Skip to content
Snippets Groups Projects
  1. Mar 23, 2005
  2. Mar 21, 2005
  3. Mar 18, 2005
  4. Mar 17, 2005
  5. Mar 16, 2005
  6. Mar 15, 2005
  7. Mar 14, 2005
  8. Mar 11, 2005
  9. Mar 10, 2005
  10. Mar 07, 2005
    • Eelco Dolstra's avatar
      * In the checker, do traversals of the dependency graph explicitly. A · 97c93526
      Eelco Dolstra authored
        conditional expression in the blacklist can specify when to
        continue/stop a traversal.  For example, in
      
          <condition>
            <within>
              <traverse>
                <not><hasAttr name='outputHash' value='.+' /></not>
              </traverse>
              <hasAttr name='outputHash' value='ef1cb003448b4a53517b8f25adb12452' />
            </within>
          </condition>
      
        we traverse the dependency graph, not following the dependencies of
        `fetchurl' derivations (as indicated by the presence of an
        `outputHash' attribute - this is a bit ugly).  The resulting set of
        paths is scanned for a fetch of a file with the given hash, in this
        case, the hash of zlib-1.2.1.tar.gz (which has a security bug).  The
        intent is that a dependency on zlib is not a problem if it is in a
        `fetchurl' derivation, since that's build-time only.  (Other
        build-time uses of zlib *might* be a problem, e.g., static linking.)
      97c93526
    • Eelco Dolstra's avatar
      * Use XML::LibXML. · bfbc55cb
      Eelco Dolstra authored
      bfbc55cb
    • Eelco Dolstra's avatar
      * Automatically add propagated build inputs to user environments. · 543d7a41
      Eelco Dolstra authored
        Maybe this is a bad idea.
      543d7a41
  11. Mar 04, 2005
  12. Mar 03, 2005
  13. Mar 02, 2005
  14. Mar 01, 2005
Loading