Files
nxdns/flake.nix
T
mokhtar 6e9a36903e
Gates / frontend (push) Successful in 1m52s
Gates / test (push) Successful in 2m22s
Gates / test-aarch64 (push) Successful in 8m10s
Gates / package (push) Successful in 4m22s
Gates / container (push) Successful in 10s
CI / gates (push) Successful in 28m22s
Release / guard (push) Successful in 35s
Gates / frontend (push) Successful in 1m53s
Gates / test (push) Successful in 2m20s
Gates / test-aarch64 (push) Successful in 7m26s
Gates / package (push) Successful in 51s
Gates / container (push) Successful in 11s
Release / gates (push) Successful in 10m52s
Release / publish (push) Successful in 4m56s
build: bump version to 0.0.20
2026-09-12 15:10:09 +02:00

115 lines
3.8 KiB
Nix

{
description = "nxdns: DNS sinkhole with per-client policy groups";
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
outputs =
{ nixpkgs, ... }:
let
# `zig build cut` rewrites the lines between the delimiters by text replacement.
# BEGIN GENERATED BY zig build cut
version = "0.0.20";
hashes = {
"aarch64-linux" = "sha256-2p86FImDgi4SDDzmV6w0qkrkp9dtDRyi/ZMOZ8WAEm4=";
"x86_64-linux" = "sha256-rnTpjo7J9uY+pINxJ4ZgwbqU7E2o7N0gr9z7VRhQiZ0=";
};
# END GENERATED BY zig build cut
triples = {
"aarch64-linux" = "aarch64-linux-musl";
"x86_64-linux" = "x86_64-linux-musl";
};
systems = builtins.attrNames hashes;
package =
system:
let
pkgs = nixpkgs.legacyPackages.${system};
lib = pkgs.lib;
triple = triples.${system};
in
pkgs.stdenv.mkDerivation {
pname = "nxdns";
inherit version;
src = pkgs.fetchurl {
url = "https://git.mial.net/mokhtar/nxdns/releases/download/v${version}/nxdns-${version}-${triple}.tar.gz";
hash = hashes.${system};
};
# Static musl binary: the install check asserts that no interpreter was patched in.
dontPatchELF = true;
dontStrip = true;
installPhase = ''
runHook preInstall
install -Dm755 nxdns $out/bin/nxdns
install -Dm644 LICENSE $out/share/doc/nxdns/LICENSE
install -Dm644 THIRD-PARTY-NOTICES $out/share/doc/nxdns/THIRD-PARTY-NOTICES
runHook postInstall
'';
doInstallCheck = true;
# GNU readelf prints `INTERP`, not `PT_INTERP`; `${READELF:?}` keeps an unset variable from turning the grep into a pass.
installCheckPhase = ''
runHook preInstallCheck
# Captured first: piping readelf straight into grep hides its exit
# status, so a readelf that failed to read the file at all would
# print nothing, match nothing, and pass as "static".
if ! segments="$(''${READELF:?} -l "$out/bin/nxdns")"; then
echo "readelf -l failed on $out/bin/nxdns" >&2
exit 1
fi
if printf '%s' "$segments" | grep -q INTERP; then
echo "nxdns has an INTERP segment: it is dynamically linked, not static" >&2
exit 1
fi
if ! dynamic="$(''${READELF:?} -d "$out/bin/nxdns")"; then
echo "readelf -d failed on $out/bin/nxdns" >&2
exit 1
fi
if printf '%s' "$dynamic" | grep -q NEEDED; then
echo "nxdns has DT_NEEDED entries: it links against shared libraries" >&2
exit 1
fi
if ! reported="$($out/bin/nxdns version)"; then
echo "nxdns version exited non-zero: the binary does not run here" >&2
exit 1
fi
# Prefix match: releases before 0.0.17 print a commit sha after the version.
case "$reported" in
"nxdns ${version}"*) echo "nxdns version reports: $reported" ;;
*)
echo "nxdns version reports '$reported'; expected it to start with 'nxdns ${version}'" >&2
exit 1
;;
esac
runHook postInstallCheck
'';
meta = {
description = "DNS sinkhole with per-client policy groups";
homepage = "https://git.mial.net/mokhtar/nxdns";
license = lib.licenses.eupl12;
mainProgram = "nxdns";
platforms = systems;
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
};
};
in
{
packages = nixpkgs.lib.genAttrs systems (system: {
default = package system;
});
};
}