openscap: discover built-in plugins (like SCE)

openscap calls dlopen() to discover plugins.
It prefixes the path that is dlopened with
OSCAP_CHECK_ENGINE_PLUGIN_DIR. By setting
that env-var we can make openscap discover
the built-in plugins that it ships with by
default. (Currently only SCE).
This commit is contained in:
Arian van Putten
2025-11-15 13:02:50 +01:00
parent 5d66a00427
commit 7f556b60b6
+9
View File
@@ -26,6 +26,7 @@
valgrind,
asciidoc,
installShellFiles,
makeWrapper,
rpm,
system-sendmail,
gnome2,
@@ -55,6 +56,7 @@ stdenv.mkDerivation rec {
cmake
asciidoc
doxygen
makeWrapper
rpm
swig
util-linux
@@ -143,6 +145,13 @@ stdenv.mkDerivation rec {
rm -rf $out/share/man8
'';
postFixup = ''
# Set plugin directory to discover the SCE plugin.
# openscap calls dlopen with this as the directory prefix.
wrapProgram $out/bin/oscap \
--set OSCAP_CHECK_ENGINE_PLUGIN_DIR $out/lib
'';
meta = {
description = "NIST Certified SCAP 1.2 toolkit";
homepage = "https://github.com/OpenSCAP/openscap";