From 486749fd7851f503a22dd7a3dd5c0d9eecbb32e0 Mon Sep 17 00:00:00 2001 From: Raito Bezarius Date: Fri, 22 Sep 2023 18:13:03 +0200 Subject: [PATCH] pesign: init at 116 https://github.com/rhboot/pesign Linux tooling for signing PE-COFF binaries --- pkgs/by-name/pe/pesign/package.nix | 52 ++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 pkgs/by-name/pe/pesign/package.nix diff --git a/pkgs/by-name/pe/pesign/package.nix b/pkgs/by-name/pe/pesign/package.nix new file mode 100644 index 000000000000..b39db9cd430b --- /dev/null +++ b/pkgs/by-name/pe/pesign/package.nix @@ -0,0 +1,52 @@ +{ lib +, stdenv +, fetchFromGitHub +, pkg-config +, nss +, efivar +, util-linux +, popt +, nspr +, mandoc +}: + +stdenv.mkDerivation rec { + pname = "pesign"; + version = "116"; + + src = fetchFromGitHub { + owner = "rhboot"; + repo = "pesign"; + rev = version; + hash = "sha256-cuOSD/ZHkilgguDFJviIZCG8kceRWw2JgssQuWN02Do="; + }; + + # nss-util is missing because it is already contained in nss + # Red Hat seems to be shipping a separate nss-util: + # https://centos.pkgs.org/7/centos-x86_64/nss-util-devel-3.44.0-4.el7_7.x86_64.rpm.html + # containing things we already have in `nss`. + # We can ignore all the errors pertaining to a missing + # nss-util.pc I suppose. + buildInputs = [ efivar util-linux nss popt nspr mandoc ]; + nativeBuildInputs = [ pkg-config ]; + + makeFlags = [ "INSTALLROOT=$(out)" ]; + + postInstall = '' + mv $out/usr/bin $out/bin + mv $out/usr/share $out/share + + rm -rf $out/usr + rm -rf $out/etc + rm -rf $out/run + ''; + + meta = with lib; { + description = "Signing tools for PE-COFF binaries. Compliant with the PE and Authenticode specifications."; + homepage = "https://github.com/rhboot/pesign"; + license = licenses.gpl2Only; + maintainers = with maintainers; [ raitobezarius ]; + # efivar is currently Linux-only. + platforms = platforms.linux; + }; +}