Commit Graph

287312 Commits

Author SHA1 Message Date
sternenseemann
f39a5c4e50 lib/strings: forbid lists in isStorePath
When a list is passed to isStorePath this is most likely a mistake and
it is therefore better to just return false. There is one case where
this theoretically makes sense (if a list contains a single element for
which isStorePath elem), but since that case is also probably seldomly
intentional, it may save someone from debbuging unclear evaluation
errors.
2021-05-07 01:22:30 +02:00
sternenseemann
326d0970e0 lib/strings: fix example for isStorePath
Since it checks if dirOf x is the nix store dir, a trailing slash will
break this check and make it return false.
2021-05-07 01:22:30 +02:00
Sander van der Burg
5af7d3ebbd
Merge pull request #121936 from svanderburg/disnix_style_fixes
Disnix style fixes
2021-05-06 21:30:59 +02:00
Jonathan Ringer
ac36e938f2 python3Packages.azure-storage: fix missing dep 2021-05-06 11:50:10 -07:00
Jonathan Ringer
00cb1ea400 azure-cli: 2.20.0 -> 2.23.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
fa58d21382 python3Packages.azure-mgmt-servicefabricmanagedclusters: init at 1.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
67c2e45b2a python3Packages.azure-synapse-artifacts: 0.5.0 -> 0.6.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
e38f56aa4f python3Packages.azure-storage-file-share: 12.4.1 -> 12.4.2 2021-05-06 11:50:10 -07:00
Jonathan Ringer
03f5eafcd0 python3Packages.azure-storage-blob: 12.8.0 -> 12.8.1 2021-05-06 11:50:10 -07:00
Jonathan Ringer
c2dd90a895 python3Packages.azure-servicefabric: 7.2.0.46 -> 8.0.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
e22c8bc8c6 python3Packages.azure-servicebus: 7.1.0 -> 7.1.1 2021-05-06 11:50:10 -07:00
Jonathan Ringer
015825f224 python3Packages.azure-mgmt-synapse: 1.0.0 -> 2.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
a808925e9b python3Packages.azure-mgmt-storage: 17.0.0 -> 17.1.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
24ca01abe5 python3Packages.azure-mgmt-resource: 16.0.0 -> 16.1.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
102b7b1644 python3Packages.azure-mgmt-privatedns: 0.1.0 -> 1.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
750507ae6b python3Packages.azure-mgmt-maps: 0.1.0 -> 1.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
19ec2ee159 python3Packages.azure-mgmt-managedservices: 1.0.0 -> 6.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
9e122f8864 python3Packages.azure-mgmt-loganalytics: 8.0.0 -> 9.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
7c68e8e622 python3Packages.azure-mgmt-kusto: 1.0.0 -> 2.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
43f97a6cca python3Packages.azure-mgmt-keyvault: 8.0.0 -> 9.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
3b6e8aa4ec python3Packages.azure-mgmt-hanaonazure: 0.15.0 -> 1.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
82437398a6 python3Packages.azure-mgmt-dns: 3.0.0 -> 8.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
2d1a12ba9a python3Packages.azure-mgmt-datamigration: 4.1.0 -> 9.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
939c236154 python3Packages.azure-mgmt-databoxedge: 0.2.0 -> 1.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
44451e292f python3Packages.azure-mgmt-cosmosdb: 6.1.0 -> 6.2.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
aff15bcca1 python3Packages.azure-mgmt-containerservice: 15.0.0 -> 15.1.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
8665095ea1 python3Packages.azure-mgmt-compute: 19.0.0 -> 20.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
6a91defc7d python3Packages.azure-mgmt-cdn: 10.0.0 -> 11.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
df64191897 python3Packages.azure-mgmt-apimanagement: 1.0.0 -> 2.0.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
57dccbab5a python3Packages.azure-eventgrid: 4.1.0 -> 4.1.1 2021-05-06 11:50:10 -07:00
Jonathan Ringer
7d85bc2b82 python3Packages.azure-datalake-store: 0.0.51 -> 0.0.52 2021-05-06 11:50:10 -07:00
Jonathan Ringer
3ef55161e5 python3Packages.azure-core: 1.12.0 -> 1.13.0 2021-05-06 11:50:10 -07:00
Jonathan Ringer
3fe1f00593 python3Packages.azure-common: 1.1.26 -> 1.1.27 2021-05-06 11:50:10 -07:00
Jonathan Ringer
e219febe6c python3Packages.uamqp: 1.2.13 -> 1.4.0 2021-05-06 11:50:10 -07:00
Emery Hemingway
dfacb8329b nym: remove unused inputs 2021-05-06 19:54:46 +02:00
Andrey Kuznetsov
f9104687f6 nym: 0.8.1 -> 0.10.0 2021-05-06 19:46:16 +02:00
Sander van der Burg
77295e7e6b nixos/disnix: configure the remote client by default, if multi-user mode has been enabled 2021-05-06 19:33:02 +02:00
Sander van der Burg
a4c768fccd dydisnix: tidy up expression 2021-05-06 19:28:50 +02:00
Sander van der Burg
52c427b8be dysnomia: make function header more readable 2021-05-06 19:15:46 +02:00
Fabian Affolter
28907d3bff
Merge pull request #121677 from fabaff/bump-labelbox
python3Packages.labelbox: 2.5.1 -> 2.5.4
2021-05-06 18:42:27 +02:00
R. RyanTM
59bf1c28dc
kubecfg: 0.18.0 -> 0.19.0 (#121884) 2021-05-06 12:22:25 -04:00
Martin Weinelt
6a09bc4405
Merge pull request #121865 from mweinelt/home-assistant 2021-05-06 18:05:00 +02:00
Martin Weinelt
51836ac425
Merge pull request #121705 from mweinelt/esphome
esphome: 1.16.0 -> 1.17.1
2021-05-06 18:03:51 +02:00
John Ericson
8e84cafcd9
Merge pull request #121654 from Ericson2314/darwin-cross-prep
treewide: Do a number of no-op cleanups for cross and darwin
2021-05-06 11:38:09 -04:00
Thomas Tuegel
67c476a5cc
Merge pull request #121682 from dasj19/clementine-translations
clementine: added support for translations
2021-05-06 10:36:12 -05:00
Thomas Tuegel
3548951109
Merge pull request #121256 from FliegendeWurst/k3b-ffmpeg
k3b: ffmpeg_3 -> ffmpeg
2021-05-06 10:34:32 -05:00
John Ericson
470640e7fe treewide: Do a number of no-op cleanups for cross and darwin
I am taking the non-invasive parts of #110914 to hopefully help out with #111988.

In particular:

 - Use `lib.makeScopeWithSplicing` to make the `darwin` package set have
   a proper `callPackage`.

 - Adjust Darwin `stdenv`'s overlays keeping things from the previous
   stage to not stick around too much.

 - Expose `binutilsNoLibc` / `darwin.binutilsNoLibc` to hopefully get us
   closer to a unified LLVM and GCC bootstrap.
2021-05-06 11:17:26 -04:00
Domen Kožar
0fbace6296
Merge pull request #119405 from hercules-ci/openapi-generator-cli-jre-headless
openapi-generator-cli: Use headless jre
2021-05-06 17:09:07 +02:00
Martin Weinelt
398b0cf6bd
python3Packages.PyRMVtransport: 0.3.1 -> 0.3.2 2021-05-06 17:04:38 +02:00
Martin Weinelt
24adc01e2e
nixos/home-assistant: allow netlink sockets and /proc/net inspection
Since v2021.5.0 home-assistant uses the ifaddr library in the zeroconf
component to enumerate network interfaces via netlink. Since discovery
is all over the place lets allow AF_NETLINK unconditionally.

It also relies on pyroute2 now, which additionally tries to access files
in /proc/net, so we relax ProtectProc a bit by default as well.

This leaves us with these options unsecured:

✗ PrivateNetwork=                                             Service has access to the host's network                                                                 0.5
✗ RestrictAddressFamilies=~AF_(INET|INET6)                    Service may allocate Internet sockets                                                                    0.3
✗ DeviceAllow=                                                Service has a device ACL with some special devices                                                       0.1
✗ IPAddressDeny=                                              Service does not define an IP address allow list                                                         0.2
✗ PrivateDevices=                                             Service potentially has access to hardware devices                                                       0.2
✗ PrivateUsers=                                               Service has access to other users                                                                        0.2
✗ SystemCallFilter=~@resources                                System call allow list defined for service, and @resources is included (e.g. ioprio_set is allowed)      0.2
✗ RestrictAddressFamilies=~AF_NETLINK                         Service may allocate netlink sockets                                                                     0.1
✗ RootDirectory=/RootImage=                                   Service runs within the host's root directory                                                            0.1
✗ SupplementaryGroups=                                        Service runs with supplementary groups                                                                   0.1
✗ RestrictAddressFamilies=~AF_UNIX                            Service may allocate local sockets                                                                       0.1
✗ ProcSubset=                                                 Service has full access to non-process /proc files (/proc subset=)                                       0.1

→ Overall exposure level for home-assistant.service: 1.6 OK 🙂
2021-05-06 16:55:53 +02:00