inherit pname version src; offlineCache = fetchYarnDeps { - yarnLock = src + "/yarn.lock"; + yarnLock = finalAttrs.src + "/yarn.lock"; hash = "sha256-QgT2JFvMupJo+pJc13n2lmHMZkROJRJWoozCho3E6+c="; }; - packageJSON = ./package.json; + strictDeps = true; + + nativeBuildInputs = [ + yarnConfigHook + yarnInstallHook + nodejs + ]; meta = with lib; { homepage = "https://github.com/ember-cli/ember-cli"; @@ -32,4 +40,4 @@ mkYarnPackage { platforms = platforms.all; mainProgram = "ember"; }; -} +}) From c274e99d107ba9898f2a448abb3a62bc3535ac39 Mon Sep 17 00:00:00 2001 From: detroyejr Date: Sat, 26 Oct 2024 08:55:00 -0400 Subject: [PATCH 02/49] quarto: 1.5.57 -> 1.6.30 --- pkgs/development/libraries/quarto/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/quarto/default.nix b/pkgs/development/libraries/quarto/default.nix index a3a633af6c94..dd5375ef8d56 100644 --- a/pkgs/development/libraries/quarto/default.nix +++ b/pkgs/development/libraries/quarto/default.nix @@ -19,10 +19,10 @@ stdenv.mkDerivation (final: { pname = "quarto"; - version = "1.5.57"; + version = "1.6.30"; src = fetchurl { url = "https://github.com/quarto-dev/quarto-cli/releases/download/v${final.version}/quarto-${final.version}-linux-amd64.tar.gz"; - sha256 = "sha256-ZBjv/Z98il8EMZe88fMKSi1YjeOZ8jEh7OxYDKUTMpY="; + sha256 = "sha256-2gzpQbaFLUox4EMo8RO3bwVjhsm239w5hv4Z0UuS1Qs="; }; nativeBuildInputs = [ From 2a4e508391370a42c6d8ce765189c1cfa8b63814 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 1 Nov 2024 04:21:44 +0000 Subject: [PATCH 03/49] python312Packages.deezer-python: 7.0.0 -> 7.1.0 --- pkgs/development/python-modules/deezer-python/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/deezer-python/default.nix b/pkgs/development/python-modules/deezer-python/default.nix index e0b4b3907c37..2525ab15f0fd 100644 --- a/pkgs/development/python-modules/deezer-python/default.nix +++ b/pkgs/development/python-modules/deezer-python/default.nix @@ -14,7 +14,7 @@ buildPythonPackage rec { pname = "deezer-python"; - version = "7.0.0"; + version = "7.1.0"; pyproject = true; disabled = pythonOlder "3.8"; @@ -23,7 +23,7 @@ buildPythonPackage rec { owner = "browniebroke"; repo = "deezer-python"; rev = "refs/tags/v${version}"; - hash = "sha256-V4M6qRTa7XKbl962Z3y70+v3YCeW65VjeSIv/1Oxnws="; + hash = "sha256-d+cN6f6jw8D+noxyYl/TpDAkeTb8Krt+r0/Ai65cvdU="; }; postPatch = '' From b84994641ebb112bd9544d012fa98044312d511c Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 1 Nov 2024 08:40:54 +0100 Subject: [PATCH 04/49] python312Packages.deezer-python: switch to pytest-cov-stub - update disabled --- .../development/python-modules/deezer-python/default.nix | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/pkgs/development/python-modules/deezer-python/default.nix b/pkgs/development/python-modules/deezer-python/default.nix index 2525ab15f0fd..2bd84de62eb2 100644 --- a/pkgs/development/python-modules/deezer-python/default.nix +++ b/pkgs/development/python-modules/deezer-python/default.nix @@ -5,6 +5,7 @@ fetchFromGitHub, httpx, poetry-core, + pytest-cov-stub, pytest-mock, pytest-vcr, pytestCheckHook, @@ -17,7 +18,7 @@ buildPythonPackage rec { version = "7.1.0"; pyproject = true; - disabled = pythonOlder "3.8"; + disabled = pythonOlder "3.9"; src = fetchFromGitHub { owner = "browniebroke"; @@ -26,11 +27,6 @@ buildPythonPackage rec { hash = "sha256-d+cN6f6jw8D+noxyYl/TpDAkeTb8Krt+r0/Ai65cvdU="; }; - postPatch = '' - substituteInPlace pyproject.toml \ - --replace-fail " --cov=deezer" "" - ''; - build-system = [ poetry-core ]; dependencies = [ @@ -40,6 +36,7 @@ buildPythonPackage rec { nativeCheckInputs = [ environs + pytest-cov-stub pytest-mock pytest-vcr pytestCheckHook From 181dcac3b989492305934b2607532c72794d71bc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 10:57:24 +0100 Subject: [PATCH 05/49] Revert "nix: fix macOS sandbox escape via builtin builders" This reverts commit 727b17fed097f332332ebd94075ebd9670dc9654. --- pkgs/tools/package-management/nix/common.nix | 4 - pkgs/tools/package-management/nix/default.nix | 51 --- ...vation-builders-inside-the-sandbox-o.patch | 315 ----------------- ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0003-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- ...vation-builders-inside-the-sandbox-o.patch | 312 ----------------- ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0003-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- ...vation-builders-inside-the-sandbox-o.patch | 320 ----------------- ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0003-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- ...vation-builders-inside-the-sandbox-o.patch | 320 ----------------- ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0003-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- ...vation-builders-inside-the-sandbox-o.patch | 327 ------------------ ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0003-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- ...vation-builders-inside-the-sandbox-o.patch | 323 ----------------- ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0003-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- ...vation-builders-inside-the-sandbox-o.patch | 323 ----------------- ...ckaging-Add-darwin-lsandbox-in-meson.patch | 53 --- ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0004-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- .../git/0001-Fix-meson-build-on-darwin.patch | 28 -- ...vation-builders-inside-the-sandbox-o.patch | 323 ----------------- ...ckaging-Add-darwin-lsandbox-in-meson.patch | 53 --- ...-goal-Print-sandbox-error-detail-on-.patch | 34 -- .../0005-local-derivation-goal-Refactor.patch | 41 --- ...-goal-Move-builder-preparation-to-no.patch | 75 ---- 37 files changed, 3952 deletions(-) delete mode 100644 pkgs/tools/package-management/nix/patches/2_18/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_18/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_18/0003-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_18/0004-local-derivation-goal-Move-builder-preparation-to-no.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_19/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_19/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_19/0003-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_19/0004-local-derivation-goal-Move-builder-preparation-to-no.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_20/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_20/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_20/0003-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_20/0004-local-derivation-goal-Move-builder-preparation-to-no.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_21/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_21/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_21/0003-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_21/0004-local-derivation-goal-Move-builder-preparation-to-no.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_22/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_22/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_22/0003-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_22/0004-local-derivation-goal-Move-builder-preparation-to-no.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_23/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_23/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_23/0003-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_23/0004-local-derivation-goal-Move-builder-preparation-to-no.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_24/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_24/0002-packaging-Add-darwin-lsandbox-in-meson.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_24/0003-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_24/0004-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/2_24/0005-local-derivation-goal-Move-builder-preparation-to-no.patch delete mode 100644 pkgs/tools/package-management/nix/patches/git/0001-Fix-meson-build-on-darwin.patch delete mode 100644 pkgs/tools/package-management/nix/patches/git/0002-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch delete mode 100644 pkgs/tools/package-management/nix/patches/git/0003-packaging-Add-darwin-lsandbox-in-meson.patch delete mode 100644 pkgs/tools/package-management/nix/patches/git/0004-local-derivation-goal-Print-sandbox-error-detail-on-.patch delete mode 100644 pkgs/tools/package-management/nix/patches/git/0005-local-derivation-goal-Refactor.patch delete mode 100644 pkgs/tools/package-management/nix/patches/git/0006-local-derivation-goal-Move-builder-preparation-to-no.patch diff --git a/pkgs/tools/package-management/nix/common.nix b/pkgs/tools/package-management/nix/common.nix index 07e58a41e400..4d04cbb6274d 100644 --- a/pkgs/tools/package-management/nix/common.nix +++ b/pkgs/tools/package-management/nix/common.nix @@ -16,7 +16,6 @@ let atLeast210 = lib.versionAtLeast version "2.10pre"; atLeast213 = lib.versionAtLeast version "2.13pre"; atLeast214 = lib.versionAtLeast version "2.14pre"; - atLeast218 = lib.versionAtLeast version "2.18pre"; atLeast219 = lib.versionAtLeast version "2.19pre"; atLeast220 = lib.versionAtLeast version "2.20pre"; atLeast221 = lib.versionAtLeast version "2.21pre"; @@ -43,7 +42,6 @@ in , callPackage , coreutils , curl -, darwin , docbook_xsl_ns , docbook5 , editline @@ -160,8 +158,6 @@ self = stdenv.mkDerivation { libseccomp ] ++ lib.optionals withAWS [ aws-sdk-cpp - ] ++ lib.optional (atLeast218 && stdenv.hostPlatform.isDarwin) [ - darwin.apple_sdk.libs.sandbox ]; diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index 377dbc43a288..adfa793f1d35 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -178,85 +178,42 @@ in lib.makeExtensible (self: ({ version = "2.18.8"; hash = "sha256-0rHRifdjzzxMh/im8pRx6XoY62irDTDUes+Pn0CR65I="; self_attribute_name = "nix_2_18"; - patches = [ - ./patches/2_18/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/2_18/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/2_18/0003-local-derivation-goal-Refactor.patch - ./patches/2_18/0004-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; }; nix_2_19 = common { version = "2.19.6"; hash = "sha256-XT5xiwOLgXf+TdyOjbJVOl992wu9mBO25WXHoyli/Tk="; self_attribute_name = "nix_2_19"; - patches = [ - ./patches/2_19/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/2_19/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/2_19/0003-local-derivation-goal-Refactor.patch - ./patches/2_19/0004-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; }; nix_2_20 = common { version = "2.20.8"; hash = "sha256-M2tkMtjKi8LDdNLsKi3IvD8oY/i3rtarjMpvhybS3WY="; self_attribute_name = "nix_2_20"; - patches = [ - ./patches/2_20/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/2_20/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/2_20/0003-local-derivation-goal-Refactor.patch - ./patches/2_20/0004-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; }; nix_2_21 = common { version = "2.21.4"; hash = "sha256-c6nVZ0pSrfhFX3eVKqayS+ioqyAGp3zG9ZPO5rkXFRQ="; self_attribute_name = "nix_2_21"; - patches = [ - ./patches/2_21/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/2_21/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/2_21/0003-local-derivation-goal-Refactor.patch - ./patches/2_21/0004-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; }; nix_2_22 = common { version = "2.22.3"; hash = "sha256-l04csH5rTWsK7eXPWVxJBUVRPMZXllFoSkYFTq/i8WU="; self_attribute_name = "nix_2_22"; - patches = [ - ./patches/2_22/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/2_22/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/2_22/0003-local-derivation-goal-Refactor.patch - ./patches/2_22/0004-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; }; nix_2_23 = common { version = "2.23.3"; hash = "sha256-lAoLGVIhRFrfgv7wcyduEkyc83QKrtsfsq4of+WrBeg="; self_attribute_name = "nix_2_23"; - patches = [ - ./patches/2_23/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/2_23/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/2_23/0003-local-derivation-goal-Refactor.patch - ./patches/2_23/0004-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; }; nix_2_24 = (common { version = "2.24.9"; hash = "sha256-OwJByTdCz1t91ysBqynK+ifszkoIGEXUn6HE2t82+c8="; self_attribute_name = "nix_2_24"; - patches = [ - ./patches/2_24/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/2_24/0002-packaging-Add-darwin-lsandbox-in-meson.patch - ./patches/2_24/0003-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/2_24/0004-local-derivation-goal-Refactor.patch - ./patches/2_24/0005-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; }).override (lib.optionalAttrs (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isx86_64) { # Fix the following error with the default x86_64-darwin SDK: # @@ -277,14 +234,6 @@ in lib.makeExtensible (self: ({ rev = "ca3fc1693b309ab6b8b0c09408a08d0055bf0363"; hash = "sha256-Hp7dkx7zfB9a4l5QusXUob0b1T2qdZ23LFo5dcp3xrU="; }; - patches = [ - ./patches/git/0001-Fix-meson-build-on-darwin.patch - ./patches/git/0002-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch - ./patches/git/0003-packaging-Add-darwin-lsandbox-in-meson.patch - ./patches/git/0004-local-derivation-goal-Print-sandbox-error-detail-on-.patch - ./patches/git/0005-local-derivation-goal-Refactor.patch - ./patches/git/0006-local-derivation-goal-Move-builder-preparation-to-no.patch - ]; self_attribute_name = "git"; }).override (lib.optionalAttrs (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isx86_64) { # Fix the following error with the default x86_64-darwin SDK: diff --git a/pkgs/tools/package-management/nix/patches/2_18/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/2_18/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index c13844f8bdd7..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_18/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,315 +0,0 @@ -From 3c4bc6929eb13cf648c54931a28797bb1c289052 Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - flake.nix | 1 + - src/libstore/build/local-derivation-goal.cc | 221 ++++++++++---------- - 3 files changed, 114 insertions(+), 114 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 4e50d0913..44852ad79 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -58,13 +58,17 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - AC_STRUCT_DIRENT_D_TYPE - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/flake.nix b/flake.nix -index 6c9bef4d8..66ac1bfd8 100644 ---- a/flake.nix -+++ b/flake.nix -@@ -173,6 +173,7 @@ - boost - lowdown-nix - ] -+ ++ lib.optionals stdenv.isDarwin [darwin.apple_sdk.libs.sandbox] - ++ lib.optionals stdenv.isLinux [(libseccomp.overrideAttrs (_: rec { - version = "2.5.5"; - src = fetchurl { -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index 4d690beaf..fb83cfdc7 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -53,6 +53,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2034,141 +2038,132 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : dirsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; - -- /* And we want the store in there regardless of how empty dirsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ if (useChroot) { -+ -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : dirsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- dirsInChroot[p] = p; -- } -- -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* And we want the store in there regardless of how empty dirsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- sandboxProfile += -- #include "sandbox-defaults.sb" -- ; -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ dirsInChroot[p] = p; -+ } - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : dirsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- struct stat st; -- if (lstat(path.c_str(), &st)) { -- if (i.second.optional && errno == ENOENT) -- continue; -- throw SysError("getting attributes of path '%s", path); -- } -- if (S_ISDIR(st.st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; - -- sandboxProfile += additionalSandboxProfile; -- } else -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-minimal.sb" -+ #include "sandbox-network.sb" - ; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ sandboxProfile += ")\n"; - -- writeFile(sandboxFile, sandboxProfile); -+ /* Our inputs (transitive dependencies and any impurities computed above) - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : dirsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -- Path globalTmpDir = canonPath(defaultTempDir(), true); -+ std::string path = i.first; -+ struct stat st; -+ if (lstat(path.c_str(), &st)) { -+ if (i.second.optional && errno == ENOENT) -+ continue; -+ throw SysError("getting attributes of path '%s", path); -+ } -+ if (S_ISDIR(st.st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- /* They don't like trailing slashes on subpath directives */ -- while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -- globalTmpDir.pop_back(); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; -+ -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); -+ -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -+ Path globalTmpDir = canonPath(defaultTempDir(), true); -+ -+ /* They don't like trailing slashes on subpath directives */ -+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -+ globalTmpDir.pop_back(); -+ -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_18/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/2_18/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index a3bc4f05cdaf..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_18/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 4ac099d6ab4b6851aeb8b7a1e37f5794716d5138 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index fb83cfdc7..d41d1c1e5 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2154,8 +2154,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_18/0003-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/2_18/0003-local-derivation-goal-Refactor.patch deleted file mode 100644 index 81997405a5f7..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_18/0003-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 6fe3a5e26def808b99856099d74aa3017ecf6d9d Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 3/4] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index d41d1c1e5..faecc403b 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2160,15 +2160,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_18/0004-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/2_18/0004-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index 4a17ccedbdbd..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_18/0004-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From d219faa93badcfc8134c81ba0d2b821775eb947c Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------ - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index faecc403b..23d5d5e3f 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2033,11 +2033,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2162,14 +2157,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2199,6 +2186,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2220,9 +2215,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_19/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/2_19/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index dfe091b48c7d..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_19/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,312 +0,0 @@ -From 172734f47a8062285cec0055133efcc45df03e54 Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - flake.nix | 1 + - src/libstore/build/local-derivation-goal.cc | 217 ++++++++++---------- - 3 files changed, 112 insertions(+), 112 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 281ba2c32..6d73804e2 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -58,13 +58,17 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - AC_STRUCT_DIRENT_D_TYPE - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/flake.nix b/flake.nix -index 6deb09f22..98f9cc25f 100644 ---- a/flake.nix -+++ b/flake.nix -@@ -202,6 +202,7 @@ - libsodium - ] - ++ lib.optionals stdenv.isLinux [libseccomp] -+ ++ lib.optionals stdenv.isDarwin [darwin.apple_sdk.libs.sandbox] - ++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid; - - checkDeps = [ -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index b6c7666e5..effd9c613 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -55,6 +55,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2031,140 +2035,131 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : pathsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; - -- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ if (useChroot) { -+ -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : pathsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- pathsInChroot[p] = p; -- } -+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ pathsInChroot[p] = p; -+ } -+ -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; -+ -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-defaults.sb" -+ #include "sandbox-network.sb" - ; - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : pathsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- struct stat st; -- if (lstat(path.c_str(), &st)) { -- if (i.second.optional && errno == ENOENT) -- continue; -- throw SysError("getting attributes of path '%s", path); -- } -- if (S_ISDIR(st.st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += ")\n"; - -- sandboxProfile += additionalSandboxProfile; -- } else -- sandboxProfile += -- #include "sandbox-minimal.sb" -- ; -+ /* Our inputs (transitive dependencies and any impurities computed above) -+ -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : pathsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); -+ -+ std::string path = i.first; -+ struct stat st; -+ if (lstat(path.c_str(), &st)) { -+ if (i.second.optional && errno == ENOENT) -+ continue; -+ throw SysError("getting attributes of path '%s", path); -+ } -+ if (S_ISDIR(st.st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; - -- writeFile(sandboxFile, sandboxProfile); -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -- Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true); -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -+ Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true); - -- /* They don't like trailing slashes on subpath directives */ -- if (globalTmpDir.back() == '/') globalTmpDir.pop_back(); -+ /* They don't like trailing slashes on subpath directives */ -+ if (globalTmpDir.back() == '/') globalTmpDir.pop_back(); - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_19/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/2_19/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index 8378f739dd7e..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_19/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 4a5018019e969537fdba36314fe5c19fe91828af Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index effd9c613..a67347b59 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2150,8 +2150,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_19/0003-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/2_19/0003-local-derivation-goal-Refactor.patch deleted file mode 100644 index f98d7069b554..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_19/0003-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From f9e5b3b52323fdcac4e21bfec4d03bd66ea6a503 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 3/4] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index a67347b59..eeb2635ee 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2156,15 +2156,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_19/0004-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/2_19/0004-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index 523e0edea3d9..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_19/0004-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 126a1fd3385175ac94ae4000a9798e0cafb3c168 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------ - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index eeb2635ee..e29330f0e 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2030,11 +2030,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2158,14 +2153,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2195,6 +2182,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2216,9 +2211,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_20/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/2_20/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index 6c5d8b785990..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_20/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,320 +0,0 @@ -From aa54b01af503644a393e4e4055c4ce2a23ce9139 Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - package.nix | 2 + - src/libstore/build/local-derivation-goal.cc | 217 ++++++++++---------- - 3 files changed, 113 insertions(+), 112 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 8c29c1e62..8c524fd93 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -58,13 +58,17 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - AC_STRUCT_DIRENT_D_TYPE - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/package.nix b/package.nix -index d1d14d10e..40283ffcf 100644 ---- a/package.nix -+++ b/package.nix -@@ -24,6 +24,7 @@ - , libgit2 - , libseccomp - , libsodium -+, darwin - , lowdown - , mdbook - , mdbook-linkcheck -@@ -233,6 +234,7 @@ in { - gtest - rapidcheck - ] ++ lib.optional stdenv.isLinux libseccomp -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox - ++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid - # There have been issues building these dependencies - ++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin)) -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index b8228bc11..9ab676429 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -57,6 +57,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2023,140 +2027,131 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : pathsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; - -- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ if (useChroot) { -+ -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : pathsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- pathsInChroot[p] = p; -- } -+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ pathsInChroot[p] = p; -+ } -+ -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; -+ -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-defaults.sb" -+ #include "sandbox-network.sb" - ; - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : pathsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- struct stat st; -- if (lstat(path.c_str(), &st)) { -- if (i.second.optional && errno == ENOENT) -- continue; -- throw SysError("getting attributes of path '%s", path); -- } -- if (S_ISDIR(st.st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += ")\n"; - -- sandboxProfile += additionalSandboxProfile; -- } else -- sandboxProfile += -- #include "sandbox-minimal.sb" -- ; -+ /* Our inputs (transitive dependencies and any impurities computed above) -+ -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : pathsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); -+ -+ std::string path = i.first; -+ struct stat st; -+ if (lstat(path.c_str(), &st)) { -+ if (i.second.optional && errno == ENOENT) -+ continue; -+ throw SysError("getting attributes of path '%s", path); -+ } -+ if (S_ISDIR(st.st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; - -- writeFile(sandboxFile, sandboxProfile); -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -- Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true); -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -+ Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true); - -- /* They don't like trailing slashes on subpath directives */ -- if (globalTmpDir.back() == '/') globalTmpDir.pop_back(); -+ /* They don't like trailing slashes on subpath directives */ -+ if (globalTmpDir.back() == '/') globalTmpDir.pop_back(); - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_20/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/2_20/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index d644be6703e7..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_20/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From b78e489f79165457b59faa2270fd89769d0fc17d Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index 9ab676429..8476e038e 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2142,8 +2142,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_20/0003-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/2_20/0003-local-derivation-goal-Refactor.patch deleted file mode 100644 index 05e8c5843ace..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_20/0003-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From db6bcf3f7714929d5a21b655c5f8ccd2ddbdf7f2 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 3/4] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index 8476e038e..12b67df69 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2148,15 +2148,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_20/0004-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/2_20/0004-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index 852940d3b711..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_20/0004-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 55be7deee1471e77e3ad408c5e23842df0d5bc28 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------ - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index 12b67df69..ada86dbb8 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2022,11 +2022,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2150,14 +2145,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2187,6 +2174,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2208,9 +2203,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_21/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/2_21/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index d35d20896e6b..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_21/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,320 +0,0 @@ -From ae8a38d29cc0fbd6394acd72fdaaa62b3798f698 Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - package.nix | 2 + - src/libstore/build/local-derivation-goal.cc | 217 ++++++++++---------- - 3 files changed, 113 insertions(+), 112 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 676b145a5..f6fa35c81 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -62,13 +62,17 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - AC_STRUCT_DIRENT_D_TYPE - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/package.nix b/package.nix -index 7d9a39771..de2e1aff1 100644 ---- a/package.nix -+++ b/package.nix -@@ -25,6 +25,7 @@ - , libseccomp - , libsodium - , man -+, darwin - , lowdown - , mdbook - , mdbook-linkcheck -@@ -239,6 +240,7 @@ in { - gtest - rapidcheck - ] ++ lib.optional stdenv.isLinux libseccomp -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox - ++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid - # There have been issues building these dependencies - ++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin)) -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index 710304b67..c73b30b80 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -58,6 +58,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2018,140 +2022,131 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : pathsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; - -- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ if (useChroot) { -+ -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : pathsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- pathsInChroot[p] = p; -- } -+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ pathsInChroot[p] = p; -+ } -+ -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; -+ -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-defaults.sb" -+ #include "sandbox-network.sb" - ; - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : pathsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- struct stat st; -- if (lstat(path.c_str(), &st)) { -- if (i.second.optional && errno == ENOENT) -- continue; -- throw SysError("getting attributes of path '%s", path); -- } -- if (S_ISDIR(st.st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += ")\n"; - -- sandboxProfile += additionalSandboxProfile; -- } else -- sandboxProfile += -- #include "sandbox-minimal.sb" -- ; -+ /* Our inputs (transitive dependencies and any impurities computed above) -+ -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : pathsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); -+ -+ std::string path = i.first; -+ struct stat st; -+ if (lstat(path.c_str(), &st)) { -+ if (i.second.optional && errno == ENOENT) -+ continue; -+ throw SysError("getting attributes of path '%s", path); -+ } -+ if (S_ISDIR(st.st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; - -- writeFile(sandboxFile, sandboxProfile); -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -- Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true); -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to dump their files, if needed. */ -+ Path globalTmpDir = canonPath(getEnvNonEmpty("TMPDIR").value_or("/tmp"), true); - -- /* They don't like trailing slashes on subpath directives */ -- if (globalTmpDir.back() == '/') globalTmpDir.pop_back(); -+ /* They don't like trailing slashes on subpath directives */ -+ if (globalTmpDir.back() == '/') globalTmpDir.pop_back(); - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_21/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/2_21/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index 053d3eb672d9..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_21/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From b429e96583e2d005c77df8c82261022397f20648 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index c73b30b80..e6f4c397d 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2137,8 +2137,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_21/0003-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/2_21/0003-local-derivation-goal-Refactor.patch deleted file mode 100644 index 97809a556b57..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_21/0003-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 74b93c1edba00c2601e20b8acdcc78e29bd3f092 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 3/4] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index e6f4c397d..e81818fa8 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2143,15 +2143,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_21/0004-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/2_21/0004-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index b2f3b2b7815c..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_21/0004-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From c8de35f74cbce58651c3b64ba66061040f546b9f Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - src/libstore/build/local-derivation-goal.cc | 25 +++++++++------------ - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/build/local-derivation-goal.cc b/src/libstore/build/local-derivation-goal.cc -index e81818fa8..078f1a5be 100644 ---- a/src/libstore/build/local-derivation-goal.cc -+++ b/src/libstore/build/local-derivation-goal.cc -@@ -2017,11 +2017,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2145,14 +2140,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2183,6 +2170,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2204,9 +2199,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_22/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/2_22/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index 72470dec5fd2..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_22/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,327 +0,0 @@ -From 8217054e3554ffd376f42fb0a65087a7af2ddfab Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - package.nix | 5 +- - .../unix/build/local-derivation-goal.cc | 223 +++++++++--------- - 3 files changed, 118 insertions(+), 116 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 8f60bf4be..5e67e04be 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -62,13 +62,17 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - AC_STRUCT_DIRENT_D_TYPE - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/package.nix b/package.nix -index 59265f522..28be97400 100644 ---- a/package.nix -+++ b/package.nix -@@ -27,6 +27,7 @@ - , libseccomp - , libsodium - , man -+, darwin - , lowdown - , mdbook - , mdbook-linkcheck -@@ -249,7 +250,9 @@ in { - ] ++ lib.optionals buildUnitTests [ - gtest - rapidcheck -- ] ++ lib.optional stdenv.isLinux (libseccomp.overrideAttrs (_: rec { -+ ] -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox -+ ++ lib.optional stdenv.isLinux (libseccomp.overrideAttrs (_: rec { - version = "2.5.5"; - src = fetchurl { - url = "https://github.com/seccomp/libseccomp/releases/download/v${version}/libseccomp-${version}.tar.gz"; -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index b8ccdf834..449d4b07c 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -58,6 +58,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2026,141 +2030,132 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : pathsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; -+ -+ if (useChroot) { - -- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : pathsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- pathsInChroot[p] = p; -- } -- -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- sandboxProfile += -- #include "sandbox-defaults.sb" -- ; -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ pathsInChroot[p] = p; -+ } - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : pathsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- auto optSt = maybeLstat(path.c_str()); -- if (!optSt) { -- if (i.second.optional) -- continue; -- throw SysError("getting attributes of required path '%s", path); -- } -- if (S_ISDIR(optSt->st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; - -- sandboxProfile += additionalSandboxProfile; -- } else -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-minimal.sb" -+ #include "sandbox-network.sb" - ; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -- -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- writeFile(sandboxFile, sandboxProfile); -+ sandboxProfile += ")\n"; - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ /* Our inputs (transitive dependencies and any impurities computed above) - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -- Path globalTmpDir = canonPath(defaultTempDir(), true); -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : pathsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); -+ -+ std::string path = i.first; -+ auto optSt = maybeLstat(path.c_str()); -+ if (!optSt) { -+ if (i.second.optional) -+ continue; -+ throw SysError("getting attributes of required path '%s", path); -+ } -+ if (S_ISDIR(optSt->st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- /* They don't like trailing slashes on subpath directives */ -- while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -- globalTmpDir.pop_back(); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; -+ -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); -+ -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -+ Path globalTmpDir = canonPath(defaultTempDir(), true); -+ -+ /* They don't like trailing slashes on subpath directives */ -+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -+ globalTmpDir.pop_back(); -+ -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_22/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/2_22/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index 6ac281e6316c..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_22/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From f0677f190d0bd042c3a864508a5307b19a2c2d26 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 449d4b07c..b74bd2e64 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2146,8 +2146,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_22/0003-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/2_22/0003-local-derivation-goal-Refactor.patch deleted file mode 100644 index dfb5add1978d..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_22/0003-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 1b39753f4d63465c709d18482945ce680b6f3f1e Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 3/4] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index b74bd2e64..9b8b3c51b 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2152,15 +2152,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_22/0004-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/2_22/0004-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index 8e200685dc73..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_22/0004-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 9e198a75f76ac08f835975d4b2743e156616a219 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - .../unix/build/local-derivation-goal.cc | 25 ++++++++----------- - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 9b8b3c51b..08366712c 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2025,11 +2025,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2154,14 +2149,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2192,6 +2179,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2213,9 +2208,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_23/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/2_23/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index f309ff6818d4..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_23/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,323 +0,0 @@ -From 05994033d58e358ddafe51d1d04626eb76b8a192 Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 1/4] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - package.nix | 2 + - .../unix/build/local-derivation-goal.cc | 223 +++++++++--------- - 3 files changed, 116 insertions(+), 115 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 90a6d45d5..f98a0a5ea 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -62,12 +62,16 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/package.nix b/package.nix -index cf1654c6a..1dfe7ab31 100644 ---- a/package.nix -+++ b/package.nix -@@ -27,6 +27,7 @@ - , libseccomp - , libsodium - , man -+, darwin - , lowdown - , mdbook - , mdbook-linkcheck -@@ -250,6 +251,7 @@ in { - gtest - rapidcheck - ] ++ lib.optional stdenv.isLinux libseccomp -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox - ++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid - # There have been issues building these dependencies - ++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin)) -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index ae9c715d6..878644fa5 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -58,6 +58,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2017,141 +2021,132 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : pathsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; -+ -+ if (useChroot) { - -- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : pathsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- pathsInChroot[p] = p; -- } -- -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- sandboxProfile += -- #include "sandbox-defaults.sb" -- ; -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ pathsInChroot[p] = p; -+ } - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : pathsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- auto optSt = maybeLstat(path.c_str()); -- if (!optSt) { -- if (i.second.optional) -- continue; -- throw SysError("getting attributes of required path '%s", path); -- } -- if (S_ISDIR(optSt->st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; - -- sandboxProfile += additionalSandboxProfile; -- } else -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-minimal.sb" -+ #include "sandbox-network.sb" - ; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -- -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- writeFile(sandboxFile, sandboxProfile); -+ sandboxProfile += ")\n"; - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ /* Our inputs (transitive dependencies and any impurities computed above) - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -- Path globalTmpDir = canonPath(defaultTempDir(), true); -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : pathsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); -+ -+ std::string path = i.first; -+ auto optSt = maybeLstat(path.c_str()); -+ if (!optSt) { -+ if (i.second.optional) -+ continue; -+ throw SysError("getting attributes of required path '%s", path); -+ } -+ if (S_ISDIR(optSt->st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- /* They don't like trailing slashes on subpath directives */ -- while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -- globalTmpDir.pop_back(); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; -+ -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); -+ -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -+ Path globalTmpDir = canonPath(defaultTempDir(), true); -+ -+ /* They don't like trailing slashes on subpath directives */ -+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -+ globalTmpDir.pop_back(); -+ -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_23/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/2_23/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index e264b4f1b4dc..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_23/0002-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From c43954ffac356b4168cbcfe2a67b4bad3f0dff5d Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 2/4] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 878644fa5..0df1f0683 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2137,8 +2137,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_23/0003-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/2_23/0003-local-derivation-goal-Refactor.patch deleted file mode 100644 index 27c632b041dd..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_23/0003-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 53b4bdcb8b0f114bea978cffbea325fd73f779b5 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 3/4] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 0df1f0683..9e67283c9 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2143,15 +2143,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_23/0004-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/2_23/0004-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index 6ef5c8e48c4c..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_23/0004-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 67b5c7004302cbd344f63ccd306673a9adec4520 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 4/4] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - .../unix/build/local-derivation-goal.cc | 25 ++++++++----------- - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 9e67283c9..1f4bafb56 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2016,11 +2016,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2145,14 +2140,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2183,6 +2170,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2204,9 +2199,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_24/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/2_24/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index 9c3d5f987da2..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_24/0001-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,323 +0,0 @@ -From 170242cf0ca3e9fadbad2004126793634d56623e Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 1/5] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - package.nix | 2 + - .../unix/build/local-derivation-goal.cc | 223 +++++++++--------- - 3 files changed, 116 insertions(+), 115 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 5c22ed176..dff35981b 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -62,12 +62,16 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/package.nix b/package.nix -index a7c8923e8..fcd1e1898 100644 ---- a/package.nix -+++ b/package.nix -@@ -23,6 +23,7 @@ - , libseccomp - , libsodium - , man -+, darwin - , lowdown - , mdbook - , mdbook-linkcheck -@@ -235,6 +236,7 @@ in { - gtest - rapidcheck - ] ++ lib.optional stdenv.isLinux libseccomp -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox - ++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid - # There have been issues building these dependencies - ++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin)) -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 54ca69580..7ce266122 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -58,6 +58,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2039,141 +2043,132 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : pathsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; -+ -+ if (useChroot) { - -- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : pathsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- pathsInChroot[p] = p; -- } -- -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- sandboxProfile += -- #include "sandbox-defaults.sb" -- ; -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ pathsInChroot[p] = p; -+ } - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : pathsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- auto optSt = maybeLstat(path.c_str()); -- if (!optSt) { -- if (i.second.optional) -- continue; -- throw SysError("getting attributes of required path '%s", path); -- } -- if (S_ISDIR(optSt->st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; - -- sandboxProfile += additionalSandboxProfile; -- } else -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-minimal.sb" -+ #include "sandbox-network.sb" - ; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -- -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- writeFile(sandboxFile, sandboxProfile); -+ sandboxProfile += ")\n"; - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ /* Our inputs (transitive dependencies and any impurities computed above) - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -- Path globalTmpDir = canonPath(defaultTempDir(), true); -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : pathsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); -+ -+ std::string path = i.first; -+ auto optSt = maybeLstat(path.c_str()); -+ if (!optSt) { -+ if (i.second.optional) -+ continue; -+ throw SysError("getting attributes of required path '%s", path); -+ } -+ if (S_ISDIR(optSt->st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- /* They don't like trailing slashes on subpath directives */ -- while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -- globalTmpDir.pop_back(); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; -+ -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); -+ -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -+ Path globalTmpDir = canonPath(defaultTempDir(), true); -+ -+ /* They don't like trailing slashes on subpath directives */ -+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -+ globalTmpDir.pop_back(); -+ -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_24/0002-packaging-Add-darwin-lsandbox-in-meson.patch b/pkgs/tools/package-management/nix/patches/2_24/0002-packaging-Add-darwin-lsandbox-in-meson.patch deleted file mode 100644 index c709ea62354d..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_24/0002-packaging-Add-darwin-lsandbox-in-meson.patch +++ /dev/null @@ -1,53 +0,0 @@ -From f8a1a149c73113e01c44b73ce9e1005575d52a9a Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:23:17 +0200 -Subject: [PATCH 2/5] packaging: Add darwin -lsandbox in meson -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - src/libstore/meson.build | 5 +++++ - src/libstore/package.nix | 2 ++ - 2 files changed, 7 insertions(+) - -diff --git a/src/libstore/meson.build b/src/libstore/meson.build -index 50b15e15d..b23c85061 100644 ---- a/src/libstore/meson.build -+++ b/src/libstore/meson.build -@@ -68,6 +68,11 @@ has_acl_support = cxx.has_header('sys/xattr.h') \ - and cxx.has_function('lremovexattr') - configdata.set('HAVE_ACL_SUPPORT', has_acl_support.to_int()) - -+if host_machine.system() == 'darwin' -+ sandbox = cxx.find_library('sandbox') -+ deps_other += [sandbox] -+endif -+ - subdir('build-utils-meson/threads') - - boost = dependency( -diff --git a/src/libstore/package.nix b/src/libstore/package.nix -index 4582ba0d2..d98bac16d 100644 ---- a/src/libstore/package.nix -+++ b/src/libstore/package.nix -@@ -7,6 +7,7 @@ - , ninja - , pkg-config - , unixtools -+, darwin - - , nix-util - , boost -@@ -65,6 +66,7 @@ mkMesonDerivation (finalAttrs: { - sqlite - ] ++ lib.optional stdenv.hostPlatform.isLinux libseccomp - # There have been issues building these dependencies -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox - ++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin)) - aws-sdk-cpp - ; --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_24/0003-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/2_24/0003-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index 2c984b6343db..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_24/0003-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From ae7a2ea74136363c2f6ac6e624ea95da7abfafcc Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 3/5] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 7ce266122..706771e8e 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2159,8 +2159,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_24/0004-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/2_24/0004-local-derivation-goal-Refactor.patch deleted file mode 100644 index dbf54c5020c9..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_24/0004-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 047ee50db2f660eb3f50fab8f7543ce95e814b7c Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 4/5] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 706771e8e..d9738a1ea 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2165,15 +2165,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/2_24/0005-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/2_24/0005-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index c4fc9b2c2117..000000000000 --- a/pkgs/tools/package-management/nix/patches/2_24/0005-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 50f83e4bbd9107576399f94449ac9cb4e80d575e Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 5/5] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - .../unix/build/local-derivation-goal.cc | 25 ++++++++----------- - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index d9738a1ea..2a09e3dd4 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2038,11 +2038,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2167,14 +2162,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2205,6 +2192,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2226,9 +2221,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/git/0001-Fix-meson-build-on-darwin.patch b/pkgs/tools/package-management/nix/patches/git/0001-Fix-meson-build-on-darwin.patch deleted file mode 100644 index e03bed014561..000000000000 --- a/pkgs/tools/package-management/nix/patches/git/0001-Fix-meson-build-on-darwin.patch +++ /dev/null @@ -1,28 +0,0 @@ -From 766263d53ae69d70c5915426e6e8f58abd988226 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Tue, 22 Oct 2024 15:28:04 +0200 -Subject: [PATCH 1/6] Fix meson build on darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -std::stringbuf is defined in -Signed-off-by: Jörg Thalheim ---- - src/libutil/strings.cc | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/libutil/strings.cc b/src/libutil/strings.cc -index d1c9f700c..c221a43c6 100644 ---- a/src/libutil/strings.cc -+++ b/src/libutil/strings.cc -@@ -1,5 +1,6 @@ - #include - #include -+#include - - #include "strings-inline.hh" - #include "os-string.hh" --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/git/0002-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch b/pkgs/tools/package-management/nix/patches/git/0002-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch deleted file mode 100644 index 36218646f3b6..000000000000 --- a/pkgs/tools/package-management/nix/patches/git/0002-fix-Run-all-derivation-builders-inside-the-sandbox-o.patch +++ /dev/null @@ -1,323 +0,0 @@ -From d2c880b03f58eb4fdd6d19eb3ffa4345a0477419 Mon Sep 17 00:00:00 2001 -From: Puck Meerburg -Date: Fri, 1 Mar 2024 11:42:24 -0500 -Subject: [PATCH 2/6] fix: Run all derivation builders inside the sandbox on - macOS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - configure.ac | 6 +- - package.nix | 2 + - .../unix/build/local-derivation-goal.cc | 223 +++++++++--------- - 3 files changed, 116 insertions(+), 115 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 198198dea..c7c9b3f4b 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -62,12 +62,16 @@ AC_CHECK_TOOL([AR], [ar]) - AC_SYS_LARGEFILE - - --# Solaris-specific stuff. -+# OS-specific stuff. - case "$host_os" in - solaris*) - # Solaris requires -lsocket -lnsl for network functions - LDFLAGS="-lsocket -lnsl $LDFLAGS" - ;; -+ darwin*) -+ # Need to link to libsandbox. -+ LDFLAGS="-lsandbox $LDFLAGS" -+ ;; - esac - - -diff --git a/package.nix b/package.nix -index 00621d475..77f1de58c 100644 ---- a/package.nix -+++ b/package.nix -@@ -23,6 +23,7 @@ - , libseccomp - , libsodium - , man -+, darwin - , lowdown - , mdbook - , mdbook-linkcheck -@@ -232,6 +233,7 @@ in { - gtest - rapidcheck - ] ++ lib.optional stdenv.isLinux libseccomp -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox - ++ lib.optional stdenv.hostPlatform.isx86_64 libcpuid - # There have been issues building these dependencies - ++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin)) -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index b4685b3a7..067755c0d 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -58,6 +58,10 @@ - #if __APPLE__ - #include - #include -+#include -+ -+/* This definition is undocumented but depended upon by all major browsers. */ -+extern "C" int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); - #endif - - #include -@@ -2088,141 +2092,132 @@ void LocalDerivationGoal::runChild() - - std::string builder = "invalid"; - -- if (drv->isBuiltin()) { -- ; -- } - #if __APPLE__ -- else { -- /* This has to appear before import statements. */ -- std::string sandboxProfile = "(version 1)\n"; -- -- if (useChroot) { -- -- /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -- PathSet ancestry; -- -- /* We build the ancestry before adding all inputPaths to the store because we know they'll -- all have the same parents (the store), and there might be lots of inputs. This isn't -- particularly efficient... I doubt it'll be a bottleneck in practice */ -- for (auto & i : pathsInChroot) { -- Path cur = i.first; -- while (cur.compare("/") != 0) { -- cur = dirOf(cur); -- ancestry.insert(cur); -- } -- } -+ /* This has to appear before import statements. */ -+ std::string sandboxProfile = "(version 1)\n"; -+ -+ if (useChroot) { - -- /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -- path component this time, since it's typically /nix/store and we care about that. */ -- Path cur = worker.store.storeDir; -+ /* Lots and lots and lots of file functions freak out if they can't stat their full ancestry */ -+ PathSet ancestry; -+ -+ /* We build the ancestry before adding all inputPaths to the store because we know they'll -+ all have the same parents (the store), and there might be lots of inputs. This isn't -+ particularly efficient... I doubt it'll be a bottleneck in practice */ -+ for (auto & i : pathsInChroot) { -+ Path cur = i.first; - while (cur.compare("/") != 0) { -- ancestry.insert(cur); - cur = dirOf(cur); -+ ancestry.insert(cur); - } -+ } - -- /* Add all our input paths to the chroot */ -- for (auto & i : inputPaths) { -- auto p = worker.store.printStorePath(i); -- pathsInChroot[p] = p; -- } -- -- /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -- if (settings.darwinLogSandboxViolations) { -- sandboxProfile += "(deny default)\n"; -- } else { -- sandboxProfile += "(deny default (with no-log))\n"; -- } -+ /* And we want the store in there regardless of how empty pathsInChroot. We include the innermost -+ path component this time, since it's typically /nix/store and we care about that. */ -+ Path cur = worker.store.storeDir; -+ while (cur.compare("/") != 0) { -+ ancestry.insert(cur); -+ cur = dirOf(cur); -+ } - -- sandboxProfile += -- #include "sandbox-defaults.sb" -- ; -+ /* Add all our input paths to the chroot */ -+ for (auto & i : inputPaths) { -+ auto p = worker.store.printStorePath(i); -+ pathsInChroot[p] = p; -+ } - -- if (!derivationType->isSandboxed()) -- sandboxProfile += -- #include "sandbox-network.sb" -- ; -- -- /* Add the output paths we'll use at build-time to the chroot */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & [_, path] : scratchOutputs) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); -- -- sandboxProfile += ")\n"; -- -- /* Our inputs (transitive dependencies and any impurities computed above) -- -- without file-write* allowed, access() incorrectly returns EPERM -- */ -- sandboxProfile += "(allow file-read* file-write* process-exec\n"; -- for (auto & i : pathsInChroot) { -- if (i.first != i.second.source) -- throw Error( -- "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -- i.first, i.second.source); -- -- std::string path = i.first; -- auto optSt = maybeLstat(path.c_str()); -- if (!optSt) { -- if (i.second.optional) -- continue; -- throw SysError("getting attributes of required path '%s", path); -- } -- if (S_ISDIR(optSt->st_mode)) -- sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -- else -- sandboxProfile += fmt("\t(literal \"%s\")\n", path); -- } -- sandboxProfile += ")\n"; -+ /* Violations will go to the syslog if you set this. Unfortunately the destination does not appear to be configurable */ -+ if (settings.darwinLogSandboxViolations) { -+ sandboxProfile += "(deny default)\n"; -+ } else { -+ sandboxProfile += "(deny default (with no-log))\n"; -+ } - -- /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -- sandboxProfile += "(allow file-read*\n"; -- for (auto & i : ancestry) { -- sandboxProfile += fmt("\t(literal \"%s\")\n", i); -- } -- sandboxProfile += ")\n"; -+ sandboxProfile += -+ #include "sandbox-defaults.sb" -+ ; - -- sandboxProfile += additionalSandboxProfile; -- } else -+ if (!derivationType->isSandboxed()) - sandboxProfile += -- #include "sandbox-minimal.sb" -+ #include "sandbox-network.sb" - ; - -- debug("Generated sandbox profile:"); -- debug(sandboxProfile); -- -- Path sandboxFile = tmpDir + "/.sandbox.sb"; -+ /* Add the output paths we'll use at build-time to the chroot */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & [_, path] : scratchOutputs) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", worker.store.printStorePath(path)); - -- writeFile(sandboxFile, sandboxProfile); -+ sandboxProfile += ")\n"; - -- bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ /* Our inputs (transitive dependencies and any impurities computed above) - -- /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -- to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -- Path globalTmpDir = canonPath(defaultTempDir(), true); -+ without file-write* allowed, access() incorrectly returns EPERM -+ */ -+ sandboxProfile += "(allow file-read* file-write* process-exec\n"; -+ for (auto & i : pathsInChroot) { -+ if (i.first != i.second.source) -+ throw Error( -+ "can't map '%1%' to '%2%': mismatched impure paths not supported on Darwin", -+ i.first, i.second.source); -+ -+ std::string path = i.first; -+ auto optSt = maybeLstat(path.c_str()); -+ if (!optSt) { -+ if (i.second.optional) -+ continue; -+ throw SysError("getting attributes of required path '%s", path); -+ } -+ if (S_ISDIR(optSt->st_mode)) -+ sandboxProfile += fmt("\t(subpath \"%s\")\n", path); -+ else -+ sandboxProfile += fmt("\t(literal \"%s\")\n", path); -+ } -+ sandboxProfile += ")\n"; - -- /* They don't like trailing slashes on subpath directives */ -- while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -- globalTmpDir.pop_back(); -+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */ -+ sandboxProfile += "(allow file-read*\n"; -+ for (auto & i : ancestry) { -+ sandboxProfile += fmt("\t(literal \"%s\")\n", i); -+ } -+ sandboxProfile += ")\n"; - -- if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -- builder = "/usr/bin/sandbox-exec"; -- args.push_back("sandbox-exec"); -- args.push_back("-f"); -- args.push_back(sandboxFile); -- args.push_back("-D"); -- args.push_back("_GLOBAL_TMP_DIR=" + globalTmpDir); -- if (allowLocalNetworking) { -- args.push_back("-D"); -- args.push_back(std::string("_ALLOW_LOCAL_NETWORKING=1")); -- } -- args.push_back(drv->builder); -- } else { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -+ sandboxProfile += additionalSandboxProfile; -+ } else -+ sandboxProfile += -+ #include "sandbox-minimal.sb" -+ ; -+ -+ debug("Generated sandbox profile:"); -+ debug(sandboxProfile); -+ -+ bool allowLocalNetworking = parsedDrv->getBoolAttr("__darwinAllowLocalNetworking"); -+ -+ /* The tmpDir in scope points at the temporary build directory for our derivation. Some packages try different mechanisms -+ to find temporary directories, so we want to open up a broader place for them to put their files, if needed. */ -+ Path globalTmpDir = canonPath(defaultTempDir(), true); -+ -+ /* They don't like trailing slashes on subpath directives */ -+ while (!globalTmpDir.empty() && globalTmpDir.back() == '/') -+ globalTmpDir.pop_back(); -+ -+ if (getEnv("_NIX_TEST_NO_SANDBOX") != "1") { -+ Strings sandboxArgs; -+ sandboxArgs.push_back("_GLOBAL_TMP_DIR"); -+ sandboxArgs.push_back(globalTmpDir); -+ if (allowLocalNetworking) { -+ sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); -+ sandboxArgs.push_back("1"); -+ } -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -+ writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ _exit(1); - } - } -+ -+ builder = drv->builder; -+ args.push_back(std::string(baseNameOf(drv->builder))); - #else -- else { -+ if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/git/0003-packaging-Add-darwin-lsandbox-in-meson.patch b/pkgs/tools/package-management/nix/patches/git/0003-packaging-Add-darwin-lsandbox-in-meson.patch deleted file mode 100644 index 0dfbd10ab1e8..000000000000 --- a/pkgs/tools/package-management/nix/patches/git/0003-packaging-Add-darwin-lsandbox-in-meson.patch +++ /dev/null @@ -1,53 +0,0 @@ -From f7335530619f9b18d6cc249a297e4dca369101a5 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:23:17 +0200 -Subject: [PATCH 3/6] packaging: Add darwin -lsandbox in meson -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - src/libstore/meson.build | 5 +++++ - src/libstore/package.nix | 2 ++ - 2 files changed, 7 insertions(+) - -diff --git a/src/libstore/meson.build b/src/libstore/meson.build -index 6a6aabf97..c2aa5bff3 100644 ---- a/src/libstore/meson.build -+++ b/src/libstore/meson.build -@@ -69,6 +69,11 @@ has_acl_support = cxx.has_header('sys/xattr.h') \ - and cxx.has_function('lremovexattr') - configdata.set('HAVE_ACL_SUPPORT', has_acl_support.to_int()) - -+if host_machine.system() == 'darwin' -+ sandbox = cxx.find_library('sandbox') -+ deps_other += [sandbox] -+endif -+ - subdir('build-utils-meson/threads') - - boost = dependency( -diff --git a/src/libstore/package.nix b/src/libstore/package.nix -index 9568462b5..f04e3b95f 100644 ---- a/src/libstore/package.nix -+++ b/src/libstore/package.nix -@@ -3,6 +3,7 @@ - , mkMesonLibrary - - , unixtools -+, darwin - - , nix-util - , boost -@@ -56,6 +57,7 @@ mkMesonLibrary (finalAttrs: { - sqlite - ] ++ lib.optional stdenv.hostPlatform.isLinux libseccomp - # There have been issues building these dependencies -+ ++ lib.optional stdenv.hostPlatform.isDarwin darwin.apple_sdk.libs.sandbox - ++ lib.optional (stdenv.hostPlatform == stdenv.buildPlatform && (stdenv.isLinux || stdenv.isDarwin)) - aws-sdk-cpp - ; --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/git/0004-local-derivation-goal-Print-sandbox-error-detail-on-.patch b/pkgs/tools/package-management/nix/patches/git/0004-local-derivation-goal-Print-sandbox-error-detail-on-.patch deleted file mode 100644 index 4bff61efdf7f..000000000000 --- a/pkgs/tools/package-management/nix/patches/git/0004-local-derivation-goal-Print-sandbox-error-detail-on-.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 14d09e0b55898ac22d4cdeade3bf6c4174052ffd Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:44:12 +0200 -Subject: [PATCH 4/6] local-derivation-goal: Print sandbox error detail on - darwin -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index 067755c0d..f34d68403 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2208,8 +2208,9 @@ void LocalDerivationGoal::runChild() - sandboxArgs.push_back("_ALLOW_LOCAL_NETWORKING"); - sandboxArgs.push_back("1"); - } -- if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), NULL)) { -- writeFull(STDERR_FILENO, "failed to configure sandbox\n"); -+ char * sandbox_errbuf = nullptr; -+ if (sandbox_init_with_parameters(sandboxProfile.c_str(), 0, stringsToCharPtrs(sandboxArgs).data(), &sandbox_errbuf)) { -+ writeFull(STDERR_FILENO, fmt("failed to configure sandbox: %s\n", sandbox_errbuf ? sandbox_errbuf : "(null)")); - _exit(1); - } - } --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/git/0005-local-derivation-goal-Refactor.patch b/pkgs/tools/package-management/nix/patches/git/0005-local-derivation-goal-Refactor.patch deleted file mode 100644 index cec9d67513ed..000000000000 --- a/pkgs/tools/package-management/nix/patches/git/0005-local-derivation-goal-Refactor.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 06e27042e176b79561f50decb0fdf836b7bec3f5 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:50:27 +0200 -Subject: [PATCH 5/6] local-derivation-goal: Refactor -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This works because the `builder` and `args` variables are only used -in the non-builtin code path. - -Co-Authored-By: Théophane Hufschmitt -Signed-off-by: Jörg Thalheim ---- - src/libstore/unix/build/local-derivation-goal.cc | 5 +---- - 1 file changed, 1 insertion(+), 4 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index f34d68403..f781a84c6 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2214,15 +2214,12 @@ void LocalDerivationGoal::runChild() - _exit(1); - } - } -+#endif - -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); --#else - if (!drv->isBuiltin()) { - builder = drv->builder; - args.push_back(std::string(baseNameOf(drv->builder))); - } --#endif - - for (auto & i : drv->args) - args.push_back(rewriteStrings(i, inputRewrites)); --- -2.46.1 - diff --git a/pkgs/tools/package-management/nix/patches/git/0006-local-derivation-goal-Move-builder-preparation-to-no.patch b/pkgs/tools/package-management/nix/patches/git/0006-local-derivation-goal-Move-builder-preparation-to-no.patch deleted file mode 100644 index 4e63db1f183e..000000000000 --- a/pkgs/tools/package-management/nix/patches/git/0006-local-derivation-goal-Move-builder-preparation-to-no.patch +++ /dev/null @@ -1,75 +0,0 @@ -From d1e0bae55afb3c3ef0bcad5d644b0e04da6279b3 Mon Sep 17 00:00:00 2001 -From: Robert Hensing -Date: Thu, 3 Oct 2024 12:57:00 +0200 -Subject: [PATCH 6/6] local-derivation-goal: Move builder preparation to - non-builtin code path -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Signed-off-by: Jörg Thalheim ---- - .../unix/build/local-derivation-goal.cc | 25 ++++++++----------- - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/src/libstore/unix/build/local-derivation-goal.cc b/src/libstore/unix/build/local-derivation-goal.cc -index f781a84c6..dcfaadeef 100644 ---- a/src/libstore/unix/build/local-derivation-goal.cc -+++ b/src/libstore/unix/build/local-derivation-goal.cc -@@ -2087,11 +2087,6 @@ void LocalDerivationGoal::runChild() - throw SysError("setuid failed"); - } - -- /* Fill in the arguments. */ -- Strings args; -- -- std::string builder = "invalid"; -- - #if __APPLE__ - /* This has to appear before import statements. */ - std::string sandboxProfile = "(version 1)\n"; -@@ -2216,14 +2211,6 @@ void LocalDerivationGoal::runChild() - } - #endif - -- if (!drv->isBuiltin()) { -- builder = drv->builder; -- args.push_back(std::string(baseNameOf(drv->builder))); -- } -- -- for (auto & i : drv->args) -- args.push_back(rewriteStrings(i, inputRewrites)); -- - /* Indicate that we managed to set up the build environment. */ - writeFull(STDERR_FILENO, std::string("\2\n")); - -@@ -2254,6 +2241,14 @@ void LocalDerivationGoal::runChild() - } - } - -+ // Now builder is not builtin -+ -+ Strings args; -+ args.push_back(std::string(baseNameOf(drv->builder))); -+ -+ for (auto & i : drv->args) -+ args.push_back(rewriteStrings(i, inputRewrites)); -+ - #if __APPLE__ - posix_spawnattr_t attrp; - -@@ -2275,9 +2270,9 @@ void LocalDerivationGoal::runChild() - posix_spawnattr_setbinpref_np(&attrp, 1, &cpu, NULL); - } - -- posix_spawn(NULL, builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ posix_spawn(NULL, drv->builder.c_str(), NULL, &attrp, stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #else -- execve(builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); -+ execve(drv->builder.c_str(), stringsToCharPtrs(args).data(), stringsToCharPtrs(envStrs).data()); - #endif - - throw SysError("executing '%1%'", drv->builder); --- -2.46.1 - From 1b4d918680b2625619461fa4020b62cc1af71887 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:15:29 +0100 Subject: [PATCH 06/49] nixVersions.nix_2_18: 2.18.8 -> 2.18.9 Diff: https://github.com/NixOS/nix/compare/2.18.8...2.18.9 --- pkgs/tools/package-management/nix/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index adfa793f1d35..f8664914dca7 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -175,8 +175,8 @@ in lib.makeExtensible (self: ({ }; nix_2_18 = common { - version = "2.18.8"; - hash = "sha256-0rHRifdjzzxMh/im8pRx6XoY62irDTDUes+Pn0CR65I="; + version = "2.18.9"; + hash = "sha256-RrOFlDGmRXcVRV2p2HqHGqvzGNyWoD0Dado/BNlJ1SI="; self_attribute_name = "nix_2_18"; }; From f99840d380a37545f46a60b57d0abbcac99267de Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:17:29 +0100 Subject: [PATCH 07/49] nixVersions.nix_2_19: 2.19.6 -> 2.19.7 Diff: https://github.com/NixOS/nix/compare/2.19.6...2.19.7 --- pkgs/tools/package-management/nix/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index f8664914dca7..b11a35fb02c8 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -181,8 +181,8 @@ in lib.makeExtensible (self: ({ }; nix_2_19 = common { - version = "2.19.6"; - hash = "sha256-XT5xiwOLgXf+TdyOjbJVOl992wu9mBO25WXHoyli/Tk="; + version = "2.19.7"; + hash = "sha256-CkT1SNwRYYQdN2X4cTt1WX3YZfKZFWf7O1YTEo1APfc="; self_attribute_name = "nix_2_19"; }; From 381a7120421c95970c7e66539fa19104814a46f5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:19:55 +0100 Subject: [PATCH 08/49] nixVersions.nix_2_20: 2.20.8 -> 2.20.9 Diff: https://github.com/NixOS/nix/compare/2.20.8...2.20.9 --- pkgs/tools/package-management/nix/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index b11a35fb02c8..658b12c2526e 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -187,8 +187,8 @@ in lib.makeExtensible (self: ({ }; nix_2_20 = common { - version = "2.20.8"; - hash = "sha256-M2tkMtjKi8LDdNLsKi3IvD8oY/i3rtarjMpvhybS3WY="; + version = "2.20.9"; + hash = "sha256-b7smrbPLP/wcoBFCJ8j1UDNj0p4jiKT/6mNlDdlrOXA="; self_attribute_name = "nix_2_20"; }; From 107532d6644422916f9957d3a26354fc01b3fc8e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:22:31 +0100 Subject: [PATCH 09/49] nixVersions.nix_2_21: 2.21.4 -> 2.21.5 Diff: https://github.com/NixOS/nix/compare/2.21.4...2.21.5 --- pkgs/tools/package-management/nix/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index 658b12c2526e..b95b17f9978e 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -193,8 +193,8 @@ in lib.makeExtensible (self: ({ }; nix_2_21 = common { - version = "2.21.4"; - hash = "sha256-c6nVZ0pSrfhFX3eVKqayS+ioqyAGp3zG9ZPO5rkXFRQ="; + version = "2.21.5"; + hash = "sha256-/+TLpd6hvYMJFoeJvVZ+bZzjwY/jP6CxJRGmwKcXbI0="; self_attribute_name = "nix_2_21"; }; From c0b0c7f9591693291bb0f66a70632ec6c8384122 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:27:44 +0100 Subject: [PATCH 10/49] nixVersions.nix_2_23: 2.23.3 -> 2.23.4 Diff: https://github.com/NixOS/nix/compare/2.23.3...2.23.4 --- pkgs/tools/package-management/nix/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index b95b17f9978e..0b39bbbb288c 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -199,14 +199,14 @@ in lib.makeExtensible (self: ({ }; nix_2_22 = common { - version = "2.22.3"; - hash = "sha256-l04csH5rTWsK7eXPWVxJBUVRPMZXllFoSkYFTq/i8WU="; + version = "2.22.4"; + hash = "sha256-JWjJzMA+CeyImMgP2dhSBHQW4CS8wg7fc2zQ4WdKuBo="; self_attribute_name = "nix_2_22"; }; nix_2_23 = common { - version = "2.23.3"; - hash = "sha256-lAoLGVIhRFrfgv7wcyduEkyc83QKrtsfsq4of+WrBeg="; + version = "2.23.4"; + hash = "sha256-rugH4TUicHEdVfy3UuAobFIutqbuVco8Yg/z81g7clE="; self_attribute_name = "nix_2_23"; }; From 61788950c3f2291d51ceb031f329f5579ad3d0bb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:30:24 +0100 Subject: [PATCH 11/49] nixVersions.nix_2_24: 2.24.9 -> 2.24.10 Diff: https://github.com/NixOS/nix/compare/2.24.9...2.24.10 --- pkgs/tools/package-management/nix/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index 0b39bbbb288c..1f1849ee58b8 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -211,8 +211,8 @@ in lib.makeExtensible (self: ({ }; nix_2_24 = (common { - version = "2.24.9"; - hash = "sha256-OwJByTdCz1t91ysBqynK+ifszkoIGEXUn6HE2t82+c8="; + version = "2.24.10"; + hash = "sha256-XdeVy1/d6DEIYb3nOA6JIYF4fwMKNxtwJMgT3pHi+ko="; self_attribute_name = "nix_2_24"; }).override (lib.optionalAttrs (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isx86_64) { # Fix the following error with the default x86_64-darwin SDK: From 76228da81c99ff7dafa2db854c9648db2b45b196 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:36:49 +0100 Subject: [PATCH 12/49] nixVersions.git: 2.25.0pre20240920_ca3fc169 -> 2.24.10-unstable-2024-11-01 Diff: https://github.com/NixOS/nix/compare/ca3fc1693b309ab6b8b0c09408a08d0055bf0363...2e5759e3778c460efc5f7cfc4cb0b84827b5ffbe --- pkgs/tools/package-management/nix/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/tools/package-management/nix/default.nix b/pkgs/tools/package-management/nix/default.nix index 1f1849ee58b8..1a3ac948c0b5 100644 --- a/pkgs/tools/package-management/nix/default.nix +++ b/pkgs/tools/package-management/nix/default.nix @@ -227,12 +227,12 @@ in lib.makeExtensible (self: ({ git = (common rec { version = "2.25.0"; - suffix = "pre20240920_${lib.substring 0 8 src.rev}"; + suffix = "pre20241101_${lib.substring 0 8 src.rev}"; src = fetchFromGitHub { owner = "NixOS"; repo = "nix"; - rev = "ca3fc1693b309ab6b8b0c09408a08d0055bf0363"; - hash = "sha256-Hp7dkx7zfB9a4l5QusXUob0b1T2qdZ23LFo5dcp3xrU="; + rev = "2e5759e3778c460efc5f7cfc4cb0b84827b5ffbe"; + hash = "sha256-E1Sp0JHtbD1CaGO3UbBH6QajCtOGqcrVfPSKL0n63yo="; }; self_attribute_name = "git"; }).override (lib.optionalAttrs (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isx86_64) { From 17c0b43ad5e3a1e7eb2c9af8814bd238a05e19e4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Fri, 1 Nov 2024 11:48:37 +0100 Subject: [PATCH 13/49] nix: add script to update releases --- .../package-management/nix/update-all.sh | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100755 pkgs/tools/package-management/nix/update-all.sh diff --git a/pkgs/tools/package-management/nix/update-all.sh b/pkgs/tools/package-management/nix/update-all.sh new file mode 100755 index 000000000000..00a5bea82169 --- /dev/null +++ b/pkgs/tools/package-management/nix/update-all.sh @@ -0,0 +1,23 @@ +#!/usr/bin/env nix-shell +#!nix-shell -i bash -p bash nix-update jq + +set -xeuo pipefail + +SCRIPT_DIR=$(dirname "$(readlink -f "$0")") +NIXPKGS_DIR=$(readlink -f "$SCRIPT_DIR/../../../..") +cd "$NIXPKGS_DIR" + +nix_versions=$(nix eval --impure --json --expr "with import ./. { config.allowAliases = false; }; builtins.filter (name: builtins.match \"nix_.*\" name != null) (builtins.attrNames nixVersions)" | jq -r '.[]') +for name in $nix_versions; do + minor_version=${name#nix_*_} + if [[ "$name" = "nix_2_3" ]]; then # not maintained by the nix team + continue + fi + nix-update --override-filename "$SCRIPT_DIR/default.nix" --version-regex "(2\\.${minor_version}\..+)" --build --commit "nixVersions.$name" +done + +commit_json=$(curl -s https://api.github.com/repos/NixOS/nix/commits/master) # format: 2024-11-01T10:18:53Z +date_of_commit=$(echo "$commit_json" | jq -r '.commit.author.date') +suffix="pre$(date -d "$date_of_commit" +%Y%m%d)_" +sed -i -e "s|\"pre[0-9]\{8\}_|\"$suffix|g" "$SCRIPT_DIR/default.nix" +nix-update --override-filename "$SCRIPT_DIR/default.nix" --version branch --build --commit "nixVersions.git" From f83f99270023d739b4ab3fa51f39778165bb4920 Mon Sep 17 00:00:00 2001 From: Dixon Sean Low Yan Feng Date: Sat, 2 Nov 2024 12:02:02 +0800 Subject: [PATCH 14/49] catppuccin-cursors: 1.0.0 -> 1.0.1 --- pkgs/by-name/ca/catppuccin-cursors/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ca/catppuccin-cursors/package.nix b/pkgs/by-name/ca/catppuccin-cursors/package.nix index 57357ea47c2b..bc85007b0c67 100644 --- a/pkgs/by-name/ca/catppuccin-cursors/package.nix +++ b/pkgs/by-name/ca/catppuccin-cursors/package.nix @@ -40,7 +40,7 @@ let }; variantName = { palette, color }: palette + color; variants = lib.mapCartesianProduct variantName dimensions; - version = "1.0.0"; + version = "1.0.1"; in stdenvNoCC.mkDerivation { pname = "catppuccin-cursors"; @@ -50,7 +50,7 @@ stdenvNoCC.mkDerivation { owner = "catppuccin"; repo = "cursors"; rev = "v${version}"; - hash = "sha256-LZ2k8i4w68VW4YFmC659iMQsQyduHJOfyL8cLlXhUHo="; + hash = "sha256-l01L0UiE9bgUOMHhs74Bndarw2b6TaJGW/xU/8rfoAk="; }; nativeBuildInputs = [ From 06c36180659773211e650bafde9b25e1a0d958ee Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 2 Nov 2024 09:25:13 +0100 Subject: [PATCH 15/49] python312Packages.meshtastic: 2.5.3 -> 2.5.4 Diff: https://github.com/meshtastic/Meshtastic-python/compare/refs/tags/2.5.3...2.5.4 Changelog: https://github.com/meshtastic/python/releases/tag/2.5.4 --- pkgs/development/python-modules/meshtastic/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/meshtastic/default.nix b/pkgs/development/python-modules/meshtastic/default.nix index b285141cf06a..e2bc68074ee4 100644 --- a/pkgs/development/python-modules/meshtastic/default.nix +++ b/pkgs/development/python-modules/meshtastic/default.nix @@ -33,7 +33,7 @@ buildPythonPackage rec { pname = "meshtastic"; - version = "2.5.3"; + version = "2.5.4"; pyproject = true; disabled = pythonOlder "3.7"; @@ -42,7 +42,7 @@ buildPythonPackage rec { owner = "meshtastic"; repo = "Meshtastic-python"; rev = "refs/tags/${version}"; - hash = "sha256-6U/oAVqzNsKFgNtQPzDovoWR23J0Ax0ssCIUjjRVeR4="; + hash = "sha256-A1C+xkQFjoEMKyz9S7T/GzZYrcznpi/9yjBmue1Ahu4="; }; pythonRelaxDeps = [ From cbc4b05d384491a7610f16757ee0e8f8ad8983c5 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 2 Nov 2024 11:01:05 +0100 Subject: [PATCH 16/49] dep-scan: 5.4.3 -> 5.4.8 Diff: https://github.com/owasp-dep-scan/dep-scan/compare/refs/tags/v5.4.3...v5.4.8 Changelog: https://github.com/owasp-dep-scan/dep-scan/releases/tag/v5.4.8 --- pkgs/by-name/de/dep-scan/package.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/de/dep-scan/package.nix b/pkgs/by-name/de/dep-scan/package.nix index 1aac043fcf83..561d97debfa1 100644 --- a/pkgs/by-name/de/dep-scan/package.nix +++ b/pkgs/by-name/de/dep-scan/package.nix @@ -7,10 +7,10 @@ let appthreat-vulnerability-db = ( python3.pkgs.appthreat-vulnerability-db.overrideAttrs (oldAttrs: rec { - version = "5.7.3"; + version = "5.7.8"; src = oldAttrs.src.override { rev = "refs/tags/v${version}"; - hash = "sha256-MrlgBUx3T2G46Pnah3obe5b4yKDzsAFVC/B7AHM0kZY="; + hash = "sha256-R00/a9+1NctVPi+EL7K65w/e88c9oSW5xXGgno+MCXo="; }; }) ); @@ -18,16 +18,18 @@ let in python3.pkgs.buildPythonApplication rec { pname = "dep-scan"; - version = "5.4.3"; + version = "5.4.8"; pyproject = true; src = fetchFromGitHub { owner = "owasp-dep-scan"; repo = "dep-scan"; rev = "refs/tags/v${version}"; - hash = "sha256-m0vDsCetOSfScu1eprrGaDJ1VuXxuNFBitK8N5GtfSQ="; + hash = "sha256-QTvxKoqBxTb/xFaIHsYe3N+7ABJ6sDd2vVcjkMbm3xI="; }; + pythonRelaxDeps = [ "oras" ]; + build-system = with python3.pkgs; [ setuptools ]; dependencies = with python3.pkgs; [ From c14a9572885b6ac684a10cea1c29f7bdc37ac085 Mon Sep 17 00:00:00 2001 From: happysalada Date: Sat, 2 Nov 2024 06:33:59 -0400 Subject: [PATCH 17/49] python312Packages.litellm: 1.48.6 -> 1.51.2 --- pkgs/development/python-modules/litellm/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/litellm/default.nix b/pkgs/development/python-modules/litellm/default.nix index 466d750da078..89f32222a762 100644 --- a/pkgs/development/python-modules/litellm/default.nix +++ b/pkgs/development/python-modules/litellm/default.nix @@ -37,7 +37,7 @@ buildPythonPackage rec { pname = "litellm"; - version = "1.48.6"; + version = "1.51.2"; pyproject = true; disabled = pythonOlder "3.8"; @@ -46,7 +46,7 @@ buildPythonPackage rec { owner = "BerriAI"; repo = "litellm"; rev = "refs/tags/v${version}"; - hash = "sha256-7Or9rZGehejSYv0/5M7PNPNtoSt28DSHBiWXcJutD2I="; + hash = "sha256-jC5BiD4JFfsiyNOSlY6rH6l3Dk6AKKXJ8+Q6MTGYTpM="; }; build-system = [ poetry-core ]; From de1d45059e60fb905b8b58a042ef860b998e98a0 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 19 Oct 2024 21:16:37 +0200 Subject: [PATCH 18/49] python312Packages.pygit2: 1.15.1 -> 1.16.0 Changelog: https://github.com/libgit2/pygit2/blob/v1.16.0/CHANGELOG.md --- pkgs/development/python-modules/pygit2/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pygit2/default.nix b/pkgs/development/python-modules/pygit2/default.nix index bfd0b7507f57..f9310c711e5f 100644 --- a/pkgs/development/python-modules/pygit2/default.nix +++ b/pkgs/development/python-modules/pygit2/default.nix @@ -16,14 +16,14 @@ buildPythonPackage rec { pname = "pygit2"; - version = "1.15.1"; + version = "1.16.0"; pyproject = true; disabled = pythonOlder "3.9"; src = fetchPypi { inherit pname version; - hash = "sha256-4f6LhQU9lxMEPIHszHQTL55bYD8gnoBzPXlV6v0i650="; + hash = "sha256-eymmeWuqFfyJ1EOsjVF3VBHZseWwbcQNRYxWyFdrSKI="; }; preConfigure = lib.optionalString stdenv.hostPlatform.isDarwin '' From fc857b618b22329b8a6172e8d054e1ffb48f429a Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 19 Oct 2024 21:16:57 +0200 Subject: [PATCH 19/49] tartufo: 5.0.1 -> 5.0.2 Diff: https://github.com/godaddy/tartufo/compare/refs/tags/v5.0.1...v5.0.2 Changelog: https://github.com/godaddy/tartufo/blob/refs/tags/v5.0.2/CHANGELOG.md --- pkgs/by-name/ta/tartufo/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ta/tartufo/package.nix b/pkgs/by-name/ta/tartufo/package.nix index 1ee23cf2516c..92cd656bd7e0 100644 --- a/pkgs/by-name/ta/tartufo/package.nix +++ b/pkgs/by-name/ta/tartufo/package.nix @@ -6,14 +6,14 @@ python3.pkgs.buildPythonApplication rec { pname = "tartufo"; - version = "5.0.1"; + version = "5.0.2"; pyproject = true; src = fetchFromGitHub { owner = "godaddy"; repo = "tartufo"; rev = "refs/tags/v${version}"; - hash = "sha256-mwwenmSCxnzD2DLf1a/dsQjwJ2GetMgRGj/noqWJ/E0="; + hash = "sha256-s7gqGvOnie7lGlpW3wfd8igWfowxwg9mftRjiHnvedc="; }; pythonRelaxDeps = [ "tomlkit" ]; From 4765d1a9741049e43abdbb16a6275e4329e59ff6 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 2 Nov 2024 11:37:31 +0100 Subject: [PATCH 20/49] python311Packages.git-annex-adapter: disable failing tests --- pkgs/development/python-modules/git-annex-adapter/default.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/git-annex-adapter/default.nix b/pkgs/development/python-modules/git-annex-adapter/default.nix index 7778ecd9ca88..e84c2321aaee 100644 --- a/pkgs/development/python-modules/git-annex-adapter/default.nix +++ b/pkgs/development/python-modules/git-annex-adapter/default.nix @@ -65,9 +65,11 @@ buildPythonPackage rec { disabledTests = [ # KeyError and AssertionError + "test_annex_keys" + "test_batchjson_metadata" + "test_file_tree" "test_jsonprocess_annex_metadata_batch" "test_process_annex_metadata_batch" - "test_batchjson_metadata" ]; meta = with lib; { From 2432363385b9e705ab2b48dc905b065881f29da2 Mon Sep 17 00:00:00 2001 From: happysalada Date: Sat, 2 Nov 2024 07:02:03 -0400 Subject: [PATCH 21/49] aider-chat: 0.60.0 -> 0.61.0 --- pkgs/by-name/ai/aider-chat/package.nix | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ai/aider-chat/package.nix b/pkgs/by-name/ai/aider-chat/package.nix index 2b2e9cc9dbbe..400cce650f94 100644 --- a/pkgs/by-name/ai/aider-chat/package.nix +++ b/pkgs/by-name/ai/aider-chat/package.nix @@ -12,7 +12,7 @@ let self = python3; packageOverrides = _: super: { tree-sitter = super.tree-sitter_0_21; }; }; - version = "0.60.0"; + version = "0.61.0"; in python3.pkgs.buildPythonApplication { pname = "aider-chat"; @@ -23,7 +23,7 @@ python3.pkgs.buildPythonApplication { owner = "Aider-AI"; repo = "aider"; rev = "refs/tags/v${version}"; - hash = "sha256-0jAdUcGGJzxvTKY/56an0oLEghZHz6fdNLg8cPer1Qc="; + hash = "sha256-C1VMdLRb+FVN8zwWRa7RCkRxZgdUPNUfBdAjMi9efjQ="; }; pythonRelaxDeps = true; @@ -113,6 +113,13 @@ python3.pkgs.buildPythonApplication { wcwidth yarl zipp + + # Not listed in requirements + mixpanel + monotonic + posthog + propcache + python-dateutil ]; buildInputs = [ portaudio ]; @@ -151,6 +158,15 @@ python3.pkgs.buildPythonApplication { export AIDER_CHECK_UPDATE=false ''; + optional-dependencies = with python3.pkgs; { + playwright = [ + greenlet + playwright + pyee + typing-extensions + ]; + }; + meta = { description = "AI pair programming in your terminal"; homepage = "https://github.com/paul-gauthier/aider"; From 4a1d5d1e4e94a6f074767f7ac83a91a5b5c27565 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9=20Vitor=20de=20Lima=20Matos?= Date: Sat, 2 Nov 2024 08:05:44 -0300 Subject: [PATCH 22/49] pgadmin4: fix service start issue systemd service unit currently fails with requiring `pkg_resources` to be available --- pkgs/tools/admin/pgadmin/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/tools/admin/pgadmin/default.nix b/pkgs/tools/admin/pgadmin/default.nix index 4047c572fb80..57300e9798a3 100644 --- a/pkgs/tools/admin/pgadmin/default.nix +++ b/pkgs/tools/admin/pgadmin/default.nix @@ -205,6 +205,7 @@ pythonPackages.buildPythonApplication rec { rich jsonformatter libgravatar + setuptools ]; passthru.tests = { From 885b88c6a6fd51af55163123209ffaefe339e8e3 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 2 Nov 2024 13:27:46 +0100 Subject: [PATCH 23/49] python312Packages.sensorpush-ble: 1.7.0 -> 1.7.1 Diff: https://github.com/Bluetooth-Devices/sensorpush-ble/compare/refs/tags/v1.7.0...v1.7.1 Changelog: https://github.com/Bluetooth-Devices/sensorpush-ble/releases/tag/v1.7.1 --- pkgs/development/python-modules/sensorpush-ble/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/sensorpush-ble/default.nix b/pkgs/development/python-modules/sensorpush-ble/default.nix index e8fb3446dd95..2281fdcd60fd 100644 --- a/pkgs/development/python-modules/sensorpush-ble/default.nix +++ b/pkgs/development/python-modules/sensorpush-ble/default.nix @@ -14,7 +14,7 @@ buildPythonPackage rec { pname = "sensorpush-ble"; - version = "1.7.0"; + version = "1.7.1"; pyproject = true; disabled = pythonOlder "3.10"; @@ -23,7 +23,7 @@ buildPythonPackage rec { owner = "Bluetooth-Devices"; repo = "sensorpush-ble"; rev = "refs/tags/v${version}"; - hash = "sha256-etsrXJn6n9yL0vhiZNnTepCcau50X0t2wPrhZ9R7XL4="; + hash = "sha256-T2sjzQoWWRGAKiMDN29jZ7jZ5/i75qpNCiuVB7VEhJw="; }; build-system = [ poetry-core ]; From 7a0875b4c0be084e34bfa882e174b80fcd2ddd9a Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 2 Nov 2024 13:51:36 +0100 Subject: [PATCH 24/49] python312Packages.aiocomelit: 0.9.1 -> 0.10.0 Diff: https://github.com/chemelli74/aiocomelit/compare/refs/tags/v0.9.1...v0.10.0 Changelog: https://github.com/chemelli74/aiocomelit/blob/0.10.0/CHANGELOG.md --- pkgs/development/python-modules/aiocomelit/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/aiocomelit/default.nix b/pkgs/development/python-modules/aiocomelit/default.nix index c79904c5d05f..2fe16b53a0b2 100644 --- a/pkgs/development/python-modules/aiocomelit/default.nix +++ b/pkgs/development/python-modules/aiocomelit/default.nix @@ -12,7 +12,7 @@ buildPythonPackage rec { pname = "aiocomelit"; - version = "0.9.1"; + version = "0.10.0"; pyproject = true; disabled = pythonOlder "3.10"; @@ -21,7 +21,7 @@ buildPythonPackage rec { owner = "chemelli74"; repo = "aiocomelit"; rev = "refs/tags/v${version}"; - hash = "sha256-3r9DyvzqtQ88VwKCghAC9nn5kXbBzbR8drTFTnWC/bM="; + hash = "sha256-5XyCc/OMFA99qwVjsVLCA4NedvcDBSSBzG8TvSg4sk0="; }; postPatch = '' From d07295e32407ea6765346f44ecd26e964d23077e Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 2 Nov 2024 13:57:40 +0100 Subject: [PATCH 25/49] python312Packages.aiocomelit: refactor --- .../python-modules/aiocomelit/default.nix | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/pkgs/development/python-modules/aiocomelit/default.nix b/pkgs/development/python-modules/aiocomelit/default.nix index 2fe16b53a0b2..a3cdc57503be 100644 --- a/pkgs/development/python-modules/aiocomelit/default.nix +++ b/pkgs/development/python-modules/aiocomelit/default.nix @@ -6,6 +6,7 @@ fetchFromGitHub, pint, poetry-core, + pytest-cov-stub, pytestCheckHook, pythonOlder, }: @@ -15,7 +16,7 @@ buildPythonPackage rec { version = "0.10.0"; pyproject = true; - disabled = pythonOlder "3.10"; + disabled = pythonOlder "3.12"; src = fetchFromGitHub { owner = "chemelli74"; @@ -24,20 +25,16 @@ buildPythonPackage rec { hash = "sha256-5XyCc/OMFA99qwVjsVLCA4NedvcDBSSBzG8TvSg4sk0="; }; - postPatch = '' - substituteInPlace pyproject.toml \ - --replace-fail " --cov=aiocomelit --cov-report=term-missing:skip-covered" "" - ''; + build-system = [ poetry-core ]; - nativeBuildInputs = [ poetry-core ]; - - propagatedBuildInputs = [ + dependencies = [ aiohttp + colorlog pint ]; nativeCheckInputs = [ - colorlog + pytest-cov-stub pytestCheckHook ]; @@ -46,7 +43,7 @@ buildPythonPackage rec { meta = with lib; { description = "Library to control Comelit Simplehome"; homepage = "https://github.com/chemelli74/aiocomelit"; - changelog = "https://github.com/chemelli74/aiocomelit/blob/${version}/CHANGELOG.md"; + changelog = "https://github.com/chemelli74/aiocomelit/blob/v${version}/CHANGELOG.md"; license = licenses.asl20; maintainers = with maintainers; [ fab ]; }; From aab8fb80e66bbcba3f7eda4954102f4c333533ae Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sat, 2 Nov 2024 14:10:20 +0100 Subject: [PATCH 26/49] python312Packages.deezer-python: move tornado to nativeCheckInputs --- pkgs/development/python-modules/deezer-python/default.nix | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/deezer-python/default.nix b/pkgs/development/python-modules/deezer-python/default.nix index 2bd84de62eb2..78d31ec97224 100644 --- a/pkgs/development/python-modules/deezer-python/default.nix +++ b/pkgs/development/python-modules/deezer-python/default.nix @@ -29,10 +29,7 @@ buildPythonPackage rec { build-system = [ poetry-core ]; - dependencies = [ - httpx - tornado - ]; + dependencies = [ httpx ]; nativeCheckInputs = [ environs @@ -40,6 +37,7 @@ buildPythonPackage rec { pytest-mock pytest-vcr pytestCheckHook + tornado ]; pythonImportsCheck = [ "deezer" ]; From a754e8164970c5a53db4b2b9b84d939e8e83d951 Mon Sep 17 00:00:00 2001 From: John Titor <50095635+JohnRTitor@users.noreply.github.com> Date: Sat, 2 Nov 2024 21:10:57 +0530 Subject: [PATCH 27/49] hypridle: 0.1.4 -> 0.1.5 add passthru.updateScript --- pkgs/by-name/hy/hypridle/package.nix | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/hy/hypridle/package.nix b/pkgs/by-name/hy/hypridle/package.nix index 05ce061e19ca..34de210fc5c0 100644 --- a/pkgs/by-name/hy/hypridle/package.nix +++ b/pkgs/by-name/hy/hypridle/package.nix @@ -11,17 +11,18 @@ hyprlang, sdbus-cpp_2, systemd, + nix-update-script, }: stdenv.mkDerivation (finalAttrs: { pname = "hypridle"; - version = "0.1.4"; + version = "0.1.5"; src = fetchFromGitHub { owner = "hyprwm"; repo = "hypridle"; rev = "v${finalAttrs.version}"; - hash = "sha256-20a3pg94dyLFflbBIN+EYJ04nWfWldTfd2YmB/rcrqY="; + hash = "sha256-esE2L7+9CsmlSjTIHwU9VAhzvsFSMC3kO7EiutCPQpg="; }; nativeBuildInputs = [ @@ -39,6 +40,10 @@ stdenv.mkDerivation (finalAttrs: { wayland-protocols ]; + passthru = { + updateScript = nix-update-script { }; + }; + meta = { description = "Hyprland's idle daemon"; homepage = "https://github.com/hyprwm/hypridle"; From 30b1670361affd5308e7c2f0622983c916cb1362 Mon Sep 17 00:00:00 2001 From: John Titor <50095635+JohnRTitor@users.noreply.github.com> Date: Sat, 2 Nov 2024 21:13:15 +0530 Subject: [PATCH 28/49] hypridle: add johnrtitor as maintainer --- pkgs/by-name/hy/hypridle/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/hy/hypridle/package.nix b/pkgs/by-name/hy/hypridle/package.nix index 34de210fc5c0..370b99283a4c 100644 --- a/pkgs/by-name/hy/hypridle/package.nix +++ b/pkgs/by-name/hy/hypridle/package.nix @@ -50,6 +50,7 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.bsd3; maintainers = with lib.maintainers; [ iogamaster + johnrtitor khaneliman ]; mainProgram = "hypridle"; From 619980e7caee2c3ba0f28db78e8914509c24290b Mon Sep 17 00:00:00 2001 From: John Titor <50095635+JohnRTitor@users.noreply.github.com> Date: Sat, 2 Nov 2024 21:16:30 +0530 Subject: [PATCH 29/49] hypridle: systemd -> systemdLibs We only need `libsystemd`, so no need to import the whole `systemd` package. This can reduce the size. --- pkgs/by-name/hy/hypridle/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/hy/hypridle/package.nix b/pkgs/by-name/hy/hypridle/package.nix index 370b99283a4c..6265bd2dc005 100644 --- a/pkgs/by-name/hy/hypridle/package.nix +++ b/pkgs/by-name/hy/hypridle/package.nix @@ -10,7 +10,7 @@ wayland-scanner, hyprlang, sdbus-cpp_2, - systemd, + systemdLibs, nix-update-script, }: @@ -35,7 +35,7 @@ stdenv.mkDerivation (finalAttrs: { hyprlang hyprutils sdbus-cpp_2 - systemd + systemdLibs wayland wayland-protocols ]; From ba3e5b02f6114c253bda6f54725b8fdc7914dfa2 Mon Sep 17 00:00:00 2001 From: r-vdp Date: Sat, 2 Nov 2024 18:18:37 +0100 Subject: [PATCH 30/49] nixos/tools: set the enable options with mkDefault This makes it easier to enable some of them again. --- nixos/modules/installer/tools/tools.nix | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/nixos/modules/installer/tools/tools.nix b/nixos/modules/installer/tools/tools.nix index 6e3e2eb475f3..19b42c391abd 100644 --- a/nixos/modules/installer/tools/tools.nix +++ b/nixos/modules/installer/tools/tools.nix @@ -238,13 +238,13 @@ in config = lib.mkMerge [ (lib.mkIf config.system.disableInstallerTools { system.tools = { - nixos-build-vms.enable = false; - nixos-enter.enable = false; - nixos-generate-config.enable = false; - nixos-install.enable = false; - nixos-option.enable = false; - nixos-rebuild.enable = false; - nixos-version.enable = false; + nixos-build-vms.enable = lib.mkDefault false; + nixos-enter.enable = lib.mkDefault false; + nixos-generate-config.enable = lib.mkDefault false; + nixos-install.enable = lib.mkDefault false; + nixos-option.enable = lib.mkDefault false; + nixos-rebuild.enable = lib.mkDefault false; + nixos-version.enable = lib.mkDefault false; }; }) { From ab06b3bd6c52ba83a0131865820f1a8e695b33be Mon Sep 17 00:00:00 2001 From: Mika Tammi Date: Sat, 2 Nov 2024 18:54:21 +0200 Subject: [PATCH 31/49] python3Packages.accelerate: Add huggingface-hub Add huggingface-hub to the dependencies, this should fix various import errors. Signed-off-by: Mika Tammi --- pkgs/development/python-modules/accelerate/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/python-modules/accelerate/default.nix b/pkgs/development/python-modules/accelerate/default.nix index bcbd29bcc963..70c5ac7822c1 100644 --- a/pkgs/development/python-modules/accelerate/default.nix +++ b/pkgs/development/python-modules/accelerate/default.nix @@ -12,6 +12,7 @@ setuptools, # dependencies + huggingface-hub, numpy, packaging, psutil, @@ -45,6 +46,7 @@ buildPythonPackage rec { build-system = [ setuptools ]; dependencies = [ + huggingface-hub numpy packaging psutil From db21952673992c4d5a91154eb7d64039dc2f9f9c Mon Sep 17 00:00:00 2001 From: Mika Tammi Date: Sat, 2 Nov 2024 18:55:46 +0200 Subject: [PATCH 32/49] python3Packages.accelerate: 1.0.0 -> 1.1.0 Signed-off-by: Mika Tammi --- pkgs/development/python-modules/accelerate/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/accelerate/default.nix b/pkgs/development/python-modules/accelerate/default.nix index 70c5ac7822c1..54c29b54280e 100644 --- a/pkgs/development/python-modules/accelerate/default.nix +++ b/pkgs/development/python-modules/accelerate/default.nix @@ -31,14 +31,14 @@ buildPythonPackage rec { pname = "accelerate"; - version = "1.0.0"; + version = "1.1.0"; pyproject = true; src = fetchFromGitHub { owner = "huggingface"; repo = "accelerate"; rev = "refs/tags/v${version}"; - hash = "sha256-XVJqyhDSUPQDHdaB6GDxHhuC6EWCSZNArjzyLpvhQHI="; + hash = "sha256-GBNe4zomy8dmfvYrk/9Q77Z6r+JJA+2dgAhJx2opqAc="; }; buildInputs = [ llvmPackages.openmp ]; From f28e7aaed04b56f138fe3a13c13e835036d2a8dc Mon Sep 17 00:00:00 2001 From: Mika Tammi Date: Sat, 2 Nov 2024 19:35:07 +0200 Subject: [PATCH 33/49] python3Packages.accelerate: disable some tests darwin: Disable some tests, which started failing after enabling MPS in pytorch package. Signed-off-by: Mika Tammi --- .../python-modules/accelerate/default.nix | 25 +++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/pkgs/development/python-modules/accelerate/default.nix b/pkgs/development/python-modules/accelerate/default.nix index 54c29b54280e..ea8efbcad1b1 100644 --- a/pkgs/development/python-modules/accelerate/default.nix +++ b/pkgs/development/python-modules/accelerate/default.nix @@ -115,6 +115,31 @@ buildPythonPackage rec { "test_init_trackers" "test_log" "test_log_with_tensor" + + # After enabling MPS in pytorch, these tests started failing + "test_accelerated_optimizer_step_was_skipped" + "test_auto_wrap_policy" + "test_autocast_kwargs" + "test_automatic_loading" + "test_backward_prefetch" + "test_can_resume_training" + "test_can_resume_training_checkpoints_relative_path" + "test_can_resume_training_with_folder" + "test_can_unwrap_model_fp16" + "test_checkpoint_deletion" + "test_cpu_offload" + "test_cpu_ram_efficient_loading" + "test_grad_scaler_kwargs" + "test_invalid_registration" + "test_map_location" + "test_mixed_precision" + "test_mixed_precision_buffer_autocast_override" + "test_project_dir" + "test_project_dir_with_config" + "test_sharding_strategy" + "test_state_dict_type" + "test_with_save_limit" + "test_with_scheduler" ] ++ lib.optionals (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isx86_64) [ # RuntimeError: torch_shm_manager: execl failed: Permission denied From 2eb92f4063a3714d8168ef0669139be8abdbcffd Mon Sep 17 00:00:00 2001 From: r-vdp Date: Sat, 2 Nov 2024 19:03:29 +0100 Subject: [PATCH 34/49] fixup! nixos/tools: set the enable options with mkDefault --- nixos/modules/installer/tools/tools.nix | 33 ++++++++----------------- 1 file changed, 10 insertions(+), 23 deletions(-) diff --git a/nixos/modules/installer/tools/tools.nix b/nixos/modules/installer/tools/tools.nix index 19b42c391abd..34526c1b20a3 100644 --- a/nixos/modules/installer/tools/tools.nix +++ b/nixos/modules/installer/tools/tools.nix @@ -217,7 +217,7 @@ in imports = let mkToolModule = { name, package ? pkgs.${name} }: { config, ... }: { options.system.tools.${name}.enable = lib.mkEnableOption "${name} script" // { - default = config.nix.enable; + default = config.nix.enable && ! config.system.disableInstallerTools; internal = true; }; @@ -235,27 +235,14 @@ in (mkToolModule { name = "nixos-version"; package = nixos-version; }) ]; - config = lib.mkMerge [ - (lib.mkIf config.system.disableInstallerTools { - system.tools = { - nixos-build-vms.enable = lib.mkDefault false; - nixos-enter.enable = lib.mkDefault false; - nixos-generate-config.enable = lib.mkDefault false; - nixos-install.enable = lib.mkDefault false; - nixos-option.enable = lib.mkDefault false; - nixos-rebuild.enable = lib.mkDefault false; - nixos-version.enable = lib.mkDefault false; - }; - }) - { - documentation.man.man-db.skipPackages = [ nixos-version ]; + config = { + documentation.man.man-db.skipPackages = [ nixos-version ]; - # These may be used in auxiliary scripts (ie not part of toplevel), so they are defined unconditionally. - system.build = { - inherit nixos-generate-config nixos-install nixos-rebuild; - nixos-option = lib.warn "Accessing nixos-option through `config.system.build` is deprecated, use `pkgs.nixos-option` instead." pkgs.nixos-option; - nixos-enter = lib.warn "Accessing nixos-enter through `config.system.build` is deprecated, use `pkgs.nixos-enter` instead." pkgs.nixos-enter; - }; - } - ]; + # These may be used in auxiliary scripts (ie not part of toplevel), so they are defined unconditionally. + system.build = { + inherit nixos-generate-config nixos-install nixos-rebuild; + nixos-option = lib.warn "Accessing nixos-option through `config.system.build` is deprecated, use `pkgs.nixos-option` instead." pkgs.nixos-option; + nixos-enter = lib.warn "Accessing nixos-enter through `config.system.build` is deprecated, use `pkgs.nixos-enter` instead." pkgs.nixos-enter; + }; + }; } From 477731fb05c44e990225618eeb4c5be534cd35d9 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Sat, 2 Nov 2024 20:09:20 +0100 Subject: [PATCH 35/49] tuisky: init at 0.1.3 --- pkgs/by-name/tu/tuisky/package.nix | 50 ++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 pkgs/by-name/tu/tuisky/package.nix diff --git a/pkgs/by-name/tu/tuisky/package.nix b/pkgs/by-name/tu/tuisky/package.nix new file mode 100644 index 000000000000..76a045ebd204 --- /dev/null +++ b/pkgs/by-name/tu/tuisky/package.nix @@ -0,0 +1,50 @@ +{ + lib, + rustPlatform, + fetchFromGitHub, + pkg-config, + openssl, + versionCheckHook, + nix-update-script, +}: + +rustPlatform.buildRustPackage rec { + pname = "tuisky"; + version = "0.1.3"; + + src = fetchFromGitHub { + owner = "sugyan"; + repo = "tuisky"; + rev = "refs/tags/v${version}"; + hash = "sha256-TsxERi+xxWk6SJwIxMgqiYCAUrDLzZXPL1xQCIXtUr0="; + }; + + cargoHash = "sha256-p6Yqg4HdkviuOuYMGEPXyySduiS47aPOshr5iXE+f+A="; + + nativeBuildInputs = [ + pkg-config + ]; + + buildInputs = [ + openssl + ]; + + nativeInstallCheckInputs = [ + versionCheckHook + ]; + versionCheckProgramArg = [ "--version" ]; + doInstallCheck = true; + + passthru = { + updateScript = nix-update-script { }; + }; + + meta = { + description = "TUI client for bluesky"; + homepage = "https://github.com/sugyan/tuisky"; + changelog = "https://github.com/sugyan/tuisky/blob/${lib.removePrefix "refs/tags/" src.rev}/CHANGELOG.md"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ GaetanLepage ]; + mainProgram = "tuisky"; + }; +} From 096aa57d3794fb0986a6dac17a7c2d292e36040b Mon Sep 17 00:00:00 2001 From: Ilya Fedin Date: Sat, 2 Nov 2024 23:41:19 +0400 Subject: [PATCH 36/49] kotatogram-desktop: specify license as all other tdesktop forks do --- .../instant-messengers/telegram/kotatogram-desktop/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix index ad1173be2ed1..aa2d68f2b667 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix @@ -59,7 +59,7 @@ It contains some useful (or purely cosmetic) features, but they could be unstable. A detailed list is available here: https://kotatogram.github.io/changes ''; - license = licenses.gpl3; + license = licenses.gpl3Only; platforms = platforms.all; homepage = "https://kotatogram.github.io"; changelog = "https://github.com/kotatogram/kotatogram-desktop/releases/tag/k{version}"; From ca8eb1e29d1457cab21edc7821e3ed9e5624d12d Mon Sep 17 00:00:00 2001 From: Ilya Fedin Date: Sat, 2 Nov 2024 23:42:32 +0400 Subject: [PATCH 37/49] kotatogram-desktop: fix changelog link --- .../telegram/kotatogram-desktop/default.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix index aa2d68f2b667..1ee0f49ca0d1 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/default.nix @@ -7,6 +7,9 @@ , yasm }: +let + version = "1.4.9"; +in (libsForQt5.callPackage ../telegram-desktop/default.nix { inherit stdenv; @@ -30,7 +33,7 @@ withWebKitGTK = false; }).overrideAttrs { pname = "kotatogram-desktop"; - version = "1.4.9-unstable-2024-09-27"; + version = "${version}-unstable-2024-09-27"; src = fetchFromGitHub { owner = "kotatogram"; @@ -62,7 +65,7 @@ license = licenses.gpl3Only; platforms = platforms.all; homepage = "https://kotatogram.github.io"; - changelog = "https://github.com/kotatogram/kotatogram-desktop/releases/tag/k{version}"; + changelog = "https://github.com/kotatogram/kotatogram-desktop/releases/tag/k${version}"; maintainers = with maintainers; [ ilya-fedin ]; mainProgram = if stdenv.hostPlatform.isLinux then "kotatogram-desktop" else "Kotatogram"; }; From bf8dff745685abad8bcc93c5463456e9d1297c79 Mon Sep 17 00:00:00 2001 From: Noa Aarts Date: Sat, 2 Nov 2024 21:10:50 +0100 Subject: [PATCH 38/49] abracadabra: 2.6.0 -> 2.7.0 --- pkgs/applications/radio/abracadabra/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/radio/abracadabra/default.nix b/pkgs/applications/radio/abracadabra/default.nix index faede7f8d7f6..6089c1ba78ce 100644 --- a/pkgs/applications/radio/abracadabra/default.nix +++ b/pkgs/applications/radio/abracadabra/default.nix @@ -20,13 +20,13 @@ stdenv.mkDerivation rec { pname = "abracadabra"; - version = "2.6.0"; + version = "2.7.0"; src = fetchFromGitHub { owner = "KejPi"; repo = "AbracaDABra"; rev = "v${version}"; - hash = "sha256-oO8ef2VTw/gVNNU2JRXtEHEkJm7X7dypjZr0vZXCfH8="; + hash = "sha256-iHa41VmCrNGsj+6LeYIigwiBahQuTVr+bAo0kFmQ6dw="; }; nativeBuildInputs = [ From c06fa3b4a97717e29a9d1274aea958dadfe27be0 Mon Sep 17 00:00:00 2001 From: Noa Aarts Date: Sat, 2 Nov 2024 21:13:21 +0100 Subject: [PATCH 39/49] abracadabra: move to by-name --- .../ab/abracadabra/package.nix} | 19 +++++++------------ pkgs/top-level/all-packages.nix | 2 -- 2 files changed, 7 insertions(+), 14 deletions(-) rename pkgs/{applications/radio/abracadabra/default.nix => by-name/ab/abracadabra/package.nix} (83%) diff --git a/pkgs/applications/radio/abracadabra/default.nix b/pkgs/by-name/ab/abracadabra/package.nix similarity index 83% rename from pkgs/applications/radio/abracadabra/default.nix rename to pkgs/by-name/ab/abracadabra/package.nix index 6089c1ba78ce..498a10e24807 100644 --- a/pkgs/applications/radio/abracadabra/default.nix +++ b/pkgs/by-name/ab/abracadabra/package.nix @@ -3,12 +3,7 @@ stdenv, fetchFromGitHub, cmake, - wrapQtAppsHook, - qtbase, - qtmultimedia, - qttools, - qtpositioning, - qtlocation, + qt6, faad2, mpg123, portaudio, @@ -31,15 +26,15 @@ stdenv.mkDerivation rec { nativeBuildInputs = [ cmake - wrapQtAppsHook - qttools + qt6.wrapQtAppsHook + qt6.qttools ]; buildInputs = [ - qtbase - qtmultimedia - qtlocation - qtpositioning + qt6.qtbase + qt6.qtmultimedia + qt6.qtlocation + qt6.qtpositioning faad2 mpg123 portaudio diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index d66ad450ec82..880035f7362a 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -2928,8 +2928,6 @@ with pkgs; twine = with python3Packages; toPythonApplication twine; - abracadabra = qt6Packages.callPackage ../applications/radio/abracadabra { }; - accelergy = callPackage ../applications/science/computer-architecture/accelergy { }; aldo = callPackage ../applications/radio/aldo { }; From cfa05be0af5c1f79db1f048df3caecc2b50565c8 Mon Sep 17 00:00:00 2001 From: Ilya Fedin Date: Sat, 2 Nov 2024 23:39:54 +0400 Subject: [PATCH 40/49] kotatogram-desktop-with-webkit: inherit argv0 --- .../telegram/kotatogram-desktop/with-webkit.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix index 731042ac924a..684893491eda 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix @@ -13,6 +13,7 @@ stdenv.mkDerivation { postFixup = '' mkdir -p $out/bin makeWrapper ${kotatogram-desktop}/bin/kotatogram-desktop $out/bin/kotatogram-desktop \ + --inherit-argv0 \ --prefix GIO_EXTRA_MODULES : ${glib-networking}/lib/gio/modules \ --prefix LD_LIBRARY_PATH : ${lib.makeLibraryPath [ webkitgtk_4_1 ]} ''; From 4340feec952b459b15053547ef5650bad521be47 Mon Sep 17 00:00:00 2001 From: Ilya Fedin Date: Sat, 2 Nov 2024 23:40:17 +0400 Subject: [PATCH 41/49] kotatogram-desktop-with-webkit: use mainProgram --- .../telegram/kotatogram-desktop/with-webkit.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix index 684893491eda..0976f18bf9c7 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix @@ -12,7 +12,7 @@ stdenv.mkDerivation { ''; postFixup = '' mkdir -p $out/bin - makeWrapper ${kotatogram-desktop}/bin/kotatogram-desktop $out/bin/kotatogram-desktop \ + makeWrapper {${kotatogram-desktop},$out}/bin/${kotatogram-desktop.meta.mainProgram} \ --inherit-argv0 \ --prefix GIO_EXTRA_MODULES : ${glib-networking}/lib/gio/modules \ --prefix LD_LIBRARY_PATH : ${lib.makeLibraryPath [ webkitgtk_4_1 ]} From 5bd8cc4f3cf4a3f2e087de4b22c7cd870e6315e1 Mon Sep 17 00:00:00 2001 From: Ilya Fedin Date: Sun, 3 Nov 2024 00:47:12 +0400 Subject: [PATCH 42/49] kotatogram-desktop-with-webkit: switch to binary wrapper --- .../telegram/kotatogram-desktop/with-webkit.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix index 0976f18bf9c7..f708b8a6246e 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/kotatogram-desktop/with-webkit.nix @@ -1,9 +1,9 @@ -{ stdenv, lib, kotatogram-desktop, glib-networking, webkitgtk_4_1, makeWrapper }: +{ stdenv, lib, kotatogram-desktop, glib-networking, webkitgtk_4_1, makeBinaryWrapper }: stdenv.mkDerivation { pname = "${kotatogram-desktop.pname}-with-webkit"; version = kotatogram-desktop.version; - nativeBuildInputs = [ makeWrapper ]; + nativeBuildInputs = [ makeBinaryWrapper ]; dontUnpack = true; installPhase = '' mkdir -p $out @@ -12,7 +12,7 @@ stdenv.mkDerivation { ''; postFixup = '' mkdir -p $out/bin - makeWrapper {${kotatogram-desktop},$out}/bin/${kotatogram-desktop.meta.mainProgram} \ + makeBinaryWrapper {${kotatogram-desktop},$out}/bin/${kotatogram-desktop.meta.mainProgram} \ --inherit-argv0 \ --prefix GIO_EXTRA_MODULES : ${glib-networking}/lib/gio/modules \ --prefix LD_LIBRARY_PATH : ${lib.makeLibraryPath [ webkitgtk_4_1 ]} From 7cead3b24f2412ecc81938c6aac55ff75081a6f8 Mon Sep 17 00:00:00 2001 From: Noa Aarts Date: Sat, 2 Nov 2024 15:24:55 +0100 Subject: [PATCH 43/49] google-cloud-iot: fix derivation Replaced the old `including_default_value_fields` with `always_print_fields_with_no_presence` to make the tests pass --- .../python-modules/google-cloud-iot/default.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/development/python-modules/google-cloud-iot/default.nix b/pkgs/development/python-modules/google-cloud-iot/default.nix index 4cd4dc257fda..73ece34efc16 100644 --- a/pkgs/development/python-modules/google-cloud-iot/default.nix +++ b/pkgs/development/python-modules/google-cloud-iot/default.nix @@ -39,6 +39,15 @@ buildPythonPackage rec { pytestCheckHook ]; + # including_default_value_fields was deprecated, the new version is called + # always_print_fields_with_no_presence + postPatch = '' + substituteInPlace "tests/unit/gapic/iot_v1/test_device_manager.py" \ + --replace-fail "including_default_value_fields" "always_print_fields_with_no_presence" + substituteInPlace "google/cloud/iot_v1/services/device_manager/transports/rest.py" \ + --replace-fail "including_default_value_fields" "always_print_fields_with_no_presence" + ''; + disabledTests = [ # requires credentials "test_list_device_registries" From 1fcd82e7c8eb399c153ed87aab3066643276b919 Mon Sep 17 00:00:00 2001 From: Gavin John Date: Wed, 11 Sep 2024 15:40:13 -0700 Subject: [PATCH 44/49] paup: rename to paup-cli --- pkgs/by-name/pa/{paup => paup-cli}/package.nix | 2 +- pkgs/top-level/aliases.nix | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) rename pkgs/by-name/pa/{paup => paup-cli}/package.nix (97%) diff --git a/pkgs/by-name/pa/paup/package.nix b/pkgs/by-name/pa/paup-cli/package.nix similarity index 97% rename from pkgs/by-name/pa/paup/package.nix rename to pkgs/by-name/pa/paup-cli/package.nix index 62bb5206587a..12796245bced 100644 --- a/pkgs/by-name/pa/paup/package.nix +++ b/pkgs/by-name/pa/paup-cli/package.nix @@ -9,7 +9,7 @@ }: stdenvNoCC.mkDerivation { - pname = "paup"; + pname = "paup-cli"; version = "4.0a168"; src = fetchurl { diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 6603b96b8191..d4dabc1083cb 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -924,6 +924,7 @@ mapAliases { paperless-ng = paperless-ngx; # Added 2022-04-11 partition-manager = libsForQt5.partitionmanager; # Added 2024-01-08 patchelfStable = patchelf; # Added 2024-01-25 + paup = paup-cli; # Added 2024-09-11 pcsctools = pcsc-tools; # Added 2023-12-07 pcsxr = throw "pcsxr was removed as it has been abandoned for over a decade; please use DuckStation, Mednafen, or the RetroArch PCSX ReARMed core"; # Added 2024-08-20 pdf4tcl = tclPackages.pdf4tcl; # Added 2024-10-02 From 4fc7130a3255ad8c7b3f244848c2730616c0d8e2 Mon Sep 17 00:00:00 2001 From: Gavin John Date: Wed, 11 Sep 2024 15:41:43 -0700 Subject: [PATCH 45/49] dendropy: switch to paup-cli from paup --- pkgs/development/python-modules/dendropy/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/dendropy/default.nix b/pkgs/development/python-modules/dendropy/default.nix index 8cc15b7210c7..37336cddb4a7 100644 --- a/pkgs/development/python-modules/dendropy/default.nix +++ b/pkgs/development/python-modules/dendropy/default.nix @@ -7,12 +7,12 @@ pythonOlder, nix-update-script, setuptools, - paup, + paup-cli, paupIntegration ? false, }: let - paupPath = if paupIntegration then lib.getExe paup else "NONE"; + paupPath = if paupIntegration then lib.getExe paup-cli else "NONE"; in buildPythonPackage rec { pname = "dendropy"; From 412bca2b38a4018501d352f2d71d984ff0097352 Mon Sep 17 00:00:00 2001 From: mrtnvgr Date: Wed, 8 Nov 2023 13:57:04 +0700 Subject: [PATCH 46/49] fna3d: init at 24.11 --- pkgs/by-name/fn/fna3d/package.nix | 39 +++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) create mode 100644 pkgs/by-name/fn/fna3d/package.nix diff --git a/pkgs/by-name/fn/fna3d/package.nix b/pkgs/by-name/fn/fna3d/package.nix new file mode 100644 index 000000000000..84e7920a0bd1 --- /dev/null +++ b/pkgs/by-name/fn/fna3d/package.nix @@ -0,0 +1,39 @@ +{ + lib, + stdenv, + fetchFromGitHub, + cmake, + SDL2, +}: +stdenv.mkDerivation rec { + pname = "fna3d"; + version = "24.11"; + + src = fetchFromGitHub { + owner = "FNA-XNA"; + repo = "FNA3D"; + rev = version; + fetchSubmodules = true; + hash = "sha256-NTVaPY39acSRibGQjLuh5ZBGC1Zep/rybVcOU0WrNIw="; + }; + + buildInputs = [ SDL2 ]; + nativeBuildInputs = [ cmake ]; + + installPhase = '' + runHook preInstall + install -Dm755 libFNA3D.so $out/lib/libFNA3D.so + ln -s libFNA3D.so $out/lib/libFNA3D.so.0 + ln -s libFNA3D.so $out/lib/libFNA3D.so.0.${version} + runHook postInstall + ''; + + meta = { + description = "Accuracy-focused XNA4 reimplementation for open platforms"; + homepage = "https://fna-xna.github.io/"; + license = lib.licenses.mspl; + platforms = lib.platforms.linux; + mainProgram = pname; + maintainers = with lib.maintainers; [ mrtnvgr ]; + }; +} From 9e686bd1367dfa3b1369706761cf64671827ecb1 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 Nov 2024 05:23:38 +0000 Subject: [PATCH 47/49] python312Packages.pulsectl-asyncio: 1.2.1 -> 1.2.2 --- pkgs/development/python-modules/pulsectl-asyncio/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pulsectl-asyncio/default.nix b/pkgs/development/python-modules/pulsectl-asyncio/default.nix index 8b7c70dc79eb..ce5216428dd7 100644 --- a/pkgs/development/python-modules/pulsectl-asyncio/default.nix +++ b/pkgs/development/python-modules/pulsectl-asyncio/default.nix @@ -9,7 +9,7 @@ buildPythonPackage rec { pname = "pulsectl-asyncio"; - version = "1.2.1"; + version = "1.2.2"; pyproject = true; disabled = pythonOlder "3.7"; @@ -18,7 +18,7 @@ buildPythonPackage rec { owner = "mhthies"; repo = "pulsectl-asyncio"; rev = "refs/tags/v${version}"; - hash = "sha256-VmogNphVZNJSUKUqp7xADRl78Ooofhl1YYrtYz5MBYc="; + hash = "sha256-lHVLrkFdNM8Y4t6TcXYnX8sQ4COrW3vV2sTDWeI4xZU="; }; build-system = [ setuptools ]; From 8cf0d3a761620eda71b0f750b85d3f1b5e1d759d Mon Sep 17 00:00:00 2001 From: George Huebner Date: Tue, 22 Oct 2024 08:45:04 -0500 Subject: [PATCH 48/49] gtkwave: use desktopToDarwinBundle This has the primary benefit of preventing the name of the wrapper from leaking into the UI and process info (see #60260 for more info). --- .../science/electronics/gtkwave/default.nix | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/pkgs/applications/science/electronics/gtkwave/default.nix b/pkgs/applications/science/electronics/gtkwave/default.nix index d82438a31119..9028d3a80288 100644 --- a/pkgs/applications/science/electronics/gtkwave/default.nix +++ b/pkgs/applications/science/electronics/gtkwave/default.nix @@ -12,6 +12,7 @@ , tk , wrapGAppsHook3 , xz +, desktopToDarwinBundle }: stdenv.mkDerivation rec { @@ -23,7 +24,11 @@ stdenv.mkDerivation rec { sha256 = "sha256-VKpFeI1tUq+2WcOu8zWq/eDvLImQp3cPjqpk5X8ic0Y="; }; - nativeBuildInputs = [ pkg-config wrapGAppsHook3 ]; + nativeBuildInputs = [ + pkg-config wrapGAppsHook3 + ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ + desktopToDarwinBundle + ]; buildInputs = [ bzip2 glib gperf gtk3 judy tcl tk xz ] ++ lib.optional stdenv.hostPlatform.isDarwin gtk-mac-integration; @@ -42,6 +47,14 @@ stdenv.mkDerivation rec { "--enable-gtk3" ]; + postFixup = lib.optionalString stdenv.hostPlatform.isDarwin '' + mv $out/bin/.gtkwave-wrapped $out/Applications/GTKWave.app/Contents/MacOS/.gtkwave-wrapped + makeWrapper $out/Applications/GTKWave.app/Contents/MacOS/.gtkwave-wrapped $out/Applications/GTKWave.app/Contents/MacOS/GTKWave \ + --inherit-argv0 \ + "''${gappsWrapperArgs[@]}" + ln -sf $out/Applications/GTKWave.app/Contents/MacOS/GTKWave $out/bin/gtkwave + ''; + meta = { description = "VCD/Waveform viewer for Unix and Win32"; homepage = "https://gtkwave.sourceforge.net"; From 68a61b1bb65f6ab5d0d869c1c8c388ad928dfe5f Mon Sep 17 00:00:00 2001 From: Matteo Pacini Date: Sun, 3 Nov 2024 11:12:13 +0000 Subject: [PATCH 49/49] libspf2: fix darwin build (#353188) Co-authored-by: Matteo Pacini --- pkgs/development/libraries/libspf2/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/libspf2/default.nix b/pkgs/development/libraries/libspf2/default.nix index d8746f72f3b5..9e64441af558 100644 --- a/pkgs/development/libraries/libspf2/default.nix +++ b/pkgs/development/libraries/libspf2/default.nix @@ -23,6 +23,8 @@ stdenv.mkDerivation rec { -e '/bin_PROGRAMS/s/spf_example_static//' src/spf_example/Makefile.am ''; + CFLAGS = lib.optionalString stdenv.cc.isClang "-Wno-implicit-function-declaration"; + doCheck = true; meta = with lib; {