2023-11-16 04:20:00 +00:00
|
|
|
{ lib, stdenv, fetchurl, darwin, pkg-config, perl, nixosTests
|
2022-07-18 16:21:45 +00:00
|
|
|
, brotliSupport ? false, brotli
|
2022-10-30 15:09:59 +00:00
|
|
|
, c-aresSupport ? false, c-aresMinimal
|
2022-07-18 16:21:45 +00:00
|
|
|
, gnutlsSupport ? false, gnutls
|
|
|
|
, gsaslSupport ? false, gsasl
|
2021-09-18 10:52:07 +00:00
|
|
|
, gssSupport ? with stdenv.hostPlatform; (
|
2021-05-28 09:39:13 +00:00
|
|
|
!isWindows &&
|
2023-05-24 13:37:59 +00:00
|
|
|
# disable gss because of: undefined reference to `k5_bcmp'
|
2021-05-28 09:39:13 +00:00
|
|
|
# a very sad story re static: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439039
|
|
|
|
!isStatic &&
|
|
|
|
# the "mig" tool does not configure its compiler correctly. This could be
|
|
|
|
# fixed in mig, but losing gss support on cross compilation to darwin is
|
|
|
|
# not worth the effort.
|
|
|
|
!(isDarwin && (stdenv.buildPlatform != stdenv.hostPlatform))
|
2022-07-18 16:21:45 +00:00
|
|
|
), libkrb5
|
|
|
|
, http2Support ? true, nghttp2
|
|
|
|
, http3Support ? false, nghttp3, ngtcp2
|
2024-01-25 14:12:00 +00:00
|
|
|
, websocketSupport ? false
|
2022-07-18 16:21:45 +00:00
|
|
|
, idnSupport ? false, libidn2
|
|
|
|
, ldapSupport ? false, openldap
|
|
|
|
, opensslSupport ? zlibSupport, openssl
|
|
|
|
, pslSupport ? false, libpsl
|
|
|
|
, rtmpSupport ? false, rtmpdump
|
2024-09-26 11:04:55 +00:00
|
|
|
, scpSupport ? zlibSupport && !stdenv.hostPlatform.isSunOS && !stdenv.hostPlatform.isCygwin, libssh2
|
2022-07-18 16:21:45 +00:00
|
|
|
, wolfsslSupport ? false, wolfssl
|
2023-04-12 12:48:02 +00:00
|
|
|
, rustlsSupport ? false, rustls-ffi
|
2022-07-18 16:21:45 +00:00
|
|
|
, zlibSupport ? true, zlib
|
|
|
|
, zstdSupport ? false, zstd
|
2022-05-18 14:49:53 +00:00
|
|
|
|
|
|
|
# for passthru.tests
|
|
|
|
, coeurl
|
|
|
|
, curlpp
|
|
|
|
, haskellPackages
|
|
|
|
, ocamlPackages
|
|
|
|
, phpExtensions
|
2024-02-29 20:09:43 +00:00
|
|
|
, pkgsStatic
|
2022-05-18 14:49:53 +00:00
|
|
|
, python3
|
2022-08-12 12:06:08 +00:00
|
|
|
, tests
|
2023-02-16 17:41:37 +00:00
|
|
|
, testers
|
2022-08-12 12:06:08 +00:00
|
|
|
, fetchpatch
|
2020-04-24 23:36:52 +00:00
|
|
|
}:
|
|
|
|
|
2020-08-20 17:08:02 +00:00
|
|
|
# Note: this package is used for bootstrapping fetchurl, and thus
|
|
|
|
# cannot use fetchpatch! All mutable patches (generated by GitHub or
|
|
|
|
# cgit) that are needed here should be included directly in Nixpkgs as
|
|
|
|
# files.
|
|
|
|
|
2023-04-12 12:48:02 +00:00
|
|
|
assert !((lib.count (x: x) [ gnutlsSupport opensslSupport wolfsslSupport rustlsSupport ]) > 1);
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2022-08-12 12:06:08 +00:00
|
|
|
stdenv.mkDerivation (finalAttrs: {
|
2020-06-02 18:00:15 +00:00
|
|
|
pname = "curl";
|
2024-09-19 14:19:46 +00:00
|
|
|
version = "8.9.1";
|
2020-04-24 23:36:52 +00:00
|
|
|
|
|
|
|
src = fetchurl {
|
|
|
|
urls = [
|
2023-08-10 07:59:29 +00:00
|
|
|
"https://curl.haxx.se/download/curl-${finalAttrs.version}.tar.xz"
|
2023-10-09 19:29:22 +00:00
|
|
|
"https://github.com/curl/curl/releases/download/curl-${builtins.replaceStrings [ "." ] [ "_" ] finalAttrs.version}/curl-${finalAttrs.version}.tar.xz"
|
2020-04-24 23:36:52 +00:00
|
|
|
];
|
2024-09-19 14:19:46 +00:00
|
|
|
hash = "sha256-8pL2zAUdW7q/cl74XUMt/qzIcR3XF+qXYSrlkGQ4AeU=";
|
2020-04-24 23:36:52 +00:00
|
|
|
};
|
|
|
|
|
2024-09-19 14:19:46 +00:00
|
|
|
patches = [
|
|
|
|
# fixes https://github.com/curl/curl/issues/14344
|
|
|
|
# https://github.com/curl/curl/pull/14390
|
|
|
|
./fix-sigpipe-leak.patch
|
|
|
|
] ++ lib.optionals gnutlsSupport [
|
|
|
|
# https://curl.se/docs/CVE-2024-8096.html
|
|
|
|
./CVE-2024-8096.patch
|
2024-05-15 15:35:15 +00:00
|
|
|
];
|
|
|
|
|
2024-06-20 14:57:18 +00:00
|
|
|
# this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion
|
|
|
|
# necessary for FreeBSD code path in configure
|
2024-02-29 20:09:43 +00:00
|
|
|
postPatch = ''
|
2024-06-20 14:57:18 +00:00
|
|
|
substituteInPlace ./config.guess --replace-fail /usr/bin/uname uname
|
2024-02-29 20:09:43 +00:00
|
|
|
patchShebangs scripts
|
|
|
|
'';
|
2024-01-13 08:15:51 +00:00
|
|
|
|
2020-04-24 23:36:52 +00:00
|
|
|
outputs = [ "bin" "dev" "out" "man" "devdoc" ];
|
2024-09-26 11:04:55 +00:00
|
|
|
separateDebugInfo = stdenv.hostPlatform.isLinux;
|
2020-04-24 23:36:52 +00:00
|
|
|
|
|
|
|
enableParallelBuilding = true;
|
|
|
|
|
2021-09-18 10:52:07 +00:00
|
|
|
strictDeps = true;
|
|
|
|
|
2021-02-05 17:12:51 +00:00
|
|
|
nativeBuildInputs = [ pkg-config perl ];
|
2020-04-24 23:36:52 +00:00
|
|
|
|
|
|
|
# Zlib and OpenSSL must be propagated because `libcurl.la' contains
|
|
|
|
# "-lz -lssl", which aren't necessary direct build inputs of
|
|
|
|
# applications that use Curl.
|
2024-09-19 14:19:46 +00:00
|
|
|
propagatedBuildInputs =
|
|
|
|
lib.optional brotliSupport brotli ++
|
|
|
|
lib.optional c-aresSupport c-aresMinimal ++
|
|
|
|
lib.optional gnutlsSupport gnutls ++
|
|
|
|
lib.optional gsaslSupport gsasl ++
|
|
|
|
lib.optional gssSupport libkrb5 ++
|
|
|
|
lib.optional http2Support nghttp2 ++
|
|
|
|
lib.optionals http3Support [ nghttp3 ngtcp2 ] ++
|
|
|
|
lib.optional idnSupport libidn2 ++
|
|
|
|
lib.optional ldapSupport openldap ++
|
|
|
|
lib.optional opensslSupport openssl ++
|
|
|
|
lib.optional pslSupport libpsl ++
|
|
|
|
lib.optional rtmpSupport rtmpdump ++
|
|
|
|
lib.optional scpSupport libssh2 ++
|
|
|
|
lib.optional wolfsslSupport wolfssl ++
|
|
|
|
lib.optional rustlsSupport rustls-ffi ++
|
|
|
|
lib.optional zlibSupport zlib ++
|
|
|
|
lib.optional zstdSupport zstd ++
|
2024-09-26 11:04:55 +00:00
|
|
|
lib.optionals stdenv.hostPlatform.isDarwin (with darwin.apple_sdk.frameworks; [
|
2023-11-16 04:20:00 +00:00
|
|
|
CoreFoundation
|
|
|
|
CoreServices
|
|
|
|
SystemConfiguration
|
|
|
|
]);
|
2020-04-24 23:36:52 +00:00
|
|
|
|
|
|
|
# for the second line see https://curl.haxx.se/mail/tracker-2014-03/0087.html
|
|
|
|
preConfigure = ''
|
|
|
|
sed -e 's|/usr/bin|/no-such-path|g' -i.bak configure
|
|
|
|
rm src/tool_hugehelp.c
|
2024-02-29 20:09:43 +00:00
|
|
|
'' + lib.optionalString (pslSupport && stdenv.hostPlatform.isStatic) ''
|
|
|
|
# curl doesn't understand that libpsl2 has deps because it doesn't use
|
|
|
|
# pkg-config.
|
|
|
|
# https://github.com/curl/curl/pull/12919
|
|
|
|
configureFlagsArray+=("LIBS=-lidn2 -lunistring")
|
2020-04-24 23:36:52 +00:00
|
|
|
'';
|
|
|
|
|
|
|
|
configureFlags = [
|
2024-09-19 14:19:46 +00:00
|
|
|
"--enable-versioned-symbols"
|
2022-01-26 04:04:25 +00:00
|
|
|
# Build without manual
|
|
|
|
"--disable-manual"
|
|
|
|
(lib.enableFeature c-aresSupport "ares")
|
|
|
|
(lib.enableFeature ldapSupport "ldap")
|
|
|
|
(lib.enableFeature ldapSupport "ldaps")
|
2024-01-25 14:12:00 +00:00
|
|
|
(lib.enableFeature websocketSupport "websockets")
|
2023-04-12 12:48:02 +00:00
|
|
|
# --with-ca-fallback is only supported for openssl and gnutls https://github.com/curl/curl/blame/curl-8_0_1/acinclude.m4#L1640
|
|
|
|
(lib.withFeature (opensslSupport || gnutlsSupport) "ca-fallback")
|
2022-01-26 04:04:25 +00:00
|
|
|
(lib.withFeature http3Support "nghttp3")
|
|
|
|
(lib.withFeature http3Support "ngtcp2")
|
|
|
|
(lib.withFeature rtmpSupport "librtmp")
|
2023-04-12 12:48:02 +00:00
|
|
|
(lib.withFeature rustlsSupport "rustls")
|
2022-01-26 04:04:25 +00:00
|
|
|
(lib.withFeature zstdSupport "zstd")
|
2024-02-29 20:09:43 +00:00
|
|
|
(lib.withFeature pslSupport "libpsl")
|
2022-01-26 04:04:25 +00:00
|
|
|
(lib.withFeatureAs brotliSupport "brotli" (lib.getDev brotli))
|
2021-12-26 17:43:05 +00:00
|
|
|
(lib.withFeatureAs gnutlsSupport "gnutls" (lib.getDev gnutls))
|
2022-01-26 04:04:25 +00:00
|
|
|
(lib.withFeatureAs idnSupport "libidn2" (lib.getDev libidn2))
|
|
|
|
(lib.withFeatureAs opensslSupport "openssl" (lib.getDev openssl))
|
2021-12-26 17:43:05 +00:00
|
|
|
(lib.withFeatureAs scpSupport "libssh2" (lib.getDev libssh2))
|
2022-01-26 04:04:25 +00:00
|
|
|
(lib.withFeatureAs wolfsslSupport "wolfssl" (lib.getDev wolfssl))
|
2020-04-24 23:36:52 +00:00
|
|
|
]
|
2021-12-26 17:43:05 +00:00
|
|
|
++ lib.optional gssSupport "--with-gssapi=${lib.getDev libkrb5}"
|
2020-04-24 23:36:52 +00:00
|
|
|
# For the 'urandom', maybe it should be a cross-system option
|
2021-01-15 22:18:51 +00:00
|
|
|
++ lib.optional (stdenv.hostPlatform != stdenv.buildPlatform)
|
2020-04-24 23:36:52 +00:00
|
|
|
"--with-random=/dev/urandom"
|
2021-01-15 22:18:51 +00:00
|
|
|
++ lib.optionals stdenv.hostPlatform.isWindows [
|
2020-04-24 23:36:52 +00:00
|
|
|
"--disable-shared"
|
|
|
|
"--enable-static"
|
2024-09-26 11:04:55 +00:00
|
|
|
] ++ lib.optionals stdenv.hostPlatform.isDarwin [
|
2022-04-27 09:35:20 +00:00
|
|
|
# Disable default CA bundle, use NIX_SSL_CERT_FILE or fallback to nss-cacert from the default profile.
|
|
|
|
# Without this curl might detect /etc/ssl/cert.pem at build time on macOS, causing curl to ignore NIX_SSL_CERT_FILE.
|
2022-05-18 14:49:53 +00:00
|
|
|
"--without-ca-bundle"
|
2022-04-27 09:35:20 +00:00
|
|
|
"--without-ca-path"
|
2023-04-12 12:48:02 +00:00
|
|
|
] ++ lib.optionals (!gnutlsSupport && !opensslSupport && !wolfsslSupport && !rustlsSupport) [
|
2023-03-27 19:17:25 +00:00
|
|
|
"--without-ssl"
|
2024-09-26 11:04:55 +00:00
|
|
|
] ++ lib.optionals (rustlsSupport && !stdenv.hostPlatform.isDarwin) [
|
2024-09-19 14:19:46 +00:00
|
|
|
"--with-ca-bundle=/etc/ssl/certs/ca-certificates.crt"
|
2024-09-26 11:04:55 +00:00
|
|
|
] ++ lib.optionals (gnutlsSupport && !stdenv.hostPlatform.isDarwin) [
|
2024-07-31 10:19:44 +00:00
|
|
|
"--with-ca-path=/etc/ssl/certs"
|
2020-04-24 23:36:52 +00:00
|
|
|
];
|
|
|
|
|
|
|
|
CXX = "${stdenv.cc.targetPrefix}c++";
|
|
|
|
CXXCPP = "${stdenv.cc.targetPrefix}c++ -E";
|
|
|
|
|
2022-08-12 12:06:08 +00:00
|
|
|
# takes 14 minutes on a 24 core and because many other packages depend on curl
|
|
|
|
# they cannot be run concurrently and are a bottleneck
|
|
|
|
# tests are available in passthru.tests.withCheck
|
|
|
|
doCheck = false;
|
2022-05-18 14:49:53 +00:00
|
|
|
preCheck = ''
|
|
|
|
patchShebangs tests/
|
2024-09-26 11:04:55 +00:00
|
|
|
'' + lib.optionalString stdenv.hostPlatform.isDarwin ''
|
2022-05-18 14:49:53 +00:00
|
|
|
# bad interaction with sandbox if enabled?
|
|
|
|
rm tests/data/test1453
|
|
|
|
rm tests/data/test1086
|
|
|
|
'' + lib.optionalString stdenv.hostPlatform.isMusl ''
|
|
|
|
# different resolving behaviour?
|
|
|
|
rm tests/data/test1592
|
|
|
|
'';
|
2020-04-24 23:36:52 +00:00
|
|
|
|
|
|
|
postInstall = ''
|
|
|
|
moveToOutput bin/curl-config "$dev"
|
|
|
|
|
|
|
|
# Install completions
|
|
|
|
make -C scripts install
|
2021-01-15 22:18:51 +00:00
|
|
|
'' + lib.optionalString scpSupport ''
|
2021-12-26 17:43:05 +00:00
|
|
|
sed '/^dependency_libs/s|${lib.getDev libssh2}|${lib.getLib libssh2}|' -i "$out"/lib/*.la
|
2021-01-15 22:18:51 +00:00
|
|
|
'' + lib.optionalString gnutlsSupport ''
|
2022-06-16 17:23:12 +00:00
|
|
|
ln $out/lib/libcurl${stdenv.hostPlatform.extensions.sharedLibrary} $out/lib/libcurl-gnutls${stdenv.hostPlatform.extensions.sharedLibrary}
|
|
|
|
ln $out/lib/libcurl${stdenv.hostPlatform.extensions.sharedLibrary} $out/lib/libcurl-gnutls${stdenv.hostPlatform.extensions.sharedLibrary}.4
|
|
|
|
ln $out/lib/libcurl${stdenv.hostPlatform.extensions.sharedLibrary} $out/lib/libcurl-gnutls${stdenv.hostPlatform.extensions.sharedLibrary}.4.4.0
|
2020-04-24 23:36:52 +00:00
|
|
|
'';
|
|
|
|
|
2022-08-12 12:06:08 +00:00
|
|
|
passthru = let
|
|
|
|
useThisCurl = attr: attr.override { curl = finalAttrs.finalPackage; };
|
|
|
|
in {
|
2021-12-06 16:07:01 +00:00
|
|
|
inherit opensslSupport openssl;
|
2022-05-18 14:49:53 +00:00
|
|
|
tests = {
|
2022-08-12 12:06:08 +00:00
|
|
|
withCheck = finalAttrs.finalPackage.overrideAttrs (_: { doCheck = true; });
|
|
|
|
curlpp = useThisCurl curlpp;
|
|
|
|
coeurl = useThisCurl coeurl;
|
|
|
|
haskell-curl = useThisCurl haskellPackages.curl;
|
|
|
|
ocaml-curly = useThisCurl ocamlPackages.curly;
|
|
|
|
pycurl = useThisCurl python3.pkgs.pycurl;
|
|
|
|
php-curl = useThisCurl phpExtensions.curl;
|
|
|
|
# error: attribute 'override' missing
|
2022-06-16 17:23:12 +00:00
|
|
|
# Additional checking with support http3 protocol.
|
2022-08-12 12:06:08 +00:00
|
|
|
# nginx-http3 = useThisCurl nixosTests.nginx-http3;
|
|
|
|
nginx-http3 = nixosTests.nginx-http3;
|
2023-02-16 17:41:37 +00:00
|
|
|
pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage;
|
2024-04-21 15:54:59 +00:00
|
|
|
} // lib.optionalAttrs (stdenv.hostPlatform.system != "x86_64-darwin") {
|
2024-02-29 20:09:43 +00:00
|
|
|
static = pkgsStatic.curl;
|
2024-09-26 11:04:55 +00:00
|
|
|
} // lib.optionalAttrs (!stdenv.hostPlatform.isDarwin) {
|
2024-02-29 20:09:43 +00:00
|
|
|
fetchpatch = tests.fetchpatch.simple.override { fetchpatch = (fetchpatch.override { fetchurl = useThisCurl fetchurl; }) // { version = 1; }; };
|
2022-05-18 14:49:53 +00:00
|
|
|
};
|
2020-04-24 23:36:52 +00:00
|
|
|
};
|
|
|
|
|
2024-09-19 14:19:46 +00:00
|
|
|
meta = {
|
|
|
|
changelog = "https://curl.se/ch/${finalAttrs.version}.html";
|
2024-06-20 14:57:18 +00:00
|
|
|
description = "Command line tool for transferring files with URL syntax";
|
2021-12-26 17:43:05 +00:00
|
|
|
homepage = "https://curl.se/";
|
2024-09-19 14:19:46 +00:00
|
|
|
license = lib.licenses.curl;
|
|
|
|
maintainers = with lib.maintainers; [ lovek323 ];
|
|
|
|
platforms = lib.platforms.all;
|
2021-09-18 10:52:07 +00:00
|
|
|
# Fails to link against static brotli or gss
|
2024-09-19 14:19:46 +00:00
|
|
|
broken = stdenv.hostPlatform.isStatic && (brotliSupport || gssSupport || stdenv.hostPlatform.system == "x86_64-darwin");
|
2023-02-16 17:41:37 +00:00
|
|
|
pkgConfigModules = [ "libcurl" ];
|
2023-08-10 07:59:29 +00:00
|
|
|
mainProgram = "curl";
|
2020-04-24 23:36:52 +00:00
|
|
|
};
|
2022-08-12 12:06:08 +00:00
|
|
|
})
|