hiawatha
11.7Eval errorAdvanced and secure webserver
Planning log · · This campaign
pkgs/by-name/hi/hiawatha/package.nixPackage ‘hiawatha-11.7’ is marked as insecure, refusing to evaluate.
Full diagnostic
GC Warning: Failed to expand heap by 4194304 KiB
error:
… while evaluating attribute 'drv'
at /nix/store/01va76hp6j011dz90bk8jrm120kaq9yq-filnix-experiment-0.7.0/lib/experiment/planner.nix:14:3:
13| {
14| drv = p.drvPath;
| ^
15| name = p.name;
… while evaluating the attribute 'drvPath'
at /nix/store/mydslvfxmzvpagyhv3xba9grd34mq3ji-source/lib/customisation.nix:418:7:
417| // {
418| drvPath =
| ^
419| assert condition;
(stack trace truncated; use '--show-trace' to show the full, detailed trace)
error: Package ‘hiawatha-11.7’ in /nix/store/mydslvfxmzvpagyhv3xba9grd34mq3ji-source/pkgs/by-name/hi/hiawatha/package.nix:73 is marked as insecure, refusing to evaluate.
Known issues:
- CVE-2025-57783: request smuggling
- CVE-2025-57784: local authentication bypass
- CVE-2025-57785: double free, possible arbitrary code execution
You can install it anyway by allowing this package, using the
following methods:
a) To temporarily allow all insecure packages, you can use an environment
variable for a single invocation of the nix tools:
$ export NIXPKGS_ALLOW_INSECURE=1
Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake,
then pass `--impure` in order to allow use of environment variables.
b) for `nixos-rebuild` you can add ‘hiawatha-11.7’ to
`nixpkgs.config.permittedInsecurePackages` in the configuration.nix,
like so:
{
nixpkgs.config.permittedInsecurePackages = [
"hiawatha-11.7"
];
}
c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add
‘hiawatha-11.7’ to `permittedInsecurePackages` in
~/.config/nixpkgs/config.nix, like so:
{
permittedInsecurePackages = [
"hiawatha-11.7"
];
}
Direct dependencies
None recorded.
Selected dependents
None recorded.