nixpkgs/pkgs/tools/security/ecryptfs/default.nix

60 lines
2.4 KiB
Nix
Raw Normal View History

{ stdenv, fetchurl, pkgconfig, perl, utillinux, keyutils, nss, nspr, python, pam
, intltool, makeWrapper, coreutils, bash, gettext, cryptsetup, lvm2, rsync, which, lsof }:
2014-05-10 07:31:34 +02:00
2015-04-02 01:01:17 +02:00
stdenv.mkDerivation rec {
name = "ecryptfs-${version}";
2016-03-24 13:10:13 +01:00
version = "110";
src = fetchurl {
2015-04-02 01:01:17 +02:00
url = "http://launchpad.net/ecryptfs/trunk/${version}/+download/ecryptfs-utils_${version}.orig.tar.gz";
2016-03-24 13:10:13 +01:00
sha256 = "1x03m9s409fmzjcnsa9f9ghzkpxcnj9irj05rx7jlwm5cach0lqs";
};
2016-03-24 13:10:13 +01:00
# TODO: replace wrapperDir below with from <nixos> config.security.wrapperDir;
wrapperDir = "/var/setuid-wrappers";
2015-04-02 01:01:17 +02:00
postPatch = ''
FILES="$(grep -r '/bin/sh' src/utils -l; find src -name \*.c)"
for file in $FILES; do
substituteInPlace "$file" \
2016-03-24 13:10:13 +01:00
--replace /sbin/mount.ecryptfs_private ${wrapperDir}/mount.ecryptfs_private \
--replace /sbin/umount.ecryptfs_private ${wrapperDir}/umount.ecryptfs_private \
--replace /sbin/mount.ecryptfs $out/sbin/mount.ecryptfs \
--replace /sbin/umount.ecryptfs $out/sbin/umount.ecryptfs \
--replace /usr/bin/ecryptfs-rewrite-file $out/bin/ecryptfs-rewrite-file \
--replace /usr/bin/ecryptfs-mount-private $out/bin/ecryptfs-mount-private \
--replace /usr/bin/ecryptfs-setup-private $out/bin/ecryptfs-setup-private \
--replace /sbin/cryptsetup ${cryptsetup}/sbin/cryptsetup \
--replace /sbin/dmsetup ${lvm2}/sbin/dmsetup \
--replace /bin/mount ${utillinux}/bin/mount \
--replace /bin/umount ${utillinux}/bin/umount \
2016-03-24 13:10:13 +01:00
--replace /sbin/unix_chkpwd ${wrapperDir}/unix_chkpwd \
--replace /bin/bash ${bash}/bin/bash
done
'';
2014-05-10 07:31:34 +02:00
buildInputs = [ pkgconfig perl nss nspr python pam intltool makeWrapper ];
propagatedBuildInputs = [ coreutils gettext cryptsetup lvm2 rsync keyutils which ];
2014-05-10 07:31:34 +02:00
postInstall = ''
FILES="$(grep -r '/bin/sh' $out/bin -l)"
2014-05-10 07:31:34 +02:00
for file in $FILES; do
wrapProgram $file \
--prefix PATH ":" "${coreutils}/bin" \
--prefix PATH ":" "${gettext}/bin" \
--prefix PATH ":" "${rsync}/bin" \
--prefix PATH ":" "${keyutils}/bin" \
--prefix PATH ":" "${which}/bin" \
--prefix PATH ":" "${lsof}/bin" \
2014-05-10 07:31:34 +02:00
--prefix PATH ":" "$out/bin"
done
'';
2014-05-10 07:31:34 +02:00
meta = with stdenv.lib; {
description = "Enterprise-class stacked cryptographic filesystem";
2016-03-24 13:10:13 +01:00
license = licenses.gpl2Plus;
maintainers = [ maintainers.obadz ];
2016-03-24 13:10:13 +01:00
platforms = platforms.linux;
};
}