2018-10-10 22:33:43 +01:00
|
|
|
{ stdenv, fetchFromGitHub, autoconf, bison, flex, libtool, pkgconfig, which
|
2018-12-04 21:47:48 +00:00
|
|
|
, libnl, protobuf, protobufc, shadow
|
|
|
|
}:
|
2015-08-10 18:34:09 +01:00
|
|
|
|
|
|
|
stdenv.mkDerivation rec {
|
2017-10-21 23:13:11 +01:00
|
|
|
name = "nsjail-${version}";
|
2018-11-23 23:26:40 +00:00
|
|
|
version = "2.8";
|
2015-08-10 18:34:09 +01:00
|
|
|
|
2017-10-21 23:13:11 +01:00
|
|
|
src = fetchFromGitHub {
|
|
|
|
owner = "google";
|
|
|
|
repo = "nsjail";
|
|
|
|
rev = version;
|
|
|
|
fetchSubmodules = true;
|
2018-11-23 23:26:40 +00:00
|
|
|
sha256 = "0cgycj0cz74plmz4asxryqprg6mkzpmnxzqbfsp1wwackinxq5fq";
|
2015-08-10 18:34:09 +01:00
|
|
|
};
|
|
|
|
|
2018-12-04 21:47:48 +00:00
|
|
|
postPatch = ''
|
|
|
|
substituteInPlace user.cc \
|
|
|
|
--replace "/usr/bin/newgidmap" "${shadow}/bin/newgidmap" \
|
|
|
|
--replace "/usr/bin/newuidmap" "${shadow}/bin/newuidmap"
|
|
|
|
'';
|
|
|
|
|
2018-10-10 22:33:43 +01:00
|
|
|
nativeBuildInputs = [ autoconf bison flex libtool pkgconfig which ];
|
|
|
|
buildInputs = [ libnl protobuf protobufc ];
|
2017-11-04 19:02:23 +00:00
|
|
|
enableParallelBuilding = true;
|
2017-10-21 23:13:11 +01:00
|
|
|
|
2015-08-10 18:34:09 +01:00
|
|
|
installPhase = ''
|
2017-11-04 19:02:23 +00:00
|
|
|
mkdir -p $out/bin $out/share/man/man1
|
|
|
|
install nsjail $out/bin/
|
|
|
|
install nsjail.1 $out/share/man/man1/
|
2015-08-10 18:34:09 +01:00
|
|
|
'';
|
|
|
|
|
2017-10-21 23:13:11 +01:00
|
|
|
meta = with stdenv.lib; {
|
|
|
|
description = "A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters";
|
|
|
|
homepage = http://nsjail.com/;
|
2017-11-04 19:02:23 +00:00
|
|
|
license = licenses.asl20;
|
|
|
|
maintainers = with maintainers; [ bosu c0bw3b ];
|
2017-10-21 23:13:11 +01:00
|
|
|
platforms = platforms.linux;
|
2015-08-10 18:34:09 +01:00
|
|
|
};
|
|
|
|
}
|