Gates / frontend (push) Successful in 1m52s
Gates / test (push) Successful in 2m22s
Gates / test-aarch64 (push) Successful in 8m10s
Gates / package (push) Successful in 4m22s
Gates / container (push) Successful in 10s
CI / gates (push) Successful in 28m22s
Release / guard (push) Successful in 35s
Gates / frontend (push) Successful in 1m53s
Gates / test (push) Successful in 2m20s
Gates / test-aarch64 (push) Successful in 7m26s
Gates / package (push) Successful in 51s
Gates / container (push) Successful in 11s
Release / gates (push) Successful in 10m52s
Release / publish (push) Successful in 4m56s
115 lines
3.8 KiB
Nix
115 lines
3.8 KiB
Nix
{
|
|
description = "nxdns: DNS sinkhole with per-client policy groups";
|
|
|
|
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
|
|
|
|
outputs =
|
|
{ nixpkgs, ... }:
|
|
let
|
|
# `zig build cut` rewrites the lines between the delimiters by text replacement.
|
|
# BEGIN GENERATED BY zig build cut
|
|
version = "0.0.20";
|
|
hashes = {
|
|
"aarch64-linux" = "sha256-2p86FImDgi4SDDzmV6w0qkrkp9dtDRyi/ZMOZ8WAEm4=";
|
|
"x86_64-linux" = "sha256-rnTpjo7J9uY+pINxJ4ZgwbqU7E2o7N0gr9z7VRhQiZ0=";
|
|
};
|
|
# END GENERATED BY zig build cut
|
|
|
|
triples = {
|
|
"aarch64-linux" = "aarch64-linux-musl";
|
|
"x86_64-linux" = "x86_64-linux-musl";
|
|
};
|
|
|
|
systems = builtins.attrNames hashes;
|
|
|
|
package =
|
|
system:
|
|
let
|
|
pkgs = nixpkgs.legacyPackages.${system};
|
|
lib = pkgs.lib;
|
|
triple = triples.${system};
|
|
in
|
|
pkgs.stdenv.mkDerivation {
|
|
pname = "nxdns";
|
|
inherit version;
|
|
|
|
src = pkgs.fetchurl {
|
|
url = "https://git.mial.net/mokhtar/nxdns/releases/download/v${version}/nxdns-${version}-${triple}.tar.gz";
|
|
hash = hashes.${system};
|
|
};
|
|
|
|
# Static musl binary: the install check asserts that no interpreter was patched in.
|
|
dontPatchELF = true;
|
|
dontStrip = true;
|
|
|
|
installPhase = ''
|
|
runHook preInstall
|
|
|
|
install -Dm755 nxdns $out/bin/nxdns
|
|
install -Dm644 LICENSE $out/share/doc/nxdns/LICENSE
|
|
install -Dm644 THIRD-PARTY-NOTICES $out/share/doc/nxdns/THIRD-PARTY-NOTICES
|
|
|
|
runHook postInstall
|
|
'';
|
|
|
|
doInstallCheck = true;
|
|
|
|
# GNU readelf prints `INTERP`, not `PT_INTERP`; `${READELF:?}` keeps an unset variable from turning the grep into a pass.
|
|
installCheckPhase = ''
|
|
runHook preInstallCheck
|
|
|
|
# Captured first: piping readelf straight into grep hides its exit
|
|
# status, so a readelf that failed to read the file at all would
|
|
# print nothing, match nothing, and pass as "static".
|
|
if ! segments="$(''${READELF:?} -l "$out/bin/nxdns")"; then
|
|
echo "readelf -l failed on $out/bin/nxdns" >&2
|
|
exit 1
|
|
fi
|
|
if printf '%s' "$segments" | grep -q INTERP; then
|
|
echo "nxdns has an INTERP segment: it is dynamically linked, not static" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if ! dynamic="$(''${READELF:?} -d "$out/bin/nxdns")"; then
|
|
echo "readelf -d failed on $out/bin/nxdns" >&2
|
|
exit 1
|
|
fi
|
|
if printf '%s' "$dynamic" | grep -q NEEDED; then
|
|
echo "nxdns has DT_NEEDED entries: it links against shared libraries" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if ! reported="$($out/bin/nxdns version)"; then
|
|
echo "nxdns version exited non-zero: the binary does not run here" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Prefix match: releases before 0.0.17 print a commit sha after the version.
|
|
case "$reported" in
|
|
"nxdns ${version}"*) echo "nxdns version reports: $reported" ;;
|
|
*)
|
|
echo "nxdns version reports '$reported'; expected it to start with 'nxdns ${version}'" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
|
|
runHook postInstallCheck
|
|
'';
|
|
|
|
meta = {
|
|
description = "DNS sinkhole with per-client policy groups";
|
|
homepage = "https://git.mial.net/mokhtar/nxdns";
|
|
license = lib.licenses.eupl12;
|
|
mainProgram = "nxdns";
|
|
platforms = systems;
|
|
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
|
|
};
|
|
};
|
|
in
|
|
{
|
|
packages = nixpkgs.lib.genAttrs systems (system: {
|
|
default = package system;
|
|
});
|
|
};
|
|
}
|