{ stdenv, fetchurl, pkgconfig, utillinux, hexdump, which , knot-dns, luajit, libuv, lmdb , cmocka, systemd, hiredis, libmemcached , gnutls, nettle , luajitPackages, makeWrapper }: let inherit (stdenv.lib) optional; in stdenv.mkDerivation rec { name = "knot-resolver-${version}"; version = "1.2.2"; src = fetchurl { url = "http://secure.nic.cz/files/knot-resolver/${name}.tar.xz"; sha256 = "89ab2ac8058b297c1f73f1c12e0f16d6e160aa86363e99ffa590bee7fe307931"; }; outputs = [ "out" "dev" ]; configurePhase = ":"; nativeBuildInputs = [ pkgconfig which makeWrapper hexdump ]; buildInputs = [ knot-dns lmdb luajit libuv gnutls ] ## optional dependencies ++ optional doInstallCheck cmocka ++ optional stdenv.isLinux systemd # socket activation ++ [ nettle # DNS cookies hiredis libmemcached # additional cache backends # http://knot-resolver.readthedocs.io/en/latest/build.html#requirements ]; makeFlags = [ "PREFIX=$(out)" ]; CFLAGS = [ "-O2" "-DNDEBUG" ]; enableParallelBuilding = true; doInstallCheck = true; installCheckTarget = "check"; preInstallCheck = '' export LD_LIBRARY_PATH="$out/lib" ''; # optional: to allow auto-bootstrapping root trust anchor via https postInstall = with luajitPackages; '' wrapProgram "$out/sbin/kresd" \ --set LUA_PATH '${ stdenv.lib.concatStringsSep ";" (map getLuaPath [ luasec luasocket ]) }' \ --set LUA_CPATH '${ stdenv.lib.concatStringsSep ";" (map getLuaCPath [ luasec luasocket ]) }' ''; meta = with stdenv.lib; { description = "Caching validating DNS resolver, from .cz domain registry"; homepage = https://knot-resolver.cz; license = licenses.gpl3Plus; platforms = platforms.unix; maintainers = [ maintainers.vcunat /* upstream developer */ ]; }; }