opentoonz

1.7.1Eval error

Full-featured 2D animation creation software

Planning log · · This campaign

pkgs/applications/graphics/opentoonz/default.nix
Package ‘libtiff-4.0.3-opentoonz’ is marked as insecure, refusing to evaluate.
Full diagnostic
GC Warning: Failed to expand heap by 4194304 KiB
error:
       … while evaluating attribute 'drv'
         at /nix/store/9jzmw2l7ci5rnc4y8i3lapmwl908r143-filnix-experiment-0.9.0/lib/experiment/planner.nix:14:3:
           13| {
           14|   drv = p.drvPath;
             |   ^
           15|   name = p.name;

       … while evaluating the attribute 'drvPath'
         at /nix/store/zzypf2f2yycd0kwbbw1sqvpy54h90v2h-source/lib/customisation.nix:418:7:
          417|     // {
          418|       drvPath =
             |       ^
          419|         assert condition;

       (stack trace truncated; use '--show-trace' to show the full, detailed trace)

       error: Package ‘libtiff-4.0.3-opentoonz’ in /nix/store/zzypf2f2yycd0kwbbw1sqvpy54h90v2h-source/pkgs/by-name/li/libtiff/package.nix:150 is marked as insecure, refusing to evaluate.


       Known issues:
        - Do not open untrusted files with Opentoonz:
       Opentoonz uses an old custom fork of tibtiff from 2012 that is known to
       be affected by at least these 50 vulnerabilities:
         CVE-2012-4564 CVE-2013-4232 CVE-2013-4243 CVE-2013-4244 CVE-2014-8127
         CVE-2014-8128 CVE-2014-8129 CVE-2014-8130 CVE-2014-9330 CVE-2015-1547
         CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 CVE-2015-8784 CVE-2015-8870
         CVE-2016-3620 CVE-2016-3621 CVE-2016-3623 CVE-2016-3624 CVE-2016-3625
         CVE-2016-3631 CVE-2016-3632 CVE-2016-3633 CVE-2016-3634 CVE-2016-3658
         CVE-2016-3945 CVE-2016-3990 CVE-2016-3991 CVE-2016-5102 CVE-2016-5314
         CVE-2016-5315 CVE-2016-5316 CVE-2016-5318 CVE-2016-5319 CVE-2016-5321
         CVE-2016-5322 CVE-2016-5323 CVE-2016-6223 CVE-2016-9453 CVE-2016-9532
         CVE-2017-9935 CVE-2017-9937 CVE-2018-10963 CVE-2018-5360
         CVE-2019-14973 CVE-2019-17546 CVE-2020-35521 CVE-2020-35522
         CVE-2020-35523 CVE-2020-35524
       More info at https://github.com/opentoonz/opentoonz/issues/4193


       You can install it anyway by allowing this package, using the
       following methods:

       a) To temporarily allow all insecure packages, you can use an environment
          variable for a single invocation of the nix tools:

            $ export NIXPKGS_ALLOW_INSECURE=1

          Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake,
                then pass `--impure` in order to allow use of environment variables.

       b) for `nixos-rebuild` you can add ‘libtiff-4.0.3-opentoonz’ to
          `nixpkgs.config.permittedInsecurePackages` in the configuration.nix,
          like so:

            {
              nixpkgs.config.permittedInsecurePackages = [
                "libtiff-4.0.3-opentoonz"
              ];
            }

       c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add
          ‘libtiff-4.0.3-opentoonz’ to `permittedInsecurePackages` in
          ~/.config/nixpkgs/config.nix, like so:

            {
              permittedInsecurePackages = [
                "libtiff-4.0.3-opentoonz"
              ];
            }

Direct dependencies

None recorded.

Selected dependents

None recorded.