2021-01-19 06:50:56 +00:00
|
|
|
{ stdenv, lib, fetchurl, pkg-config, perl
|
2016-04-18 19:42:50 +01:00
|
|
|
, http2Support ? true, nghttp2
|
2015-06-02 10:32:28 +01:00
|
|
|
, idnSupport ? false, libidn ? null
|
|
|
|
, ldapSupport ? false, openldap ? null
|
2018-11-18 07:59:40 +00:00
|
|
|
, zlibSupport ? true, zlib ? null
|
|
|
|
, sslSupport ? zlibSupport, openssl ? null
|
2017-02-05 12:37:16 +00:00
|
|
|
, gnutlsSupport ? false, gnutls ? null
|
2019-11-28 12:26:42 +00:00
|
|
|
, wolfsslSupport ? false, wolfssl ? null
|
2018-11-18 07:59:40 +00:00
|
|
|
, scpSupport ? zlibSupport && !stdenv.isSunOS && !stdenv.isCygwin, libssh2 ? null
|
2021-08-07 13:00:00 +01:00
|
|
|
, gssSupport ? with stdenv.hostPlatform; (
|
2020-11-19 07:41:58 +00:00
|
|
|
!isWindows &&
|
2021-08-19 18:56:53 +01:00
|
|
|
# disable gss becuase of: undefined reference to `k5_bcmp'
|
2020-11-19 07:41:58 +00:00
|
|
|
# a very sad story re static: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439039
|
|
|
|
!isStatic &&
|
|
|
|
# the "mig" tool does not configure its compiler correctly. This could be
|
|
|
|
# fixed in mig, but losing gss support on cross compilation to darwin is
|
|
|
|
# not worth the effort.
|
|
|
|
!(isDarwin && (stdenv.buildPlatform != stdenv.hostPlatform))
|
|
|
|
), libkrb5 ? null
|
2015-06-02 10:32:28 +01:00
|
|
|
, c-aresSupport ? false, c-ares ? null
|
2017-11-29 10:55:11 +00:00
|
|
|
, brotliSupport ? false, brotli ? null
|
2010-07-18 22:01:17 +01:00
|
|
|
}:
|
2005-06-17 11:30:13 +01:00
|
|
|
|
2020-06-26 21:44:45 +01:00
|
|
|
# Note: this package is used for bootstrapping fetchurl, and thus
|
|
|
|
# cannot use fetchpatch! All mutable patches (generated by GitHub or
|
|
|
|
# cgit) that are needed here should be included directly in Nixpkgs as
|
|
|
|
# files.
|
|
|
|
|
2016-04-18 19:42:50 +01:00
|
|
|
assert http2Support -> nghttp2 != null;
|
2015-06-02 10:32:28 +01:00
|
|
|
assert idnSupport -> libidn != null;
|
|
|
|
assert ldapSupport -> openldap != null;
|
|
|
|
assert zlibSupport -> zlib != null;
|
|
|
|
assert sslSupport -> openssl != null;
|
2017-02-05 12:37:16 +00:00
|
|
|
assert !(gnutlsSupport && sslSupport);
|
2019-11-28 12:26:42 +00:00
|
|
|
assert !(gnutlsSupport && wolfsslSupport);
|
|
|
|
assert !(sslSupport && wolfsslSupport);
|
2017-02-05 12:37:16 +00:00
|
|
|
assert gnutlsSupport -> gnutls != null;
|
2019-11-28 12:26:42 +00:00
|
|
|
assert wolfsslSupport -> wolfssl != null;
|
2015-06-02 10:32:28 +01:00
|
|
|
assert scpSupport -> libssh2 != null;
|
|
|
|
assert c-aresSupport -> c-ares != null;
|
2017-11-29 10:55:11 +00:00
|
|
|
assert brotliSupport -> brotli != null;
|
2018-11-18 07:59:40 +00:00
|
|
|
assert gssSupport -> libkrb5 != null;
|
2015-06-01 19:52:03 +01:00
|
|
|
|
2009-03-11 15:16:17 +00:00
|
|
|
stdenv.mkDerivation rec {
|
2020-05-04 17:47:47 +01:00
|
|
|
pname = "curl";
|
2021-03-31 09:06:18 +01:00
|
|
|
version = "7.76.1";
|
2010-08-06 13:45:39 +01:00
|
|
|
|
* The stdenv setup script now defines a generic builder that allows
builders for typical Autoconf-style to be much shorten, e.g.,
. $stdenv/setup
genericBuild
The generic builder does lots of stuff automatically:
- Unpacks source archives specified by $src or $srcs (it knows about
gzip, bzip2, tar, zip, and unpacked source trees).
- Determines the source tree.
- Applies patches specified by $patches.
- Fixes libtool not to search for libraries in /lib etc.
- Runs `configure'.
- Runs `make'.
- Runs `make install'.
- Strips debug information from static libraries.
- Writes nested log information (in the format accepted by
`log2xml').
There are also lots of hooks and variables to customise the generic
builder. See `stdenv/generic/docs.txt'.
* Adapted the base packages (i.e., the ones used by stdenv) to use the
generic builder.
* We now use `curl' instead of `wget' to download files in `fetchurl'.
* Neither `curl' nor `wget' are part of stdenv. We shouldn't
encourage people to download stuff in builders (impure!).
* Updated some packages.
* `buildinputs' is now `buildInputs' (but the old name also works).
* `findInputs' in the setup script now prevents inputs from being
processed multiple times (which could happen, e.g., if an input was
a propagated input of several other inputs; this caused the size
variables like $PATH to blow up exponentially in the worst case).
* Patched GNU Make to write nested log information in the format
accepted by `log2xml'. Also, prior to writing the build command,
Make now writes a line `building X' to indicate what is being
built. This is unfortunately often obscured by the gigantic tool
invocations in many Makefiles. The actual build commands are marked
`unimportant' so that they don't clutter pages generated by
`log2html'.
svn path=/nixpkgs/trunk/; revision=845
2004-03-19 16:53:04 +00:00
|
|
|
src = fetchurl {
|
2018-03-15 23:08:12 +00:00
|
|
|
urls = [
|
2020-05-04 17:47:47 +01:00
|
|
|
"https://curl.haxx.se/download/${pname}-${version}.tar.bz2"
|
|
|
|
"https://github.com/curl/curl/releases/download/${lib.replaceStrings ["."] ["_"] pname}-${version}/${pname}-${version}.tar.bz2"
|
2018-03-15 23:08:12 +00:00
|
|
|
];
|
2021-03-31 09:06:18 +01:00
|
|
|
sha256 = "1scmfrp0c27pkd7yva9k50miprjpsyfbb33apx72qc9igm6ii3ks";
|
* The stdenv setup script now defines a generic builder that allows
builders for typical Autoconf-style to be much shorten, e.g.,
. $stdenv/setup
genericBuild
The generic builder does lots of stuff automatically:
- Unpacks source archives specified by $src or $srcs (it knows about
gzip, bzip2, tar, zip, and unpacked source trees).
- Determines the source tree.
- Applies patches specified by $patches.
- Fixes libtool not to search for libraries in /lib etc.
- Runs `configure'.
- Runs `make'.
- Runs `make install'.
- Strips debug information from static libraries.
- Writes nested log information (in the format accepted by
`log2xml').
There are also lots of hooks and variables to customise the generic
builder. See `stdenv/generic/docs.txt'.
* Adapted the base packages (i.e., the ones used by stdenv) to use the
generic builder.
* We now use `curl' instead of `wget' to download files in `fetchurl'.
* Neither `curl' nor `wget' are part of stdenv. We shouldn't
encourage people to download stuff in builders (impure!).
* Updated some packages.
* `buildinputs' is now `buildInputs' (but the old name also works).
* `findInputs' in the setup script now prevents inputs from being
processed multiple times (which could happen, e.g., if an input was
a propagated input of several other inputs; this caused the size
variables like $PATH to blow up exponentially in the worst case).
* Patched GNU Make to write nested log information in the format
accepted by `log2xml'. Also, prior to writing the build command,
Make now writes a line `building X' to indicate what is being
built. This is unfortunately often obscured by the gigantic tool
invocations in many Makefiles. The actual build commands are marked
`unimportant' so that they don't clutter pages generated by
`log2html'.
svn path=/nixpkgs/trunk/; revision=845
2004-03-19 16:53:04 +00:00
|
|
|
};
|
2010-08-06 13:45:39 +01:00
|
|
|
|
2021-05-30 18:12:53 +01:00
|
|
|
patches = [
|
|
|
|
./CVE-2021-22897.patch
|
|
|
|
./CVE-2021-22898.patch
|
|
|
|
./CVE-2021-22901.patch
|
2021-09-27 22:10:21 +01:00
|
|
|
./CVE-2021-22945.patch
|
2021-05-30 18:12:53 +01:00
|
|
|
];
|
|
|
|
|
2016-09-01 10:07:23 +01:00
|
|
|
outputs = [ "bin" "dev" "out" "man" "devdoc" ];
|
2017-07-05 15:04:54 +01:00
|
|
|
separateDebugInfo = stdenv.isLinux;
|
2015-10-06 14:32:17 +01:00
|
|
|
|
2017-01-24 12:51:30 +00:00
|
|
|
enableParallelBuilding = true;
|
|
|
|
|
2021-08-11 13:00:00 +01:00
|
|
|
strictDeps = true;
|
|
|
|
|
2021-01-19 06:50:56 +00:00
|
|
|
nativeBuildInputs = [ pkg-config perl ];
|
2016-01-31 14:30:40 +00:00
|
|
|
|
2015-06-02 10:32:28 +01:00
|
|
|
# Zlib and OpenSSL must be propagated because `libcurl.la' contains
|
|
|
|
# "-lz -lssl", which aren't necessary direct build inputs of
|
|
|
|
# applications that use Curl.
|
2021-01-15 09:19:50 +00:00
|
|
|
propagatedBuildInputs = with lib;
|
2016-04-18 19:42:50 +01:00
|
|
|
optional http2Support nghttp2 ++
|
2015-06-02 10:32:28 +01:00
|
|
|
optional idnSupport libidn ++
|
|
|
|
optional ldapSupport openldap ++
|
|
|
|
optional zlibSupport zlib ++
|
2018-11-18 07:59:40 +00:00
|
|
|
optional gssSupport libkrb5 ++
|
2015-06-02 10:32:28 +01:00
|
|
|
optional c-aresSupport c-ares ++
|
|
|
|
optional sslSupport openssl ++
|
2017-02-05 12:37:16 +00:00
|
|
|
optional gnutlsSupport gnutls ++
|
2019-11-28 12:26:42 +00:00
|
|
|
optional wolfsslSupport wolfssl ++
|
2017-11-29 10:55:11 +00:00
|
|
|
optional scpSupport libssh2 ++
|
|
|
|
optional brotliSupport brotli;
|
2015-06-02 10:32:28 +01:00
|
|
|
|
2017-08-02 22:50:51 +01:00
|
|
|
# for the second line see https://curl.haxx.se/mail/tracker-2014-03/0087.html
|
2015-06-02 10:32:28 +01:00
|
|
|
preConfigure = ''
|
|
|
|
sed -e 's|/usr/bin|/no-such-path|g' -i.bak configure
|
|
|
|
rm src/tool_hugehelp.c
|
|
|
|
'';
|
2013-09-07 01:38:36 +01:00
|
|
|
|
2012-10-27 18:28:08 +01:00
|
|
|
configureFlags = [
|
2018-06-23 11:13:23 +01:00
|
|
|
# Disable default CA bundle, use NIX_SSL_CERT_FILE or fallback
|
|
|
|
# to nss-cacert from the default profile.
|
|
|
|
"--without-ca-bundle"
|
|
|
|
"--without-ca-path"
|
2019-11-28 12:26:42 +00:00
|
|
|
# The build fails when using wolfssl with --with-ca-fallback
|
2021-09-07 01:59:03 +01:00
|
|
|
(lib.withFeature (!wolfsslSupport) "ca-fallback")
|
2014-08-23 03:26:04 +01:00
|
|
|
"--disable-manual"
|
2021-08-19 18:56:53 +01:00
|
|
|
(lib.withFeatureAs sslSupport "ssl" openssl.dev)
|
|
|
|
(lib.withFeatureAs gnutlsSupport "gnutls" gnutls.dev)
|
|
|
|
(lib.withFeatureAs scpSupport "libssh2" libssh2.dev)
|
|
|
|
(lib.enableFeature ldapSupport "ldap")
|
|
|
|
(lib.enableFeature ldapSupport "ldaps")
|
|
|
|
(lib.withFeatureAs idnSupport "libidn" libidn.dev)
|
|
|
|
(lib.withFeature brotliSupport "brotli")
|
2015-06-02 10:32:28 +01:00
|
|
|
]
|
2021-01-15 09:19:50 +00:00
|
|
|
++ lib.optional wolfsslSupport "--with-wolfssl=${wolfssl.dev}"
|
|
|
|
++ lib.optional c-aresSupport "--enable-ares=${c-ares}"
|
|
|
|
++ lib.optional gssSupport "--with-gssapi=${libkrb5.dev}"
|
2018-07-23 20:51:18 +01:00
|
|
|
# For the 'urandom', maybe it should be a cross-system option
|
2021-01-15 09:19:50 +00:00
|
|
|
++ lib.optional (stdenv.hostPlatform != stdenv.buildPlatform)
|
2018-10-17 20:44:35 +01:00
|
|
|
"--with-random=/dev/urandom"
|
2021-01-15 09:19:50 +00:00
|
|
|
++ lib.optionals stdenv.hostPlatform.isWindows [
|
2018-10-17 20:44:35 +01:00
|
|
|
"--disable-shared"
|
|
|
|
"--enable-static"
|
|
|
|
];
|
2010-03-06 15:17:43 +00:00
|
|
|
|
2017-10-28 04:17:55 +01:00
|
|
|
CXX = "${stdenv.cc.targetPrefix}c++";
|
|
|
|
CXXCPP = "${stdenv.cc.targetPrefix}c++ -E";
|
2015-06-02 10:32:28 +01:00
|
|
|
|
2018-04-25 04:20:18 +01:00
|
|
|
doCheck = false; # expensive, fails
|
|
|
|
|
2015-10-06 14:32:17 +01:00
|
|
|
postInstall = ''
|
2015-12-02 09:03:23 +00:00
|
|
|
moveToOutput bin/curl-config "$dev"
|
2019-04-17 18:43:37 +01:00
|
|
|
|
|
|
|
# Install completions
|
|
|
|
make -C scripts install
|
2021-01-15 09:19:50 +00:00
|
|
|
'' + lib.optionalString scpSupport ''
|
2015-10-06 14:32:17 +01:00
|
|
|
sed '/^dependency_libs/s|${libssh2.dev}|${libssh2.out}|' -i "$out"/lib/*.la
|
2021-01-15 09:19:50 +00:00
|
|
|
'' + lib.optionalString gnutlsSupport ''
|
2017-02-05 12:37:16 +00:00
|
|
|
ln $out/lib/libcurl.so $out/lib/libcurl-gnutls.so
|
|
|
|
ln $out/lib/libcurl.so $out/lib/libcurl-gnutls.so.4
|
|
|
|
ln $out/lib/libcurl.so $out/lib/libcurl-gnutls.so.4.4.0
|
2015-10-06 14:32:17 +01:00
|
|
|
'';
|
|
|
|
|
2015-06-02 10:32:28 +01:00
|
|
|
passthru = {
|
|
|
|
inherit sslSupport openssl;
|
|
|
|
};
|
2015-06-02 10:32:16 +01:00
|
|
|
|
2021-01-11 07:54:33 +00:00
|
|
|
meta = with lib; {
|
2008-04-23 10:30:09 +01:00
|
|
|
description = "A command line tool for transferring files with URL syntax";
|
2020-04-01 02:11:51 +01:00
|
|
|
homepage = "https://curl.haxx.se/";
|
2018-08-16 20:36:36 +01:00
|
|
|
license = licenses.curl;
|
2020-05-04 17:47:47 +01:00
|
|
|
maintainers = with maintainers; [ lovek323 ];
|
2018-08-16 20:36:36 +01:00
|
|
|
platforms = platforms.all;
|
2021-09-06 21:40:46 +01:00
|
|
|
# Fails to link against static brotli or gss
|
|
|
|
broken = stdenv.hostPlatform.isStatic && (brotliSupport || gssSupport);
|
2008-04-23 10:30:09 +01:00
|
|
|
};
|
2007-05-24 14:34:34 +01:00
|
|
|
}
|