Files
2026-03-21 22:33:14 +00:00

72 lines
1.4 KiB
Nix

{
lib,
stdenv,
fetchFromGitHub,
autoconf,
bison,
flex,
libtool,
pkg-config,
which,
libnl,
protobuf,
protobufc,
shadow,
installShellFiles,
}:
stdenv.mkDerivation rec {
pname = "nsjail";
version = "3.6";
src = fetchFromGitHub {
owner = "google";
repo = "nsjail";
rev = version;
fetchSubmodules = true;
hash = "sha256-4fFXPwfPErve5CkVBtjPd1In8eEDby/RhuyW952YW7Y=";
};
nativeBuildInputs = [
autoconf
bison
flex
installShellFiles
libtool
pkg-config
which
];
buildInputs = [
libnl
protobuf
protobufc
];
enableParallelBuilding = true;
env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error" ];
preBuild = ''
makeFlagsArray+=(USER_DEFINES='-DNEWUIDMAP_PATH=${shadow}/bin/newuidmap -DNEWGIDMAP_PATH=${shadow}/bin/newgidmap')
'';
installPhase = ''
runHook preInstall
install -Dm755 nsjail "$out/bin/nsjail"
installManPage nsjail.1
runHook postInstall
'';
meta = {
description = "Light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters";
homepage = "https://nsjail.dev/";
changelog = "https://github.com/google/nsjail/releases/tag/${version}";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [
arturcygan
bosu
];
platforms = lib.platforms.linux;
mainProgram = "nsjail";
};
}