Files
nxdns/flake.nix
T
mokhtar f168247b33
Gates / frontend (push) Successful in 2m23s
Gates / test (push) Successful in 3m15s
Gates / test-aarch64 (push) Successful in 8m38s
Gates / package (push) Successful in 5m0s
Gates / container (push) Successful in 19s
CI / gates (push) Successful in 17m17s
Release / guard (push) Successful in 37s
Gates / frontend (push) Successful in 2m15s
Gates / test (push) Successful in 2m34s
Gates / test-aarch64 (push) Successful in 7m33s
Gates / package (push) Successful in 51s
Gates / container (push) Successful in 10s
Release / gates (push) Successful in 11m14s
Release / publish (push) Successful in 8m35s
cut: build the release with the official zig tarball, skip hidden bundle files; re-pin 0.0.17
The first 0.0.17 cut (run 687) failed verify-pins in CI for two reasons. The asset generator embedded admin/dist/.src-hash, a freshness stamp that CI's artifact copy does not carry; it now skips dotfiles. And the Arch zig package emits different code than the ziglang.org tarball that CI installs, so the cut downloads the pinned tarball (ZIG_TARBALL_SHA256 in gates.yml, the full digest keys the cache) and builds the release with it. flake.nix is re-pinned to the bytes both now produce.

The saturated-primary pool test gates its holders on a semaphore instead of sleeps and releases every spawned holder on the way out, so a loaded runner cannot flake it. The package job uploads the payload before the pin check and runs the check when the version or flake.nix changed against the parent. The verify-a-release recipe clones the tag first and builds with the official zig.
2026-09-08 23:57:07 +02:00

115 lines
3.8 KiB
Nix

{
description = "nxdns: DNS sinkhole with per-client policy groups";
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
outputs =
{ nixpkgs, ... }:
let
# `zig build cut` rewrites the lines between the delimiters by text replacement.
# BEGIN GENERATED BY zig build cut
version = "0.0.17";
hashes = {
"aarch64-linux" = "sha256-tDnKVUlosx6NK5qLqUAPvIncJ+C7JZ1dNSa8QiEzPHc=";
"x86_64-linux" = "sha256-juCx8wse5DvLCgyOeJRp+seUUj4xRotUwZnQtXHIq2s=";
};
# END GENERATED BY zig build cut
triples = {
"aarch64-linux" = "aarch64-linux-musl";
"x86_64-linux" = "x86_64-linux-musl";
};
systems = builtins.attrNames hashes;
package =
system:
let
pkgs = nixpkgs.legacyPackages.${system};
lib = pkgs.lib;
triple = triples.${system};
in
pkgs.stdenv.mkDerivation {
pname = "nxdns";
inherit version;
src = pkgs.fetchurl {
url = "https://git.mial.net/mokhtar/nxdns/releases/download/v${version}/nxdns-${version}-${triple}.tar.gz";
hash = hashes.${system};
};
# Static musl binary: the install check asserts that no interpreter was patched in.
dontPatchELF = true;
dontStrip = true;
installPhase = ''
runHook preInstall
install -Dm755 nxdns $out/bin/nxdns
install -Dm644 LICENSE $out/share/doc/nxdns/LICENSE
install -Dm644 THIRD-PARTY-NOTICES $out/share/doc/nxdns/THIRD-PARTY-NOTICES
runHook postInstall
'';
doInstallCheck = true;
# GNU readelf prints `INTERP`, not `PT_INTERP`; `${READELF:?}` keeps an unset variable from turning the grep into a pass.
installCheckPhase = ''
runHook preInstallCheck
# Captured first: piping readelf straight into grep hides its exit
# status, so a readelf that failed to read the file at all would
# print nothing, match nothing, and pass as "static".
if ! segments="$(''${READELF:?} -l "$out/bin/nxdns")"; then
echo "readelf -l failed on $out/bin/nxdns" >&2
exit 1
fi
if printf '%s' "$segments" | grep -q INTERP; then
echo "nxdns has an INTERP segment: it is dynamically linked, not static" >&2
exit 1
fi
if ! dynamic="$(''${READELF:?} -d "$out/bin/nxdns")"; then
echo "readelf -d failed on $out/bin/nxdns" >&2
exit 1
fi
if printf '%s' "$dynamic" | grep -q NEEDED; then
echo "nxdns has DT_NEEDED entries: it links against shared libraries" >&2
exit 1
fi
if ! reported="$($out/bin/nxdns version)"; then
echo "nxdns version exited non-zero: the binary does not run here" >&2
exit 1
fi
# Prefix match: releases before 0.0.17 print a commit sha after the version.
case "$reported" in
"nxdns ${version}"*) echo "nxdns version reports: $reported" ;;
*)
echo "nxdns version reports '$reported'; expected it to start with 'nxdns ${version}'" >&2
exit 1
;;
esac
runHook postInstallCheck
'';
meta = {
description = "DNS sinkhole with per-client policy groups";
homepage = "https://git.mial.net/mokhtar/nxdns";
license = lib.licenses.eupl12;
mainProgram = "nxdns";
platforms = systems;
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
};
};
in
{
packages = nixpkgs.lib.genAttrs systems (system: {
default = package system;
});
};
}