2021-01-11 07:54:33 +00:00
|
|
|
{ lib, stdenv
|
2016-01-05 15:00:02 +00:00
|
|
|
, fetchFromGitHub
|
|
|
|
, libseccomp
|
|
|
|
, perl
|
|
|
|
, which
|
|
|
|
}:
|
|
|
|
|
2019-08-13 22:52:01 +01:00
|
|
|
stdenv.mkDerivation {
|
2019-08-15 13:41:18 +01:00
|
|
|
pname = "syscall_limiter";
|
2018-08-09 20:44:00 +01:00
|
|
|
version = "2017-01-23";
|
2016-01-05 15:00:02 +00:00
|
|
|
|
|
|
|
src = fetchFromGitHub {
|
2017-02-18 10:39:01 +00:00
|
|
|
owner = "vi";
|
|
|
|
repo = "syscall_limiter";
|
|
|
|
rev = "481c8c883f2e1260ebc83b352b63bf61a930a341";
|
|
|
|
sha256 = "0z5arj1kq1xczgrbw1b8m9kicbv3vs9bd32wvgfr4r6ndingsp5m";
|
2016-01-05 15:00:02 +00:00
|
|
|
};
|
|
|
|
|
2018-08-09 20:44:00 +01:00
|
|
|
buildInputs = [ libseccomp ];
|
2016-01-05 15:00:02 +00:00
|
|
|
|
|
|
|
installPhase = ''
|
|
|
|
mkdir -p $out/bin
|
|
|
|
cp -v limit_syscalls $out/bin
|
|
|
|
cp -v monitor.sh $out/bin/limit_syscalls_monitor.sh
|
|
|
|
substituteInPlace $out/bin/limit_syscalls_monitor.sh \
|
|
|
|
--replace perl ${perl}/bin/perl \
|
|
|
|
--replace which ${which}/bin/which
|
|
|
|
'';
|
|
|
|
|
2021-01-11 07:54:33 +00:00
|
|
|
meta = with lib; {
|
2016-01-05 15:00:02 +00:00
|
|
|
description = "Start Linux programs with only selected syscalls enabled";
|
2020-04-01 02:11:51 +01:00
|
|
|
homepage = "https://github.com/vi/syscall_limiter";
|
2017-02-18 10:39:01 +00:00
|
|
|
license = licenses.mit;
|
2016-01-05 15:00:02 +00:00
|
|
|
maintainers = with maintainers; [ obadz ];
|
2017-02-18 10:39:01 +00:00
|
|
|
platforms = platforms.linux;
|
2016-01-05 15:00:02 +00:00
|
|
|
};
|
|
|
|
}
|