diff --git a/pkgs/by-name/ap/apparmor-init/fix-rc-apparmor-functions-FHS.patch b/pkgs/by-name/ap/apparmor-init/fix-rc-apparmor-functions-FHS.patch new file mode 100644 index 000000000000..0e43f12bcecb --- /dev/null +++ b/pkgs/by-name/ap/apparmor-init/fix-rc-apparmor-functions-FHS.patch @@ -0,0 +1,34 @@ +diff --git a/rc.apparmor.functions b/rc.apparmor.functions +index 96cb23d33..4401fc420 100644 +--- a/rc.apparmor.functions ++++ b/rc.apparmor.functions +@@ -31,7 +31,10 @@ + + # Some nice defines that we use + +-PARSER=/sbin/apparmor_parser ++PATH="@PATH@${PATH:+:$PATH}" ++export PATH ++ ++PARSER=$(command -v apparmor_parser) + PARSER_OPTS= + # Suppress warnings when booting in quiet mode + if [ "${QUIET:-no}" = yes ] || [ "${quiet:-n}" = y ]; then +@@ -50,7 +53,7 @@ ADDITIONAL_PROFILE_DIR= + if [ -n "$ADDITIONAL_PROFILE_DIR" ] && [ -d "$ADDITIONAL_PROFILE_DIR" ]; then + PROFILE_DIRS="$PROFILE_DIRS $ADDITIONAL_PROFILE_DIR" + fi +-AA_STATUS=/usr/sbin/aa-status ++AA_STATUS=$(command -v aa-status) + SECURITYFS=/sys/kernel/security + SFS_MOUNTPOINT="${SECURITYFS}/apparmor" + +@@ -91,7 +94,7 @@ is_container_with_internal_policy() { + local ns_name + + # WSL needs to be detected explicitly +- if [ -x /usr/bin/systemd-detect-virt ] && \ ++ if command -v systemd-detect-virt >/dev/null 2>&1 && \ + [ "$(systemd-detect-virt --container)" = "wsl" ]; then + return 0 + fi diff --git a/pkgs/by-name/ap/apparmor-init/package.nix b/pkgs/by-name/ap/apparmor-init/package.nix new file mode 100644 index 000000000000..0e95a3f13b47 --- /dev/null +++ b/pkgs/by-name/ap/apparmor-init/package.nix @@ -0,0 +1,94 @@ +{ + lib, + stdenv, + which, + replaceVars, + perl, + buildPackages, + runtimeShellPackage, + + # apparmor deps + libapparmor, + apparmor-bin-utils, + apparmor-parser, + + # runtime deps + gnused, + gnugrep, + systemd, + coreutils, +}: +stdenv.mkDerivation (finalAttrs: { + pname = "apparmor-init"; + inherit (libapparmor) version src; + + sourceRoot = "${finalAttrs.src.name}/init"; + + patches = [ + (replaceVars ./fix-rc-apparmor-functions-FHS.patch { + PATH = lib.makeBinPath [ + # bash script needs a bunch of binaries, but we can't wrapProgram because it is more a library that will be used with `source` + apparmor-bin-utils + apparmor-parser + coreutils + gnused + gnugrep + systemd + ]; + }) + ]; + + postPatch = '' + patchShebangs . + + substituteInPlace apparmor.service \ + --replace-fail "/bin/true" "${lib.getExe' coreutils "true"}" + + # the various provided scripts hardcode /lib/apparmor + for FILE in aa-teardown apparmor.service apparmor.systemd profile-load + do + substituteInPlace "$FILE" \ + --replace-fail "/lib/apparmor" "$out/lib/apparmor" + done + ''; + + nativeBuildInputs = [ + which + perl + ]; + + buildInputs = [ + runtimeShellPackage + ]; + + makeFlags = [ + "POD2MAN=${lib.getExe' buildPackages.perl "pod2man"}" + "POD2HTML=${lib.getExe' buildPackages.perl "pod2html"}" + "MANDIR=share/man" + ]; + + installFlags = [ + "DESTDIR=${placeholder "out"}" + "DISTRO=unknown" + "USR_SBINDIR=${placeholder "out"}/bin" + "SBINDIR=${placeholder "out"}/bin" + "LOCALEDIR=${placeholder "out"}/share/locale" + "SYSTEMD_UNIT_DIR=${placeholder "out"}/lib/systemd/system" + ]; + + doCheck = true; + + installTargets = [ + "install" + # Likely not very useful for NixOS, as this is missing some NixOS awareness such as loading declarative profiles from the store + # However, the cost is low, it may be useful in the future or on non-NixOS systems, so install the systemd service too. + "install-systemd" + ]; + + strictDeps = true; + __structuredAttrs = true; + + meta = libapparmor.meta // { + description = "Mandatory access control system - init files"; + }; +})