nixpkgs/pkgs/tools/system/minijail/default.nix

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

63 lines
1.9 KiB
Nix
Raw Normal View History

{ stdenv, lib, fetchFromGitiles, glibc, libcap, qemu }:
let
dumpConstants =
if stdenv.buildPlatform == stdenv.hostPlatform then "./dump_constants"
else if stdenv.hostPlatform.isAarch32 then "qemu-arm dump_constants"
else if stdenv.hostPlatform.isAarch64 then "qemu-aarch64 dump_constants"
else if stdenv.hostPlatform.isx86_64 then "qemu-x86_64 dump_constants"
else throw "Unsupported host platform";
in
2017-11-24 18:07:36 +00:00
stdenv.mkDerivation rec {
pname = "minijail";
2021-08-17 17:39:06 +00:00
version = "17";
2017-11-24 18:07:36 +00:00
src = fetchFromGitiles {
2017-11-24 18:07:36 +00:00
url = "https://android.googlesource.com/platform/external/minijail";
rev = "linux-v${version}";
2021-08-17 17:39:06 +00:00
sha256 = "1j65h50wa39m6qvgnh1pf59fv9jdsdbc6a6c1na7y0rgljxhmdzv";
2017-11-24 18:07:36 +00:00
};
nativeBuildInputs =
lib.optional (stdenv.buildPlatform != stdenv.hostPlatform) qemu;
2017-11-24 18:07:36 +00:00
buildInputs = [ libcap ];
makeFlags = [ "LIBDIR=$(out)/lib" ];
dumpConstantsFlags = lib.optional (stdenv.hostPlatform.libc == "glibc")
"LDFLAGS=-L${glibc.static}/lib";
2017-11-24 18:07:36 +00:00
postPatch = ''
substituteInPlace common.mk --replace /bin/echo echo
patchShebangs platform2_preinstall.sh
'';
postBuild = ''
make $makeFlags $buildFlags $dumpConstantsFlags dump_constants
${dumpConstants} > constants.json
'';
2017-11-24 18:07:36 +00:00
installPhase = ''
./platform2_preinstall.sh ${version} $out/include/chromeos
mkdir -p $out/lib/pkgconfig $out/include/chromeos $out/bin \
$out/share/minijail
2017-11-24 18:07:36 +00:00
cp -v *.so $out/lib
cp -v *.pc $out/lib/pkgconfig
cp -v libminijail.h scoped_minijail.h $out/include/chromeos
cp -v minijail0 $out/bin
cp -v constants.json $out/share/minijail
2017-11-24 18:07:36 +00:00
'';
enableParallelBuilding = true;
meta = with lib; {
homepage = "https://android.googlesource.com/platform/external/minijail/";
2017-11-24 18:07:36 +00:00
description = "Sandboxing library and application using Linux namespaces and capabilities";
license = licenses.bsd3;
maintainers = with maintainers; [ pcarrier qyliss ];
platforms = platforms.linux;
2017-11-24 18:07:36 +00:00
};
}