Commit Graph
976728 Commits
Author SHA1 Message Date
Jörg ThalheimandGitHub 89c040ed9f nix: apply patches for GHSA-g3g9-5vj6-r3gj (#507672) 2026-04-07 18:07:48 +00:00
Jörg ThalheimandSergei Zimmerman 50eec35e48 nixComponents_git: add patches for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.

The second patch partially fixes the issue with cooperating processes being able
to communicate via abstract sockets. The fix is partial, because processes
outside the landlock domain of the sandboxed process can still connect to
a socket created by the FOD. There's no equivalent way of restricting inbound
connections. This closes the gap when there's no cooperating process on the host
(i.e. 2 separate FODs).

The patch applies landlock LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET on
kernels >= 6.12 (default on NixOS 25.11+) to deny abstract socket
connect from inside the build sandbox.
2026-04-07 20:52:46 +03:00
Jörg ThalheimandSergei Zimmerman 7ca89c4ab6 nixComponents_2_34: add patches for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.

The second patch partially fixes the issue with cooperating processes being able
to communicate via abstract sockets. The fix is partial, because processes
outside the landlock domain of the sandboxed process can still connect to
a socket created by the FOD. There's no equivalent way of restricting inbound
connections. This closes the gap when there's no cooperating process on the host
(i.e. 2 separate FODs).

The patch applies landlock LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET on
kernels >= 6.12 (default on NixOS 25.11+) to deny abstract socket
connect from inside the build sandbox.
2026-04-07 20:52:00 +03:00
Jörg ThalheimandSergei Zimmerman be23129938 nixComponents_2_31: add patches for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.

The second patch partially fixes the issue with cooperating processes being able
to communicate via abstract sockets. The fix is partial, because processes
outside the landlock domain of the sandboxed process can still connect to
a socket created by the FOD. There's no equivalent way of restricting inbound
connections. This closes the gap when there's no cooperating process on the host
(i.e. 2 separate FODs).

The patch applies landlock LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET on
kernels >= 6.12 (default on NixOS 25.11+) to deny abstract socket
connect from inside the build sandbox.
2026-04-07 20:51:01 +03:00
Jörg ThalheimandSergei Zimmerman 69e8fef812 nixComponents_2_30: add patch for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.
2026-04-07 20:44:30 +03:00
Jörg ThalheimandSergei Zimmerman 128dad70c6 nix_2_28: add patch for GHSA-g3g9-5vj6-r3gj
This addresses GHSA-g3g9-5vj6-r3gj, a vulnerability where
std::filesystem::copy_file follows symlinks when copying FOD outputs,
allowing a malicious builder to overwrite files outside the build
sandbox.

The patch puts FOD output copies in a temporary directory inside the
store (instead of the chroot) and tightens permissions on the
in-store temporary directory.
2026-04-07 20:44:23 +03:00
nixpkgs-ci[bot]andGitHub 0e028439dc Merge master into staging-nixos 2026-04-07 17:29:15 +00:00
nixpkgs-ci[bot]andGitHub 77bb0683a4 openfreebuds: 0.17.1 -> 0.17.3 (#507658) 2026-04-07 17:11:47 +00:00
nixpkgs-ci[bot]andGitHub b6c1d99fc4 mark: 16.0.2 -> 16.2.0 (#507636) 2026-04-07 17:11:43 +00:00
André SilvaandGitHub 24a4534ee7 sone: init at 0.14.1 (#504965) 2026-04-07 17:07:27 +00:00
R. Ryantm 84d742bba8 openfreebuds: 0.17.1 -> 0.17.3 2026-04-07 16:44:35 +00:00
Paul MeyerandGitHub dfd9566f82 distribution: 3.0.0 -> 3.1.0 (#507442) 2026-04-07 16:32:49 +00:00
Adam C. StephensandGitHub 97768c9a7d forgejo-runner: 12.7.3 -> 12.8.2 (#507649) 2026-04-07 16:32:29 +00:00
Marc JakobiandGitHub 43a2418fcd vimPlugins.{better-diagnostic-virtual-text,garbage-day-nvim,runner-nvim}: init (#507562) 2026-04-07 16:18:35 +00:00
emilylange 1283f2ac3f forgejo-runner: 12.7.3 -> 12.8.2
https://code.forgejo.org/forgejo/runner/releases/tag/v12.8.0

https://code.forgejo.org/forgejo/runner/releases/tag/v12.8.1

https://code.forgejo.org/forgejo/runner/releases/tag/v12.8.2
2026-04-07 18:17:31 +02:00
StepBroBDandGitHub 29796a13e3 osu-lazer{,-bin}: 2026.401.0 -> 2026.406.0 (#507631) 2026-04-07 16:01:26 +00:00
Martin WeineltandGitHub 8865d5f325 Firefox: 149.0 -> 149.0.2 (#507607) 2026-04-07 15:44:52 +00:00
nixpkgs-ci[bot]andGitHub b63e805ce6 tango-database: 5.28 -> 5.29 (#507600) 2026-04-07 15:40:39 +00:00
nixpkgs-ci[bot]andGitHub 18f6f2598d velocity: 3.5.0-unstable-2026-03-21 -> 3.5.0-unstable-2026-04-01 (#507463) 2026-04-07 15:40:39 +00:00
nixpkgs-ci[bot]andGitHub e37f3c604a qbz: 1.2.2 -> 1.2.3 (#507440) 2026-04-07 15:40:37 +00:00
nixpkgs-ci[bot]andGitHub 0595a19fd4 stable-diffusion-cpp: master-537-545fac4 -> master-558-8afbeb6 (#496539) 2026-04-07 15:40:23 +00:00
Thiago Kenji OkadaandGitHub ae6006a7ee libretro.fuse: 0-unstable-2024-11-24 -> 0-unstable-2026-03-31 (#507638) 2026-04-07 15:37:17 +00:00
Pol DellaieraandGitHub 8777c98512 zellij: 0.44.0 -> 0.44.1 (#507617) 2026-04-07 15:36:31 +00:00
Maximilian BoschandGitHub 31e080d9e3 livekit-cli: 1.5.1 -> 2.16.0; modernize (#506053) 2026-04-07 15:34:18 +00:00
R. Ryantm 591d34a3a7 libretro.fuse: 0-unstable-2024-11-24 -> 0-unstable-2026-03-31 2026-04-07 15:20:17 +00:00
R. Ryantm 029e37dd19 mark: 16.0.2 -> 16.2.0 2026-04-07 15:15:53 +00:00
Pol DellaieraandGitHub b1f694442a vscode-extensions.ryu1kn.partial-diff: 1.4.4 -> 1.4.6 (#507488) 2026-04-07 15:11:48 +00:00
Ulrik StridandGitHub aa1eac4f49 microsoft-edge: 146.0.3856.84 -> 146.0.3856.97 (#507523) 2026-04-07 15:09:32 +00:00
Pol DellaieraandGitHub ca90fb167d vscode-extensions.emmanuelbeziat.vscode-great-icons: 2.1.120 -> 2.1.121 (#507598) 2026-04-07 15:08:25 +00:00
K900andGitHub f05179a0d5 kdePackages: Plasma 6.6.3 -> 6.6.4 (#507633) 2026-04-07 15:03:55 +00:00
Philip TaronandGitHub 13064f99e1 json-schema-catalog-rs: use toFile instead of passAsFile (#498508) 2026-04-07 15:03:22 +00:00
K900 02ce591d4b kdePackages: Plasma 6.6.3 -> 6.6.4 2026-04-07 17:58:20 +03:00
Gutyina Gergő 66c2a56cb8 osu-lazer: 2026.401.0 -> 2026.406.0 2026-04-07 14:39:01 +00:00
Gutyina Gergő ae5450a449 osu-lazer-bin: 2026.401.0 -> 2026.406.0 2026-04-07 14:36:10 +00:00
nixpkgs-ci[bot]andGitHub 22c3790e0c railway: 4.35.0 -> 4.36.1 (#507620) 2026-04-07 14:29:16 +00:00
nixpkgs-ci[bot]andGitHub c8b29ecafa tea: 0.12.0 -> 0.13.0 (#507605) 2026-04-07 14:29:14 +00:00
Jonas ChevalierandGitHub 6ed003c564 appendOverlays: preserve splicing on empty overlay list (#501313) 2026-04-07 14:19:48 +00:00
Doron BeharandGitHub 70974cdcb4 balena-cli: 24.0.3 -> 24.0.4 (#507436) 2026-04-07 13:58:59 +00:00
David McFarlandandGitHub 68c03fedc8 dotnetCorePackages.fetchNupkg: neutralize avalonia.buildservices (#500497) 2026-04-07 13:57:23 +00:00
R. Ryantm 457ebc3de4 railway: 4.35.0 -> 4.36.1 2026-04-07 13:55:44 +00:00
Marc JakobiandGitHub d9fe6c164a neovim[-unwrapped]: 0.12.0 -> 0.12.1 (#507289) 2026-04-07 13:50:49 +00:00
nixpkgs-ci[bot]andGitHub 319a6c77df tektoncd-cli: 0.44.0 -> 0.44.1 (#507526) 2026-04-07 13:48:50 +00:00
nixpkgs-ci[bot]andGitHub b712a2490d seconlay: 0-unstable-2026-03-30 -> 0-unstable-2026-03-31 (#506810) 2026-04-07 13:48:43 +00:00
R. Ryantm 5d3a836e98 zellij: 0.44.0 -> 0.44.1 2026-04-07 13:45:49 +00:00
c6rg0andGaetan Lepage c02cfe212c neovim[-unwrapped]: 0.12.0 -> 0.12.1 2026-04-07 13:42:55 +00:00
Marc JakobiandGitHub ae921939fc vimPlugins.grug-far-nvim: prevent screenshot tests from failing (2) (#507612) 2026-04-07 13:35:25 +00:00
YtandGitHub f7450bc4fc unstructured-api: 0.1.1 -> 0.1.2 (#507573) 2026-04-07 13:30:40 +00:00
Marc Jakobi dc3e0601fb vimPlugins.grug-far-nvim: prevent screenshot tests from failing (2) 2026-04-07 15:22:44 +02:00
Austin HorstmanandGitHub 0155efca2c luaPackages.ltreesitter{,-ts}: move env variables into env for structuredAttrs (#507593) 2026-04-07 13:15:18 +00:00
Martin Weinelt 2fd58cf067 firefox-bin-unwrapped: 149.0 -> 149.0.2
https://www.mozilla.org/en-US/firefox/149.0.2/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-25/

Fixes: CVE-2026-5732, CVE-2026-5733, CVE-2026-5731, CVE-2026-5734,
       CVE-2026-5735
2026-04-07 15:10:33 +02:00