From 1a87ac2d826b1e5e9d10ef6a8383e2273d8fbc4b Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Wed, 29 Jul 2026 22:39:40 +0530 Subject: feat(chromium): use ouch, drop python dep, add assertion; add private configs - Replace unzip with ouch from file-management.ouch.package - Replace python3-based CRX header parsing with pure shell (od) - Add assertion that file-management.ouch is enabled when chromium is - Thread config through to extension lib - Add bookmark_bar.show_on_all_tabs = false to chromium prefs - Add private modules: cloudflare-warp wireguard, email, git config --- modules/web/chromium/default.nix | 6 ++- modules/web/chromium/extensions/assertions.nix | 12 +++++ modules/web/chromium/extensions/default.nix | 10 ++++- modules/web/chromium/extensions/lib.nix | 62 +++++++++++++++----------- 4 files changed, 62 insertions(+), 28 deletions(-) create mode 100644 modules/web/chromium/extensions/assertions.nix diff --git a/modules/web/chromium/default.nix b/modules/web/chromium/default.nix index 626647c..f6508e9 100644 --- a/modules/web/chromium/default.nix +++ b/modules/web/chromium/default.nix @@ -7,6 +7,7 @@ { imports = [ ./browserpass.nix + ./extensions/assertions.nix ]; options.web.chromium = { @@ -31,7 +32,7 @@ config = lib.mkIf config.web.chromium.enable ( let exts = import ./extensions { - inherit lib pkgs; + inherit lib pkgs config; checkForUpdates = config.web.chromium.checkForUpdates; }; @@ -73,6 +74,9 @@ NewTabPage = { FooterVisible = false; }; + bookmark_bar = { + show_on_all_tabs = false; + }; browser = { show_full_urls = true; theme = { diff --git a/modules/web/chromium/extensions/assertions.nix b/modules/web/chromium/extensions/assertions.nix new file mode 100644 index 0000000..52a0081 --- /dev/null +++ b/modules/web/chromium/extensions/assertions.nix @@ -0,0 +1,12 @@ +{ config, ... }: +{ + assertions = [ + { + assertion = !config.web.chromium.enable || config.file-management.ouch.enable; + message = '' + web.chromium.enable is true but file-management.ouch.enable is not. + chromium extension fetching requires ouch to decompress extension archives. Please enable file-management.ouch. + ''; + } + ]; +} diff --git a/modules/web/chromium/extensions/default.nix b/modules/web/chromium/extensions/default.nix index 9b78f73..70dd96c 100644 --- a/modules/web/chromium/extensions/default.nix +++ b/modules/web/chromium/extensions/default.nix @@ -1,10 +1,18 @@ { lib, pkgs, + config, checkForUpdates ? true, }: let - extLib = import ./lib.nix { inherit lib pkgs checkForUpdates; }; + extLib = import ./lib.nix { + inherit + lib + pkgs + config + checkForUpdates + ; + }; mkExtension = path: import path { inherit lib pkgs extLib; }; in { diff --git a/modules/web/chromium/extensions/lib.nix b/modules/web/chromium/extensions/lib.nix index f5e83a1..c7aefe3 100644 --- a/modules/web/chromium/extensions/lib.nix +++ b/modules/web/chromium/extensions/lib.nix @@ -1,6 +1,7 @@ { lib, pkgs, + config, checkForUpdates ? true, }: rec { @@ -10,7 +11,6 @@ rec { fetchLatestGithubReleaseTag = { owner, repo }: let - token = builtins.getEnv "GITHUB_TOKEN"; raw = builtins.fetchurl { url = "https://api.github.com/repos/${owner}/${repo}/releases/latest"; name = "${repo}-latest-release.json"; @@ -77,38 +77,48 @@ rec { pkgs.stdenv.mkDerivation { inherit pname version; src = pkgs.fetchurl { inherit url hash; }; + nativeBuildInputs = [ - pkgs.unzip - pkgs.python3 + config.file-management.ouch.package ]; dontUnpack = true; buildPhase = '' - runHook preBuild - mkdir -p $out + runHook preBuild + mkdir -p $out + + if [ "${lib.boolToString isCrx}" = "true" ]; then + # Verify "Cr24" magic header + magic=$(head -c 4 "$src") + if [ "$magic" != "Cr24" ]; then + echo "Error: $src is not a valid CRX file" >&2 + exit 1 + fi + + # Extract header length (bytes 8-11, little-endian) + # -An (no address), -j8 (skip 8 bytes), -N4 (read 4 bytes), -tu1 (unsigned decimal 1-byte) + bytes=$(od -An -j8 -N4 -tu1 "$src") + + # Read into individual variables and calculate the length + read b1 b2 b3 b4 <<< $bytes + hlen=$(( b1 + (b2 << 8) + (b3 << 16) + (b4 << 24) )) + offset=$(( 12 + hlen )) + + dd if=$src of=payload.zip bs=1 skip=$offset status=none + ouch decompress payload.zip --dir $out + else + ouch decompress $src --dir $out + fi - if [ "${lib.boolToString isCrx}" = "true" ]; then - offset=$(python3 -c " - import struct - with open('$src', 'rb') as f: - magic, ver, hlen = struct.unpack('<4sII', f.read(12)) - assert magic == b'Cr24', 'not a CRX file' - print(12 + hlen) - ") - dd if=$src of=payload.zip bs=1 skip=$offset status=none - unzip -q payload.zip -d $out - else - unzip -q $src -d $out - fi + # Flatten a single wrapping folder (common in GitHub release zips) + if [ "$(ls -1 $out | wc -l)" -eq 1 ] && [ -d "$out"/* ]; then + shopt -s dotglob + mv "$out"/*/* "$out"/ 2>/dev/null || true + rmdir "$out"/*/ 2>/dev/null || true + shopt -u dotglob + fi - # Flatten a single wrapping folder (common in GitHub release zips) - if [ "$(ls -1 $out | wc -l)" -eq 1 ] && [ -d "$out"/* ]; then - shopt -s dotglob - mv "$out"/*/* "$out"/ 2>/dev/null || true - rmdir "$out"/*/ 2>/dev/null || true - shopt -u dotglob - fi - runHook postBuild + runHook postBuild ''; installPhase = "true"; -- cgit v1.2.3