Commit Graph
100 Commits
Author SHA1 Message Date
Michael Weiss 835bdf1b65 Merge pull request #135327 from NixOS/backport-135228-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 92.0.4515.131 -> 92.0.4515.159
2021-08-22 21:33:54 +02:00
Michael Weiss fe10697bd0 ungoogled-chromium: 92.0.4515.131 -> 92.0.4515.159
(cherry picked from commit 76ab90294e4014a3a1e887f1099fc1f674385b94)
2021-08-22 19:13:31 +00:00
Michael Weiss f9698c475d Merge pull request #134414 from NixOS/backport-134409-to-release-21.05
[Backport release-21.05] chromium: 92.0.4515.131 -> 92.0.4515.159
2021-08-19 10:59:51 +02:00
Michael Weiss d64c771c8e Merge pull request #134719 from NixOS/backport-134704-to-release-21.05
[Backport release-21.05] signal-desktop: 5.13.1 -> 5.14.0
2021-08-19 10:36:36 +02:00
Michael Weiss da2591ed04 signal-desktop: 5.13.1 -> 5.14.0
(cherry picked from commit 8a4a84c83a62b1f8d5a0c94d0ea411ad7ee5825f)
2021-08-18 21:25:02 +00:00
Michael Weiss 587b190c8a chromium: 92.0.4515.131 -> 92.0.4515.159
https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop.html

This update includes 9 security fixes.

CVEs:
CVE-2021-30598 CVE-2021-30599 CVE-2021-30600 CVE-2021-30601
CVE-2021-30602 CVE-2021-30603 CVE-2021-30604

(cherry picked from commit 1c476a2b6dda4bef88270f0285cac5363712c980)
2021-08-17 08:55:42 +00:00
Michael Weiss 543d4ecac2 Merge pull request #134200 from primeos/security-backports-for-21.05
[21.05] glances: 3.1.7 -> 3.2.3
2021-08-16 22:36:55 +02:00
Michael Weiss 3c9c1bc642 glances: 3.2.0 -> 3.2.1
(cherry picked from commit c05bef5bc56325032f4602a9d5025551653bcc5c)
2021-08-15 15:21:49 +02:00
Michael Weiss 09e9715cc0 glances: 3.1.7 -> 3.2.0
(cherry picked from commit 035ba51146398b4ada9a89bd6246cd35e14b837e)
2021-08-15 15:21:48 +02:00
Michael Weiss ca084144c6 Merge pull request #133986 from NixOS/backport-133938-to-release-21.05
[Backport release-21.05] signal-desktop: 5.13.0 -> 5.13.1
2021-08-14 13:31:59 +02:00
Michael Weiss 0f09ebb8a2 signal-desktop: 5.13.0 -> 5.13.1
(cherry picked from commit 759dd3036f98985be36c41e9b85f6dd63db68c7b)
2021-08-14 11:13:26 +00:00
Michael Weiss 920934d188 signal-desktop: 5.12.2 -> 5.13.0
(cherry picked from commit 31a187510673af588984b5f2a4591e34ce7cfc64)
2021-08-12 21:56:27 +00:00
Michael Weiss b5510dc4d4 Merge pull request #132822 from NixOS/backport-132798-to-release-21.05
[Backport release-21.05] signal-desktop: 5.12.1 -> 5.12.2
2021-08-06 10:08:53 +02:00
Michael Weiss e96ec15bc4 signal-desktop: 5.12.1 -> 5.12.2
(cherry picked from commit bba311e5dfcc7a67aa63fea41839ce7b52fa05cf)
2021-08-05 20:46:23 +00:00
Michael Weiss 1ce07d770b Merge pull request #132757 from NixOS/backport-132695-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.164 -> 92.0.4515.131
2021-08-05 14:28:03 +02:00
Michael Weiss 8c589a79c8 Merge pull request #132771 from NixOS/backport-132756-to-release-21.05
[Backport release-21.05] signal-desktop: 5.12.0 -> 5.12.1
2021-08-05 14:08:44 +02:00
Michael Weiss 7df18c5b76 signal-desktop: 5.12.0 -> 5.12.1
(cherry picked from commit f11652f0a6ec62eb3b8f0e93db2211a14662c322)
2021-08-05 10:37:19 +00:00
Michael Weiss fa62bb8fac ungoogled-chromium: 91.0.4472.164 -> 92.0.4515.131
(cherry picked from commit 45c32f59a58b69ca6db8c8c5fdbe0ea9eee02376)
2021-08-05 09:26:03 +00:00
Michael Weiss 935e4fafbb Merge pull request #132644 from NixOS/backport-132639-to-release-21.05
[Backport release-21.05] signal-desktop: 5.11.0 -> 5.12.0
2021-08-04 14:10:42 +02:00
Michael Weiss d10d928193 signal-desktop: 5.11.0 -> 5.12.0
(cherry picked from commit f734643f0078b104eb3af9611eb0530a6fb503f3)
2021-08-04 09:54:55 +00:00
Michael Weiss dc7227dbd8 chromium: 92.0.4515.107 -> 92.0.4515.131
https://chromereleases.googleblog.com/2021/08/the-stable-channel-has-been-updated-to.html

This update includes 10 security fixes.

CVEs:
CVE-2021-30590 CVE-2021-30591 CVE-2021-30592 CVE-2021-30593
CVE-2021-30594 CVE-2021-30596 CVE-2021-30597

(cherry picked from commit 7015db7881584aa264e5cd21df03429ce64b14d0)
2021-08-03 08:01:59 +00:00
Michael Weiss 9b1bd6f7c7 tdesktop: Drop the enchant2 and dee dependencies
Ilya Fedin informed me that they aren't required anymore. Thanks :)

(cherry picked from commit 733756ccfc2e333658f77c657a3cd1c64d2ff1eb)
2021-07-31 12:40:08 +02:00
Michael Weiss 1d6b8ef74b tdesktop: 2.8.1 -> 2.8.3
(cherry picked from commit 3864c36b790f253e5109f833a788ece7e2dfbaa4)
2021-07-31 12:40:08 +02:00
Michael Weiss 11620afb1a kotatogram-desktop: Copy the old tg_owt.nix from tdesktop
The current tg_owt version (since the update of tdesktop to version
2.8.0 in 0d509d366d4) isn't compatible with kotatogram-desktop anymore.

(cherry picked from commit f287805fafbf9f9b3ad024a35db6b81dad76f491)
2021-07-31 12:40:08 +02:00
Michael Weiss 1de73b5b66 tdesktop: 2.8.0 -> 2.8.1
This also improves the packaging (see #128219).

(cherry picked from commit dc87cf529880ec6ddbc4ac3011928fc28ef2ff58)
2021-07-31 12:40:08 +02:00
Michael Weiss d73ddfe782 tdesktop: 2.7.5 -> 2.8.0
(cherry picked from commit 0d509d366d4fc692a9dc81366445e29da81202e6)
2021-07-31 12:40:07 +02:00
Michael Weiss ca137ac841 Merge pull request #131941 from NixOS/backport-131932-to-release-21.05
[Backport release-21.05] signal-desktop: 5.10.0 -> 5.11.0
2021-07-29 18:41:07 +02:00
Michael Weiss d8b84d9618 signal-desktop: 5.10.0 -> 5.11.0
(cherry picked from commit ce6a51bd14f3585b5ad63b672019bc8d6cf47ae9)
2021-07-29 11:10:21 +00:00
Michael Weiss 4f6946867e Merge pull request #131461 from primeos/chromium-backport
[21.05] chromium: 91.0.4472.164 -> 92.0.4515.107
2021-07-26 08:49:13 +02:00
Michael Weiss 37eae1967a Merge pull request #131363 from oxalica/fix/tdesktop-voice-chat-backport
[21.05] tdesktop: fix calls, dlopen and bundle fonts
2021-07-25 13:21:02 +02:00
Michael Weiss 4e8d55ce61 nixos/tests/chromium: Drop the workaround for Chrome GPU crashes
This regression was fixed by 51d83077ffb.

(cherry picked from commit 4ec2b24603e6eb4a48272678c75d2518de4e2191)
2021-07-25 13:04:53 +02:00
Michael Weiss 6dbb8d5098 nixos/tests/chromium: Check the version and that it's an official build
This also prints and screenshots the output of chrome://version which
contains useful information.

Outputs (stable, beta, ungoogled, chrome-stable, chrome-beta, chrome-dev):
Chromium	92.0.4515.107 (Official Build) (64-bit)
Chromium        92.0.4515.107 (Official Build) (64-bit)
Chromium        91.0.4472.164 (Official Build, ungoogled-chromium) (64-bit)
Google Chrome   92.0.4515.107 (Official Build) (64-bit)
Google Chrome   92.0.4515.107 (Official Build) beta (64-bit)
Google Chrome   93.0.4577.8 (Official Build) dev (64-bit)

(cherry picked from commit 7b3c0545149cb5c67611945d6022b61047439d61)
2021-07-25 13:04:52 +02:00
Michael Weiss 8b75191bea chromium: Fix the Ozone/Wayland support
The stable channel update to M92 (97570d30c7f) broke the Wayland support:
$ chromium --enable-features=UseOzonePlatform --ozone-platform=wayland
[31712:31712:0721/114725.940557:ERROR:wayland_connection.cc(137)] Failed to load wayland client libraries.
[31712:31712:0721/114725.940641:FATAL:ozone_platform_wayland.cc(177)] Failed to initialize Wayland platform
[0721/114725.947566:ERROR:process_memory_range.cc(75)] read out of range
Trace/breakpoint trap (core dumped)

(cherry picked from commit bb651d27fd86814087f54eaefda0a0fc04d4d6cf)
2021-07-25 13:04:11 +02:00
Michael Weiss a04e7e7ee4 chromium: 91.0.4472.164 -> 92.0.4515.107
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop_20.html

This update includes 35 security fixes.

CVEs:
CVE-2021-30565 CVE-2021-30566 CVE-2021-30567 CVE-2021-30568
CVE-2021-30569 CVE-2021-30571 CVE-2021-30572 CVE-2021-30573
CVE-2021-30574 CVE-2021-30575 CVE-2021-30576 CVE-2021-30577
CVE-2021-30578 CVE-2021-30579 CVE-2021-30580 CVE-2021-30581
CVE-2021-30582 CVE-2021-30583 CVE-2021-30584 CVE-2021-30585
CVE-2021-30586 CVE-2021-30587 CVE-2021-30588 CVE-2021-30589

Note: This won't be the smoothest update. Chromium seems to be fine but
requires gtk3 in $LD_LIBRARY_PATH to find libgtk-3.so.0 (otherwise it
crashes during startup) but Google Chrome fails to initialize
("GPU process exited unexpectedly: exit_code=132") and requires
"--use-gl=angle --use-angle=swiftshader" for hardware(?) acceleration
(which seems to work work fine and performant but SwiftShader should
actually use the CPU instead of the GPU).

(cherry picked from commit 97570d30c7f632e6ca25cf8e966d2a4b7e5aa546)
2021-07-25 13:04:11 +02:00
Michael Weiss 52e4b484ca Merge pull request #131453 from primeos/chromium-backport
[21.05] Backport the test improvements for Chromium (+ wrapper fix)
2021-07-25 12:23:26 +02:00
Michael Weiss 2eaf9b409a chromium: Check the text rendering
This should catch regressions like #131074 in the future. In that case a
glibc update caused a regression that caused most of the text to become
invisible (just not the "Web Store" we've already been checking for).

(cherry picked from commit 11400dcd65ed95292d7ac7cb30912e15ec4cf8e1)
2021-07-25 11:37:57 +02:00
Michael Weiss 24599a5ba6 nixos/tests/chromium: Print the content of chrome://{sandbox,gpu}
This can be very useful when running the test headless or e.g. when
looking at Hydra logs. Especially the chrome://gpu content contains a
lot of interesting information.
I also decided to refactor the test_new_win() function to avoid
duplicate code and rely less on xdo.

(cherry picked from commit c33015a0c94777261ef054a3d7dacd53e744ceea)
2021-07-25 11:37:57 +02:00
Michael Weiss 90e44d2f1c nixos/tests/chromium: Refactor launching the browser process
It should now be more flexible and less error-prone.

(cherry picked from commit 8c52061b1fce2036b70836e5dcdfcf4b702dd405)
2021-07-25 11:37:57 +02:00
Michael Weiss a20f9eb0ec nixos/tests/chromium: Fix the test for M92+
Unfortunately there are some regressions in the GPU code that cause
Chromium and Google Chrome to crash, e.g.:
machine # [0709/084047.890436:ERROR:process_memory_range.cc(75)] read out of range[   30.153484] show_signal: 20 callbacks suppressed
machine # [   30.153490] traps: chrome[1036] trap invalid opcode ip:55af03357b29 sp:7ffeaa69ad10 error:0 in chrome[55aefe7a4000+81ec000]
machine #
machine # [0709/084047.955039:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq: No such file or directory (2)
machine # [0709/084047.955078:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq: No such file or directory (2)
machine # [   30.126905] systemd[1]: Created slice system-systemd\x2dcoredump.slice.
machine # [   30.137012] systemd[1]: Started Process Core Dump (PID 1038/UID 0).
machine # [   30.571987] systemd-coredump[1039]: Process 1036 (chrome) of user 1000 dumped core.
machine # [992:1021:0709/084048.501937:ERROR:gpu_process_host.cc(995)] GPU process exited unexpectedly: exit_code=132
machine # [   30.594747] systemd[1]: systemd-coredump@0-1038-0.service: Succeeded.

Hopefully this'll be fixed upstream before the final release (there are
bug reports for it) but for the meantime we have to launch the beta and
dev versions with "--use-gl=angle --use-angle=swiftshader".

(cherry picked from commit f9645002a2d8615fd608bfdef4f924481dca391e)
2021-07-25 11:37:56 +02:00
Michael Weiss 40325d6d4a Merge pull request #131449 from primeos/chromium-backport
[21.05] Preparations for backporting Chromium M92
2021-07-25 11:37:34 +02:00
Michael Weiss a45acbc8e3 chromium: remove bendlas as maintainer
Their last Chromium commit is a52d7674cc from 2019.
Thank you for maintaining Chromium in the past.

(cherry picked from commit d4612af2c0d5e3c220bdd37c19272a69cc16cfd0)
2021-07-25 11:12:33 +02:00
Michael Weiss 9ede7cd91b chromiumDev: 93.0.4573.0 -> 93.0.4577.8
(cherry picked from commit 503dc62d0468e303758a720c8d650075a48956ec)
2021-07-25 11:12:32 +02:00
Michael Weiss 03f1833d1a chromiumBeta: 92.0.4515.101 -> 92.0.4515.107
(cherry picked from commit 5c6608144f9cd108565297c7c03ec79bb0fe611f)
2021-07-25 11:12:32 +02:00
Michael Weiss 741f8416c7 chromium: get-commit-message.py: Improve the parsing
The current stable release announcement [0] uses more HTML tags which
broke the detection of "fixes" and "zero_days". Proper HTML parsing
could be done using html.parser [1] but for our purposes the naive regex
trick works well enough.

[0]: https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html
[1]: https://docs.python.org/3/library/html.parser.html

(cherry picked from commit 3e93811d93b2bc88f047e9a989b456ab3ae3291c)
2021-07-25 11:12:31 +02:00
Michael Weiss affa0971db chromiumBeta: 92.0.4515.93 -> 92.0.4515.101
(cherry picked from commit b22b804e67e546edda690b3ae9a7d0c7cd38f37e)
2021-07-25 11:12:30 +02:00
Michael Weiss 4857d71209 chromiumDev: 93.0.4557.4 -> 93.0.4573.0
(cherry picked from commit 96a3799050f46967f4b1f0141a5965c79137c4a2)
2021-07-25 11:12:30 +02:00
Michael Weiss fe5ef8dbc0 chromiumBeta: 92.0.4515.80 -> 92.0.4515.93
(cherry picked from commit a571f3a94530f36ae1016cb74d2c861cb379ad5e)
2021-07-25 11:12:29 +02:00
Michael Weiss 9f9708fac7 chromiumBeta: Install crashpad_handler
This executable is required to fix a startup error.
TODO: Refactor the Nix expressions to allow chromiumVersionAtLeast, etc.
"everywhere" and investigate the VM test failure.

(cherry picked from commit ef7f020ec88c6aa92f3c35a4a83cd3517533d690)
2021-07-25 11:10:07 +02:00
Michael Weiss 1728c037de chromiumBeta: 92.0.4515.70 -> 92.0.4515.80
(cherry picked from commit 11237c7d83eb87cf9b608e4917f072b8ed206b27)
2021-07-25 11:10:06 +02:00
Michael Weiss c0a0749d1c chromiumDev: 93.0.4549.3 -> 93.0.4557.4
Would need to temporarily remove "ffmpeg" from gnSystemLibraries and
disable use_thin_lto to fix the build (theoretically).

(cherry picked from commit 5cae43456679428a675fb7074b48ceb5aa3f73e4)
2021-07-25 11:10:06 +02:00
Michael Weiss 9c2bdffc2a chromiumDev: Fix build errors due to the older system FFmpeg
The final linking still fails though, even with llvm-git.
We might have to diable use_thin_lto for now:
ld.lld: error: undefined symbol: snappy::Compress(char const*, unsigned long, std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >*)
>>> referenced by compression_module.cc
>>>               thinlto-cache/Thin-ed5ed5.tmp.o:(reporting::CompressionModule::CompressRecord(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >, base::OnceCallback<void (std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> >, absl::optional<reporting::CompressionInformation>)>) const)
clang-13: error: linker command failed with exit code 1 (use -v to see invocation)

(cherry picked from commit fcdcb819362836505e059ef1c5cb33c737883400)
2021-07-25 11:10:05 +02:00
Michael Weiss d6b4569f80 chromiumBeta: 92.0.4515.59 -> 92.0.4515.70
(cherry picked from commit e829ab8d659cd9e8c574bd366dadaefbef8793e7)
2021-07-25 11:10:04 +02:00
Michael Weiss 04accba48c chromiumDev: 93.0.4542.2 -> 93.0.4549.3
(cherry picked from commit c8fe353d8be0cb96e91fae004afb0b2d7b02c502)
2021-07-25 11:10:04 +02:00
Michael Weiss 4ee0ab1564 chromiumDev: Fix building from the release tarball
See https://bugs.chromium.org/p/chromium/issues/detail?id=1215229.
Before this the build failed with this error:
[101/47617] ACTION //build/util:chromium_git_revision(//build/toolchain/linux/unbundle:default)oaded_data.pbchain/linux/unbundle:default)
FAILED: gen/build/util/chromium_git_revision.h
python3 ../../build/util/lastchange.py --header gen/build/util/chromium_git_revision.h --revision-id-only --revision-id-prefix @ -m\ CHROMIUM_GIT_REVISION
ERROR:root:Failed to get git top directory from '/build/chromium-93.0.4542.2/build/util': Git command 'git git rev-parse --show-toplevel' in /build/chromium-93.0.4542.2/build/util failed: [Errno 2] No such file or directory: 'git'

(cherry picked from commit 8af443906d795aa562839f4968566dd58b76c0fd)
2021-07-25 11:10:03 +02:00
Michael Weiss dcf696ee71 chromiumBeta: 92.0.4515.51 -> 92.0.4515.59
(cherry picked from commit 28b48376b992a2126dfa79ddfbcc6c60d5c62438)
2021-07-25 11:10:02 +02:00
Michael Weiss 08c330473e chromiumDev: 93.0.4535.3 -> 93.0.4542.2
(cherry picked from commit 0876f689d75ab65caee1c1ba02ca1be65732a90f)
2021-07-25 11:10:02 +02:00
Michael Weiss 385d6c0d60 chromiumBeta: 92.0.4515.40 -> 92.0.4515.51
(cherry picked from commit 558cb984de748cdf86f08c8bf5d410390d2503ec)
2021-07-25 11:10:01 +02:00
Michael Weiss fd6da5164a Merge pull request #131056 from NixOS/backport-131053-to-release-21.05
[Backport release-21.05] signal-desktop: 5.9.0 -> 5.10.0
2021-07-22 13:47:52 +02:00
Michael Weiss bdf036229a signal-desktop: 5.9.0 -> 5.10.0
(cherry picked from commit 8c1f8ac915ec379872a88b2613718723dc7f6c35)
2021-07-22 10:50:12 +00:00
Michael Weiss c6f1d6bf1e mesa: 21.1.3 -> 21.1.4 2021-07-20 01:03:31 -04:00
Michael Weiss d7b32a155a mesa: 21.1.2 -> 21.1.3
I've also updated the URL for the RISC-V patch in case the content of
the old URL will change (not sure if that's possible after a merge
request is merged but now that the patch is upstream it seems like a
good idea regardless; and the content has actually already changed so
the old hash wasn't correct anymore).
2021-07-20 01:03:28 -04:00
Michael Weiss 00f0ce0618 mesa: 21.1.1 -> 21.1.2 2021-07-20 01:00:06 -04:00
Michael Weiss 71e0180f6f mesa: 21.0.3 -> 21.1.1
Note: This update likely causes some issues when running an application
that has a direct dependency on Mesa (e.g. Sway and XWayland) and was
compiled against a different Nixpkgs revision. See 7106fca0fe4 for more
details regarding that issue.
2021-07-20 01:00:03 -04:00
Michael Weiss e0e0ca92a6 mesa: 21.0.1 -> 21.0.3
Note: The update to Mesa 21.0.2 was reverted (25ae1fd29f) because it
caused major issues with Sway (segfault on startup [0]).
This is still the case and might affect all packages that directly
depend on "mesa" (for libgbm or libglapi) but it only causes issues when
the package depends on a "mesa" version that differs from "mesa.drivers"
used for "/run/opengl-driver/". I've noticed this while testing Mesa
updates with the NixOS option "hardware.opengl.package" (as usual)
instead of rebuilding my whole system (which would work). Unfortunately
this can/will likely also cause issues when mixing different channels,
using Flakes/Overlays, etc.

The cause of this should be similar to [1] ("mesa" updates now cause the
same issues that "glibc" updates already do, maybe triggered by certain
Mesa changes) and some additional discussions is in [2],[3].

Note: Don't backport this to NixOS 21.05, at least not without careful
consideration.

[0]: https://github.com/NixOS/nixpkgs/pull/118753#issuecomment-818950977
[1]: https://github.com/NixOS/nixpkgs/issues/95808
[2]: https://github.com/NixOS/nixpkgs/pull/120325
[3]: https://github.com/NixOS/nixpkgs/pull/119558
2021-07-20 01:00:00 -04:00
Michael Weiss c0b6513803 mesa: Cleanup enableRadv (not used anymore) 2021-07-20 00:59:49 -04:00
Michael Weiss 111e281dd8 llvmPackages_12: 12.0.0 -> 12.0.1
(cherry picked from commit 9a761a4fc8f0b07c6162e334b34c69ddd9c754e8)
2021-07-18 09:12:34 +00:00
Michael Weiss f4ba3aa382 Merge pull request #130516 from NixOS/backport-130438-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.114 -> 91.0.4472.164
2021-07-18 10:55:02 +02:00
Michael Weiss d313fefef8 ungoogled-chromium: 91.0.4472.114 -> 91.0.4472.164
(cherry picked from commit c5e29c786ffa9413a358ed3accf52e22a27f01cb)
2021-07-18 05:02:13 +00:00
Michael Weiss 0379b62657 Merge pull request #130363 from NixOS/backport-130360-to-release-21.05
[Backport release-21.05] chromium: 91.0.4472.114 -> 91.0.4472.164
2021-07-16 21:42:56 +02:00
Michael Weiss 76430622b7 chromium: 91.0.4472.114 -> 91.0.4472.164
https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html

This update includes 8 security fixes. Google is aware of reports that
an exploit for CVE-2021-30563 exists in the wild.

CVEs:
CVE-2021-30559 CVE-2021-30541 CVE-2021-30560 CVE-2021-30561
CVE-2021-30562 CVE-2021-30563 CVE-2021-30564

(cherry picked from commit 27523cad1edbfc0afd1a562e3408b2fa913f9483)
2021-07-16 10:24:41 +00:00
Michael Weiss 330acb7fb7 Merge pull request #130255 from NixOS/backport-130253-to-release-21.05
[Backport release-21.05] signal-desktop: 5.8.0 -> 5.9.0
2021-07-15 11:42:36 +02:00
Michael Weiss fa46c42246 signal-desktop: 5.8.0 -> 5.9.0
(cherry picked from commit 1a81de7c7231343983b983c4787b926919eaf169)
2021-07-15 09:25:01 +00:00
Michael Weiss 46667847c0 wlroots: 0.14.0 -> 0.14.1
(cherry picked from commit 7632ba310eb4fcb249abbaf67c4094afafd17c18)
2021-07-12 10:11:43 +02:00
Michael Weiss a6e07df310 Merge pull request #129641 from NixOS/backport-129633-to-release-21.05
[Backport release-21.05] signal-desktop: 5.7.1 -> 5.8.0
2021-07-08 14:46:11 +02:00
Michael Weiss 0f88b5e546 signal-desktop: 5.7.1 -> 5.8.0
(cherry picked from commit 5a5d6a785a4ccf5ca00c44ba4a6902830c082434)
2021-07-08 12:12:56 +00:00
Michael Weiss b68c1fea12 Merge pull request #128864 from NixOS/backport-128860-to-release-21.05
[Backport release-21.05] signal-desktop: 5.7.0 -> 5.7.1
2021-07-01 11:35:19 +02:00
Michael Weiss 78ee2e1314 signal-desktop: 5.7.0 -> 5.7.1
(cherry picked from commit 37749817ada45d283d6af16c03ca516ae0b3f1a9)
2021-07-01 09:17:24 +00:00
Michael Weiss 1534df8902 Merge pull request #128771 from NixOS/backport-128619-to-release-21.05
[Backport release-21.05] signal-desktop: 5.6.2 -> 5.7.0
2021-06-30 17:48:14 +02:00
Michael Weiss eb5a500b13 signal-desktop: 5.6.2 -> 5.7.0
(cherry picked from commit ea8bbfcae0508d4eff626a8467aa3ca69af46d1a)
2021-06-30 13:33:51 +00:00
Michael Weiss a563a3c2d1 sway: 1.6 -> 1.6.1
Since wlroots 0.14 setting WLR_RENDERER_ALLOW_SOFTWARE=1 to allow
software rendering is now enforced [0].

[0]: https://github.com/swaywm/wlroots/pull/2810

(cherry picked from commit 73d7f08b4d89b1af213db5db34e6f39518d88634)
2021-06-26 13:46:17 +02:00
Michael Weiss bec2f8e481 wlroots: 0.13.0 -> 0.14.0
The new release comes with breaking changes so we temporarily introduce
wlroots_0_13 for packages that don't yet support wlroots 0.14.
For the rest of the packages the required upstream patches for this new
wlroots release are fetched (if feasible).

(cherry picked from commit 203c8edcdac9491912cb21fa9d84392cb6a69eef)
2021-06-26 13:46:17 +02:00
Michael Weiss edba06511c libdrm: 2.4.105 -> 2.4.106
(cherry picked from commit 9057122e0f38fbc3aa3b246550fd1d9efae503e2)
2021-06-26 13:46:16 +02:00
Michael Weiss c83cd13ac2 Merge pull request #128100 from NixOS/backport-128091-to-release-21.05
[Backport release-21.05] signal-desktop: 5.6.1 -> 5.6.2
2021-06-25 15:46:20 +02:00
Michael Weiss dcd4d90508 signal-desktop: 5.6.1 -> 5.6.2
(cherry picked from commit 07fdb0c37551c5549bff1cfc57b7bda55b718d30)
2021-06-25 13:09:55 +00:00
Michael Weiss 015d169c3f Merge pull request #127845 from NixOS/backport-127840-to-release-21.05
[Backport release-21.05] signal-desktop: 5.5.0 -> 5.6.1
2021-06-23 01:24:29 +02:00
Michael Weiss aa6f5b6f91 signal-desktop: 5.5.0 -> 5.6.1
(cherry picked from commit 150a2f0b2eed02fd3e8a22047245870600071160)
2021-06-22 22:56:36 +00:00
Michael Weiss b66e719374 Merge pull request #127650 from NixOS/backport-127549-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.101 -> 91.0.4472.114
2021-06-21 12:24:02 +02:00
Michael Weiss c16274a260 Merge pull request #127458 from NixOS/backport-127426-to-release-21.05
[Backport release-21.05] chromium: fix APNG support
2021-06-21 12:01:36 +02:00
Michael Weiss e8d68469fc ungoogled-chromium: 91.0.4472.101 -> 91.0.4472.114
(cherry picked from commit 4e201c1c3ca99e9067e64802a877eda1e17e8f58)
2021-06-21 09:53:28 +00:00
Michael Weiss 3f6b386e54 Merge pull request #127339 from NixOS/backport-127334-to-release-21.05
[Backport release-21.05] chromium: 91.0.4472.106 -> 91.0.4472.114
2021-06-19 12:17:53 +02:00
Michael Weiss 3715be19ec chromium: 91.0.4472.106 -> 91.0.4472.114
https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop_17.html

This update includes 4 security fixes. Google is aware that an exploit
for CVE-2021-30554 exists in the wild.

CVEs:
CVE-2021-30554 CVE-2021-30555 CVE-2021-30556 CVE-2021-30557

(cherry picked from commit 0505ed81bc2a71be572117208829b5e69ea9fd65)
2021-06-18 10:48:25 +00:00
Michael Weiss 314d647bf7 Merge pull request #127113 from NixOS/backport-127109-to-release-21.05
[Backport release-21.05] signal-desktop: 5.4.1 -> 5.5.0
2021-06-16 20:14:18 +02:00
Michael Weiss 4561a449da signal-desktop: 5.4.1 -> 5.5.0
(cherry picked from commit fcda0d80a392240abdf12351b78ab32c6eaff62e)
2021-06-16 17:18:06 +00:00
Michael Weiss 2cd7bc6b9e Merge pull request #126933 from NixOS/backport-126924-to-release-21.05
[Backport release-21.05] chromium: 91.0.4472.101 -> 91.0.4472.106
2021-06-16 12:56:10 +02:00
Michael Weiss f47f0e58dc chromium: 91.0.4472.101 -> 91.0.4472.106
https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop_14.html
(cherry picked from commit 8540133fb7db4ad988ea2844c429b8b547dde370)
2021-06-15 11:17:15 +00:00
Michael Weiss e7c31a0eae Merge pull request #126740 from NixOS/backport-126662-to-release-21.05
[Backport release-21.05] ungoogled-chromium: 91.0.4472.77 -> 91.0.4472.101
2021-06-13 13:52:50 +02:00
Michael Weiss 39762d2342 ungoogled-chromium: 91.0.4472.77 -> 91.0.4472.101
(cherry picked from commit 3952d191751df8313e0ba0e17ea4818ded20e027)
2021-06-13 09:59:36 +00:00
Michael Weiss 2311321709 Merge pull request #126506 from primeos/chromium-backport
[21.05] chromium: 91.0.4472.77 -> 91.0.4472.101
2021-06-10 20:59:02 +02:00
Michael Weiss 0312d6fcf7 chromiumDev: Install crashpad_handler
This executable is required to fix a startup error:
[990:990:0609/092114.482805:FATAL:double_fork_and_exec.cc(131)] execv /nix/store/k02xhxzn6sn2cihaal68wwsyk8cg9pkg-chromium-unwrapped-93.0.4535.3/libexec/chromium/crashpad_handler: No such file or directory (2)

Unfortunately Chromium M93 still segfaults in the VM test:
machine # [0610/100626.225850:ERROR:process_memory_range.cc(75)] read out of range
machine # [0610/100626.227312:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_cur_freq: No such file or directory (2)
machine # [0610/100626.240410:ERROR:file_io_posix.cc(144)] open /sys/devices/system/cpu/cpu0/cpufreq/scaling_max_freq: No such file or directory (2)
machine # [   19.810981] systemd-coredump[1015]: Process 987 (chromium) of user 1000 dumped core.

(cherry picked from commit 1d6a0d3cf24f2edcf6755fd4db1901f9e1db1ac6)
2021-06-10 19:25:42 +02:00
Michael Weiss 06924553df chromium: get-commit-message.py: Support a new 0-day sentence
The current stable release announcement [0] uses a slightly different
message/structure.

[0]: https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html

(cherry picked from commit c02ac479ba55d802d6232cdb743f5228984e2ff9)
2021-06-10 19:25:42 +02:00