diff --git a/pkgs/build-support/fetchgitlab/default.nix b/pkgs/build-support/fetchgitlab/default.nix index 822c3991fa29..8a2b0ffa31d6 100644 --- a/pkgs/build-support/fetchgitlab/default.nix +++ b/pkgs/build-support/fetchgitlab/default.nix @@ -21,6 +21,8 @@ lib.makeOverridable ( deepClone ? false, forceFetchGit ? false, sparseCheckout ? [ ], + private ? false, + varPrefix ? null, ... # For hash agility }@args: @@ -51,14 +53,57 @@ lib.makeOverridable ( "tag" "fetchSubmodules" "forceFetchGit" + "private" + "varPrefix" "leaveDotGit" "deepClone" ]; + varBase = "NIX${lib.optionalString (varPrefix != null) "_${varPrefix}"}_GITLAB_PRIVATE_"; useFetchGit = fetchSubmodules || leaveDotGit || deepClone || forceFetchGit || (sparseCheckout != [ ]); fetcher = if useFetchGit then fetchgit else fetchzip; + privateAttrs = lib.optionalAttrs private ( + lib.throwIfNot (protocol == "https") "private token login is only supported for https" { + netrcPhase = '' + if [ -z "''$${varBase}USERNAME" -o -z "''$${varBase}PASSWORD" ]; then + echo "Error: Private fetchFromGitLab requires the nix building process (nix-daemon in multi user mode) to have the ${varBase}USERNAME and ${varBase}PASSWORD env vars set." >&2 + exit 1 + fi + '' + + ( + if useFetchGit then + # GitLab supports HTTP Basic Authentication only when Git is used: + # https://docs.gitlab.com/ee/user/project/settings/project_access_tokens.html#project-access-tokens + '' + cat > netrc < private-token <