summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* btrfs-progs: 4.14.1 -> 4.15.1origin/release-17.03Domen Kožar2018-04-072-5/+41
| | | | | (cherry picked from commit 11238ffbe1d1102c6519c4852ab61352d3d36f31) Signed-off-by: Domen Kožar <domen@dev.si>
* e2fsprogs: 1.43.8 -> 1.44.1Domen Kožar2018-04-071-2/+2
| | | | | (cherry picked from commit e6114781b0fad5345a2430fac3587d618273bda2) Signed-off-by: Domen Kožar <domen@dev.si>
* kernel: depend optionally on libelfDomen Kožar2018-04-071-1/+1
|
* kernel 4.14 require libelf to compile modules.David Guibert2018-04-077-8/+15
| | | | | | | | | | [...] make modules -C /nix/store/h1vzl6bq4wif3m8dd1bw2p3fv4shjg3n-linux-4.14.9-dev/lib/modules/4.14.9/build EXTRA_CFLAGS=-Werror-implicit-function-declaration M=/tmp/nix-build-spl-kernel-2017-11-16-4.14.9.drv-0/source/build /nix/store/h1vzl6bq4wif3m8dd1bw2p3fv4shjg3n-linux-4.14.9-dev/lib/modules/4.14.9/source/Makefile:939: *** "Cannot generate ORC metadata for CONFIG_UNWINDER_ORC=y, please install libelf-dev, libelf-devel or elfutils-libelf-devel". Stop. This patch introduces kernel.moduleBuildDependencies to avoid the logic "stdenv.lib.optional (stdenv.lib.versionAtLeast kernel.version "4.14") libelf" in multiple places. [dezgeg did some minor tweaks on top]
* linux: Add 4.14Tim Steinbach2018-04-063-2/+44
|
* kernel/common-config: backport 4.13+ supportYegor Timoshenko2018-01-061-1/+3
|
* Extract files one at a time from all-cabal-hashesWill Fancher2017-12-172-12/+13
|
* openssl: fix nix patch for recent updateGraham Christensen2017-11-031-3/+3
| | | | (cherry picked from commit e06dbe4f5b51850746ef2c363be8326a1a3e84bf)
* openssl_1_1_0: 1.1.0f -> 1.1.0gGraham Christensen2017-11-031-2/+2
| | | | (cherry picked from commit 5e2d96deb331b19fc1b69146c88a8128e8b6e466)
* openssl_1_0_2: 1.0.2l -> 1.0.2mGraham Christensen2017-11-031-2/+2
| | | | (cherry picked from commit 7726b4602709bbda969c021c56873a6eeebe97b2)
* libav_11: security 11.10 -> 11.11Vladimír Čunát2017-10-311-1/+2
| | | | | | Fixes CVE-2017-7862. (cherry picked from commit 25515ce9280dcb90cffc3fbd15e4ab2ac8ec0e38)
* network-interfaces-scripted: fix NixOS/nixops#640Bas van Dijk2017-10-301-2/+1
| | | | | | | Reverse the PartOf dependency between network-setup and network-addresses-* This was joint work of: @nh2, @domenkozar, @fpletz, @aszlig and @basvandijk at the NixCon 2017 hackathon.
* linux: 4.4.84 -> 4.4.95Franz Pletz2017-10-301-2/+3
| | | | (cherry picked from commit 0a5ecde8085122835a9c8ffa2025e8ccb49ddb14)
* php71: 7.1.9 -> 7.1.11Franz Pletz2017-10-301-2/+2
| | | | (cherry picked from commit f41f5a8f77a09f9629b86d88f6a6b514e416d155)
* php70: 7.0.24 -> 7.0.25Franz Pletz2017-10-301-2/+2
| | | | (cherry picked from commit 3975f267abc305d4a197fe96c0cf5f49cbfc6d7d)
* php56: 5.6.31 -> 5.6.32Franz Pletz2017-10-301-2/+2
| | | | (cherry picked from commit ecdf4f1c51c0b1093b06c17fce29f6778ee6934f)
* wget: 1.19.1 -> 1.19.2 for multiple CVEsFranz Pletz2017-10-271-10/+5
| | | | | | Fixes CVE-2017-13089, CVE-2017-13090. (cherry picked from commit 3e29dd00fc43f585995dc470e7bb9717f6d9f46e)
* Merge #30729: freeimage: apply security patchesVladimír Čunát2017-10-241-0/+13
| | | | | (cherry picked from commit dc240d20696aeb26198aa744bc99cde5bc5cf69b) They're relatively simple patches, used by Debian.
* curl: 7.56.0 -> 7.56.1Tim Steinbach2017-10-241-2/+2
| | | | (cherry picked from commit 9bd930560292209b569158a0a591b59108dd4dd9)
* foomatic-filters: fix CVE-2015-8327 & CVE-2015-8560Piotr Bogdan2017-10-241-1/+9
| | | | (cherry picked from commit 4b756e48738dc0775dacb6b97280a17799d66147)
* imagemagick7: 7.0.7-4 -> 7.0.7-8Franz Pletz2017-10-231-2/+2
| | | | (cherry picked from commit bb493911516b812d5e03567836fb049c2ee02608)
* imagemagick: 6.9.9-15 -> 6.9.9-20Franz Pletz2017-10-231-2/+2
| | | | (cherry picked from commit 6af0de6478a7028b6fd73fbd44cacf0c13c7be99)
* irssi: 1.0.4 -> 1.0.5Piotr Bogdan2017-10-231-2/+2
| | | | | | Security update, see https://irssi.org/security/irssi_sa_2017_10.txt. (cherry picked from commit c81563771985a19f9c44bca267b66374fba1b11f)
* flashplayer: 27.0.0.159 -> 27.0.0.170taku02017-10-173-10/+10
| | | | (cherry picked from commit a060b850f68906e8a5928aa24398a5d4ec76361f)
* flashplayer: 27.0.0.130 -> 27.0.0.159taku02017-10-173-10/+10
| | | | (cherry picked from commit 628c039326bd1f8e8a8009c0ea74cb99c3d82e3a)
* wpa_supplicant: patch for KRACKAttackGraham Christensen2017-10-161-0/+33
| | | | | | | | | | | | | | | CVE-2017-13077: Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake. CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake. CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way handshake. CVE-2017-13080: Reinstallation of the group key (GTK) in the group key handshake. CVE-2017-13081: Reinstallation of the integrity group key (IGTK) in the group key handshake. CVE-2017-13082: Accepting a retransmitted Fast BSS Transition (FT) Reassociation Request and reinstalling the pairwise encryption key (PTK-TK) while processing it. CVE-2017-13084: Reinstallation of the STK key in the PeerKey handshake. CVE-2017-13086: reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake. CVE-2017-13087: reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame. CVE-2017-13088: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame. (cherry picked from commit ea50efcc67cfa6c8331b54ff33ab791dacd52fe4)
* hostapd: patch for KRACKAttackGraham Christensen2017-10-161-0/+34
| | | | | | | | | | | | | | | CVE-2017-13077: Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake. CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake. CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way handshake. CVE-2017-13080: Reinstallation of the group key (GTK) in the group key handshake. CVE-2017-13081: Reinstallation of the integrity group key (IGTK) in the group key handshake. CVE-2017-13082: Accepting a retransmitted Fast BSS Transition (FT) Reassociation Request and reinstalling the pairwise encryption key (PTK-TK) while processing it. CVE-2017-13084: Reinstallation of the STK key in the PeerKey handshake. CVE-2017-13086: reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake. CVE-2017-13087: reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame. CVE-2017-13088: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame. (cherry picked from commit 629965a53251afa23a60c08c16000b732374b9f9)
* nixos/atd: remove "batch" from setuid wrappersBjørn Forsman2017-10-161-1/+3
| | | | | | | | | | | "batch" is a shell script so invoking it via setuid wrapper never worked anyway. (The kernel drops perms on executables with shebang.) A previous nixpkgs commit made "batch" invoke the NixOS setuid "at" wrapper to gain needed privileges. Thanks to @yesbox for noticing. (cherry picked from commit 497108b4568d01cefee6acdf92b738ee80e22023)
* nixos/tests: add basic test for services.atdBjørn Forsman2017-10-162-0/+37
| | | | | | (cherry picked from commit 943730ff9b6b05c61ef75d7e2f3fae17d4cbdf4f) (Fix trivial conflict in nixos/release.nix.)
* at: fix permission errors with "batch" on NixOSBjørn Forsman2017-10-161-1/+11
| | | | | | Fixes https://github.com/NixOS/nixpkgs/issues/12392 (cherry picked from commit 38e6ae8e440d3c1eb53c7f2bae9dedd2fdf9a5bb)
* curl: fix clang buildDaiderd Jordan2017-10-161-2/+2
| | | | (cherry picked from commit 514593ea31d7e67e8efa2f2ff26c9569d508a5ef)
* xorg-server: security 1.19.4 -> 1.19.5Vladimír Čunát2017-10-142-4/+4
| | | | | | CVE-2017-{12176,12177,12178,12183} (cherry picked from commit 2baf618c3ee503b20fd55f0ba92b325a976de730)
* xorg libXfont2, libXres: security updatesVladimír Čunát2017-10-142-8/+8
| | | | | | CVE-2013-1988, CVE-2017-{13720,13722} (cherry picked from commit 6328c76e7785791c0397f43eaace1f85cbf33164)
* unrar: 5.5.7 -> 5.5.8mimadrid2017-10-121-3/+3
| | | | (cherry picked from commit 94fa59228a68b4bb4cb4074f46b91921eabdc5ed)
* nss: fix includedir for pkgconfigRobin Gloster2017-10-111-1/+1
| | | | | | (cherry picked from commit 034c168aa29fa95c323125d970d4018d25ac7eee) It fixes some reverse dependencies and it's very unlikely to worsen something.
* nixos/lighttpd: add missing modules to allKnownModulesBjørn Forsman2017-10-101-1/+5
| | | | | | | | | | | | | | | | The output of ./configure shows all modules/plugins, both enabled and disabled. With this info we can finally build the _complete_ list of modules. We were missing these: mod_authn_gssapi mod_authn_ldap mod_geoip (I hit this as I was building lighttpd with ldap support and the NixOS module said ldap was unsupported, due to these missing entries in allKnownModules.) (cherry picked from commit d26f8b5e00b4a436ec8f9b7fb1b55a0dbda440c5)
* nixos/lighttpd: update list of allowed module namesBjørn Forsman2017-10-101-1/+4
| | | | | | | | | * mod_dirlisting is auto-loaded by lighttpd and should not be explicitly loaded in the configuration file. * The rest comes from looking at "ls -1 $lighttpd/lib/*.so" when lighttpd is built with "enableMagnet" and "enableMysql". (cherry picked from commit b339e6e13fb0869f5ac5ba13e8c38ab535549231)
* shutter: 0.93.1 -> 0.94jaltek2017-10-101-11/+3
| | | | (cherry picked from commit da93e6e6789dc52e24571179726813ca9d4eed61)
* fcron module: fix use with hardlink-optimized storeLéo Gaspard2017-10-091-1/+1
| | | | (cherry picked from commit 1afd97aa8f5893b92be5861d11b31c3ba9581f34)
* nixos/fcron: service needs fcron in PATHJoerg Thalheim2017-10-091-4/+1
| | | | | | | otherwise fcronsighup is not found. Set PATH to /run/current-system/sw/bin does not seems to be used by service file anyway. (cherry picked from commit e34e28e573568a0cad99d3e6aec3f78408d9cdbc)
* xorg-server: security 1.19.2 -> 1.19.4Vladimír Čunát2017-10-083-9/+4
| | | | | | | CVE-2017-{13721,13723} https://lists.x.org/archives/xorg-announce/2017-October/002808.html (cherry picked from commits 07efaaa722a8bf288 and 35b4c8be511d6f)
* ruby_2_2: 2.2.7 -> 2.2.8Piotr Bogdan2017-10-073-7/+7
| | | | | | | | | | | | | For multiple CVE's: - CVE-2017-0898 - CVE-2017-10784 - CVE-2017-14033 - CVE-2017-14064 See https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-2-8-released/ (cherry picked from commit 547fba51407afed4c3885cd935cf23702e386be8)
* ruby: 2.2.5 -> 2.2.7Tim Steinbach2017-10-073-12/+12
| | | | (cherry picked from commit ec2c46923078ceda67f944ae09bcb4d435d45ce5)
* firefox: revert the upgrade for nowVladimír Čunát2017-10-071-2/+2
| | | | It needs rustc-1.17, and I don't see how to port it ATM. /cc #30143
* icu: keep default version on 58Vladimír Čunát2017-10-071-1/+1
| | | | | | ... to avoid mass rebuilds for now. (Bumped in parent merge.) (cherry picked from commit a7159d3cdae0fc8a38b2a3a24b0fc240ebf85d9b)
* Merge #30143: firefox-*: critical security updatesVladimír Čunát2017-10-078-64/+76
| | | | (cherry picked from commit 84952fc2920e0b490ddbea483b7ab7e3e25db929)
* locate: does not use localuser for mlocateromildo2017-10-071-1/+1
| | | | (cherry picked from commit 6ef6484dd645a7d1d6b1d3d993988ba5833a5701)
* locate: fix creation of the parent directory of of locate databaseromildo2017-10-071-1/+1
| | | | (cherry picked from commit c06a10e05fedcd49c4b2f88a435e9aad64395d0a)
* curl: 7.55.1 -> 7.56.0 for CVE-2017-1000254Franz Pletz2017-10-041-2/+2
| | | | | https://curl.haxx.se/docs/adv_20171004.html (cherry picked from commit a98b96824db90446895c7cbf2c4931ef9ad9cb68)
* curl: 7.55.0 -> 7.55.1Tim Steinbach2017-10-041-6/+2
| | | | (cherry picked from commit 135a841d9124f0c27750ee909d02a84bff23b44e)