2021-01-11 07:54:33 +00:00
|
|
|
|
{ lib, stdenv, nixosTests, fetchpatch, fetchFromGitHub, autoreconfHook, libxslt
|
2020-03-11 20:51:10 +00:00
|
|
|
|
, libxml2 , docbook_xml_dtd_45, docbook_xsl, itstool, flex, bison, runtimeShell
|
2017-06-28 20:42:27 +00:00
|
|
|
|
, pam ? null, glibcCross ? null
|
|
|
|
|
}:
|
2011-11-19 18:28:16 +00:00
|
|
|
|
|
|
|
|
|
let
|
2012-07-25 21:30:01 +00:00
|
|
|
|
|
|
|
|
|
glibc =
|
2018-08-20 18:43:41 +00:00
|
|
|
|
if stdenv.hostPlatform != stdenv.buildPlatform
|
2012-07-25 21:30:01 +00:00
|
|
|
|
then glibcCross
|
2018-08-20 18:43:41 +00:00
|
|
|
|
else assert stdenv.hostPlatform.libc == "glibc"; stdenv.cc.libc;
|
2012-07-25 21:30:01 +00:00
|
|
|
|
|
2017-05-08 13:07:50 +00:00
|
|
|
|
dots_in_usernames = fetchpatch {
|
2022-02-02 06:48:42 +00:00
|
|
|
|
url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/sys-apps/shadow/files/shadow-4.1.3-dots-in-usernames.patch";
|
2012-09-18 21:56:51 +00:00
|
|
|
|
sha256 = "1fj3rg6x3jppm5jvi9y7fhd2djbi4nc5pgwisw00xlh4qapgz692";
|
|
|
|
|
};
|
|
|
|
|
|
2011-11-19 18:28:16 +00:00
|
|
|
|
in
|
2012-07-25 21:30:01 +00:00
|
|
|
|
|
2010-06-02 16:45:14 +00:00
|
|
|
|
stdenv.mkDerivation rec {
|
2019-08-15 12:41:18 +00:00
|
|
|
|
pname = "shadow";
|
2022-03-07 23:58:05 +00:00
|
|
|
|
version = "4.11.1";
|
2011-11-19 18:28:16 +00:00
|
|
|
|
|
2017-02-03 12:07:38 +00:00
|
|
|
|
src = fetchFromGitHub {
|
|
|
|
|
owner = "shadow-maint";
|
|
|
|
|
repo = "shadow";
|
2022-03-07 23:58:05 +00:00
|
|
|
|
rev = "v${version}";
|
|
|
|
|
sha256 = "sha256-PxLX5V0t18JftT5wT41krNv18Ew7Kz3MfZkOi/80ODA=";
|
2004-08-30 11:44:51 +00:00
|
|
|
|
};
|
2006-11-28 15:45:41 +00:00
|
|
|
|
|
2021-01-15 14:45:37 +00:00
|
|
|
|
buildInputs = lib.optional (pam != null && stdenv.isLinux) pam;
|
2017-05-08 13:07:50 +00:00
|
|
|
|
nativeBuildInputs = [autoreconfHook libxslt libxml2
|
2019-10-29 11:59:46 +00:00
|
|
|
|
docbook_xml_dtd_45 docbook_xsl flex bison itstool
|
2017-02-03 12:07:38 +00:00
|
|
|
|
];
|
2010-06-04 11:32:42 +00:00
|
|
|
|
|
2017-05-08 13:07:50 +00:00
|
|
|
|
patches =
|
|
|
|
|
[ ./keep-path.patch
|
2017-10-15 23:33:02 +00:00
|
|
|
|
# Obtain XML resources from XML catalog (patch adapted from gtk-doc)
|
|
|
|
|
./respect-xml-catalog-files-var.patch
|
2017-05-08 13:07:50 +00:00
|
|
|
|
dots_in_usernames
|
2020-03-11 20:51:10 +00:00
|
|
|
|
./runtime-shell.patch
|
2017-05-08 13:07:50 +00:00
|
|
|
|
];
|
2010-07-14 12:10:26 +00:00
|
|
|
|
|
2020-03-11 20:51:10 +00:00
|
|
|
|
RUNTIME_SHELL = runtimeShell;
|
|
|
|
|
|
2017-06-07 12:21:04 +00:00
|
|
|
|
# The nix daemon often forbids even creating set[ug]id files.
|
|
|
|
|
postPatch =
|
|
|
|
|
''sed 's/^\(s[ug]idperms\) = [0-9]755/\1 = 0755/' -i src/Makefile.am
|
|
|
|
|
'';
|
|
|
|
|
|
2016-09-05 12:46:41 +00:00
|
|
|
|
outputs = [ "out" "su" "man" ];
|
2014-04-05 18:41:23 +00:00
|
|
|
|
|
2017-05-08 13:07:50 +00:00
|
|
|
|
enableParallelBuilding = true;
|
|
|
|
|
|
2011-11-19 18:28:16 +00:00
|
|
|
|
# Assume System V `setpgrp (void)', which is the default on GNU variants
|
|
|
|
|
# (`AC_FUNC_SETPGRP' is not cross-compilation capable.)
|
2014-05-09 11:48:27 +00:00
|
|
|
|
preConfigure = ''
|
|
|
|
|
export ac_cv_func_setpgrp_void=yes
|
|
|
|
|
export shadow_cv_logdir=/var/log
|
|
|
|
|
'';
|
2011-11-19 18:28:16 +00:00
|
|
|
|
|
Increase max group name length to 32 characters
With #36556, a check was introduced to make sure the user and group
names do not exceed their respective maximum length. This is in part
because systemd also enforces that length, but only at runtime.
So in general it's a good idea to catch as much as we can during
evaluation time, however the maximum length of the group name was set to
16 characters according groupadd(8).
The maximum length of the group names however is a compile-time option
and even systemd allows more than 16 characters. In the mentioned pull
request (#36556) there was already a report that this has broken
evaluation for people out there.
I have also checked what other distributions are doing and they set the
length to either 31 characters or 32 characters, the latter being more
common.
Unfortunately there is a difference between the maximum length enforced
by the shadow package and systemd, both for user name lengths and group
name lengths. However, systemd enforces both length to have a maximum of
31 characters and I'm not sure if this is intended or just a off-by-one
error in systemd.
Nevertheless, I choose 32 characters simply to bring it in par with the
maximum user name length.
For the NixOS assertion however, I use a maximum length of 31 to make
sure that nobody accidentally creates services that contain group names
that systemd considers invalid because of a length of 32 characters.
Signed-off-by: aszlig <aszlig@nix.build>
Closes: #38548
Cc: @vcunat, @fpletz, @qknight
2018-04-07 13:14:47 +00:00
|
|
|
|
configureFlags = [
|
|
|
|
|
"--enable-man"
|
|
|
|
|
"--with-group-name-max-length=32"
|
2021-01-15 14:45:37 +00:00
|
|
|
|
] ++ lib.optional (stdenv.hostPlatform.libc != "glibc") "--disable-nscd";
|
2017-02-03 12:07:38 +00:00
|
|
|
|
|
2021-01-15 14:45:37 +00:00
|
|
|
|
preBuild = lib.optionalString (stdenv.hostPlatform.libc == "glibc")
|
2010-07-14 12:10:26 +00:00
|
|
|
|
''
|
2015-04-26 17:54:51 +00:00
|
|
|
|
substituteInPlace lib/nscd.c --replace /usr/sbin/nscd ${glibc.bin}/bin/nscd
|
2010-07-14 12:10:26 +00:00
|
|
|
|
'';
|
2011-11-19 18:28:16 +00:00
|
|
|
|
|
2012-07-25 21:36:34 +00:00
|
|
|
|
postInstall =
|
|
|
|
|
''
|
2014-04-05 18:41:23 +00:00
|
|
|
|
# Don't install ‘groups’, since coreutils already provides it.
|
2016-11-29 23:44:28 +00:00
|
|
|
|
rm $out/bin/groups
|
|
|
|
|
rm $man/share/man/man1/groups.*
|
2014-04-05 18:41:23 +00:00
|
|
|
|
|
|
|
|
|
# Move the su binary into the su package
|
|
|
|
|
mkdir -p $su/bin
|
|
|
|
|
mv $out/bin/su $su/bin
|
2012-07-25 21:36:34 +00:00
|
|
|
|
'';
|
|
|
|
|
|
2020-03-11 20:51:10 +00:00
|
|
|
|
disallowedReferences = lib.optional (stdenv.buildPlatform != stdenv.hostPlatform) stdenv.shellPackage;
|
|
|
|
|
|
2021-01-11 07:54:33 +00:00
|
|
|
|
meta = with lib; {
|
2020-04-01 01:11:51 +00:00
|
|
|
|
homepage = "https://github.com/shadow-maint";
|
2010-06-02 16:45:14 +00:00
|
|
|
|
description = "Suite containing authentication-related tools such as passwd and su";
|
2018-08-17 22:28:13 +00:00
|
|
|
|
license = licenses.bsd3;
|
|
|
|
|
platforms = platforms.linux;
|
2016-07-04 14:06:13 +00:00
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
passthru = {
|
|
|
|
|
shellPath = "/bin/nologin";
|
2020-12-23 18:28:30 +00:00
|
|
|
|
tests = { inherit (nixosTests) shadow; };
|
2010-06-02 16:45:14 +00:00
|
|
|
|
};
|
2004-08-30 11:44:51 +00:00
|
|
|
|
}
|