xin/pkgs/openssh.nix

173 lines
4.8 KiB
Nix
Raw Permalink Normal View History

2024-03-08 09:59:09 -07:00
{ autoreconfHook
, config
, etcDir ? "/etc/ssh"
, fetchFromGitHub
, hostname
, lib
, libedit
, libfido2
, libredirect
, libressl
, linkOpenssl ? true
, pam
, pkg-config
, stdenv
, withFIDO ? stdenv.hostPlatform.isUnix && !stdenv.hostPlatform.isMusl
, withPAM ? false
2024-03-08 09:59:09 -07:00
, zlib
, xinlib
2024-02-13 07:37:09 -07:00
, ...
2024-03-08 09:59:09 -07:00
}:
let
inherit (builtins) readFile fromJSON;
inherit (xinlib) todo;
2024-03-08 09:59:09 -07:00
verStr = fromJSON (readFile ./openssh/version.json);
hostStr = lib.strings.concatStrings [
"CI configured on '"
2024-03-08 09:59:09 -07:00
config.networking.hostName
"': running OpenSSH tests"
2024-03-08 09:59:09 -07:00
];
in
stdenv.mkDerivation {
2024-03-08 09:59:09 -07:00
pname = "openssh";
inherit (verStr) version;
src = fetchFromGitHub {
inherit (verStr) rev hash;
owner = "openssh";
repo = "openssh-portable";
};
doCheck =
if config.xinCI.enable
then
(lib.warn hostStr true)
else
true;
2023-09-03 19:58:14 -06:00
patches =
[
2024-03-08 09:59:09 -07:00
./openssh/locale_archive.patch
./openssh/ssh-keysign-8.5.patch
2023-09-03 19:58:14 -06:00
# See discussion in https://github.com/NixOS/nixpkgs/pull/16966
2024-03-08 09:59:09 -07:00
./openssh/dont_create_privsep_path.patch
];
postPatch =
# On Hydra this makes installation fail (sometimes?),
# and nix store doesn't allow such fancy permission bits anyway.
''
substituteInPlace Makefile.in --replace '$(INSTALL) -m 4711' '$(INSTALL) -m 0711'
'';
strictDeps = true;
2023-09-03 19:58:14 -06:00
nativeBuildInputs =
2024-03-08 09:59:09 -07:00
[ autoreconfHook pkg-config ];
2023-09-03 19:58:14 -06:00
buildInputs =
2023-09-12 08:44:05 -06:00
[ zlib libressl libedit ]
++ lib.optional withFIDO libfido2
++ lib.optional withPAM pam;
preConfigure = ''
# Setting LD causes `configure' and `make' to disagree about which linker
# to use: `configure' wants `gcc', but `make' wants `ld'.
unset LD
'';
# I set --disable-strip because later we strip anyway. And it fails to strip
# properly when cross building.
2023-09-03 19:58:14 -06:00
configureFlags =
[
"--sbindir=\${out}/bin"
"--localstatedir=/var"
"--with-pid-dir=/run"
"--with-mantype=man"
"--with-libedit=yes"
"--disable-strip"
2024-03-12 11:19:30 -06:00
"--disable-dsa-keys"
2023-09-03 19:58:14 -06:00
(lib.withFeature withPAM "pam")
]
++ lib.optional (etcDir != null) "--sysconfdir=${etcDir}"
++ lib.optional withFIDO "--with-security-key-builtin=yes"
++ lib.optional stdenv.isDarwin "--disable-libutil"
2024-03-08 09:59:09 -07:00
++ lib.optional (!linkOpenssl) "--without-openssl";
2023-09-03 19:58:14 -06:00
${
2024-03-08 09:59:09 -07:00
if stdenv.hostPlatform.isStatic then
"NIX_LDFLAGS"
else
null
} = [ "-laudit" ];
2023-09-12 08:44:05 -06:00
buildFlags = [ "SSH_KEYSIGN=ssh-keysign" ];
enableParallelBuilding = true;
2023-09-12 08:44:05 -06:00
hardeningEnable = [ "pie" ];
enableParallelChecking = false;
2023-09-12 08:44:05 -06:00
nativeCheckInputs = [ libressl ] ++ lib.optional (!stdenv.isDarwin) hostname;
preCheck = lib.optionalString (stdenv.hostPlatform == stdenv.buildPlatform) ''
# construct a dummy HOME
export HOME=$(realpath ../dummy-home)
mkdir -p ~/.ssh
# construct a dummy /etc/passwd file for the sshd under test
# to use to look up the connecting user
DUMMY_PASSWD=$(realpath ../dummy-passwd)
cat > $DUMMY_PASSWD <<EOF
$(whoami)::$(id -u):$(id -g)::$HOME:$SHELL
EOF
# we need to NIX_REDIRECTS /etc/passwd both for processes
# invoked directly and those invoked by the "remote" session
cat > ~/.ssh/environment.base <<EOF
NIX_REDIRECTS=/etc/passwd=$DUMMY_PASSWD
LD_PRELOAD=${libredirect}/lib/libredirect.so
EOF
# use an ssh environment file to ensure environment is set
# up appropriately for build environment even when no shell
# is invoked by the ssh session. otherwise the PATH will
# only contain default unix paths like /bin which we don't
# have in our build environment
cat - regress/test-exec.sh > regress/test-exec.sh.new <<EOF
cp $HOME/.ssh/environment.base $HOME/.ssh/environment
echo "PATH=\$PATH" >> $HOME/.ssh/environment
EOF
mv regress/test-exec.sh.new regress/test-exec.sh
# explicitly enable the PermitUserEnvironment feature
substituteInPlace regress/test-exec.sh \
--replace \
'cat << EOF > $OBJ/sshd_config' \
$'cat << EOF > $OBJ/sshd_config\n\tPermitUserEnvironment yes'
# some tests want to use files under /bin as example files
for f in regress/sftp-cmds.sh regress/forwarding.sh; do
substituteInPlace $f --replace '/bin' "$(dirname $(type -p ls))"
done
# set up NIX_REDIRECTS for direct invocations
set -a; source ~/.ssh/environment.base; set +a
'';
2024-03-08 09:59:09 -07:00
checkTarget = todo "t-exec test disabled in openssh" [ "unit" "file-tests" "interop-tests" ];
2023-09-12 08:44:05 -06:00
installTargets = [ "install-nokeys" ];
installFlags = [
"sysconfdir=\${out}/etc/ssh"
];
2024-03-08 09:59:09 -07:00
meta = with lib; {
description = "An implementation of the SSH protocol";
homepage = "https://www.openssh.com/";
changelog = "https://www.openssh.com/releasenotes.html";
license = licenses.bsd2;
platforms = platforms.unix ++ platforms.windows;
maintainers = with maintainers; [ qbit ];
mainProgram = "ssh";
};
}