2017-06-16 04:11:56 +01:00
|
|
|
{ stdenv, fetchurl, openssl, nettle, expat, libevent, dns-root-data }:
|
2010-02-09 07:28:32 +00:00
|
|
|
|
|
|
|
stdenv.mkDerivation rec {
|
2019-08-15 13:41:18 +01:00
|
|
|
pname = "unbound";
|
2019-10-03 14:10:10 +01:00
|
|
|
version = "1.9.4";
|
2010-02-09 07:28:32 +00:00
|
|
|
|
|
|
|
src = fetchurl {
|
2019-08-15 13:41:18 +01:00
|
|
|
url = "https://unbound.net/downloads/${pname}-${version}.tar.gz";
|
2019-10-03 14:10:10 +01:00
|
|
|
sha256 = "1c2bjm13x8bkw0ds1mhn9ivd2gzmfrb0x5y76bkz09a04bxjagix";
|
2010-02-09 07:28:32 +00:00
|
|
|
};
|
2014-12-23 05:49:51 +00:00
|
|
|
|
2019-10-02 19:15:47 +01:00
|
|
|
# https://github.com/NLnetLabs/unbound/pull/90
|
|
|
|
postPatch = ''
|
|
|
|
substituteInPlace validator/val_secalgo.c \
|
|
|
|
--replace '&nettle_secp_256r1' 'nettle_get_secp_256r1()' \
|
|
|
|
--replace '&nettle_secp_384r1' 'nettle_get_secp_384r1()'
|
|
|
|
'';
|
|
|
|
|
2015-10-05 09:53:30 +01:00
|
|
|
outputs = [ "out" "lib" "man" ]; # "dev" would only split ~20 kB
|
|
|
|
|
2017-02-27 16:41:35 +00:00
|
|
|
buildInputs = [ openssl nettle expat libevent ];
|
2015-01-18 00:35:30 +00:00
|
|
|
|
2014-12-23 05:49:51 +00:00
|
|
|
configureFlags = [
|
2015-10-05 14:58:37 +01:00
|
|
|
"--with-ssl=${openssl.dev}"
|
2016-04-16 17:49:30 +01:00
|
|
|
"--with-libexpat=${expat.dev}"
|
2015-10-05 14:58:37 +01:00
|
|
|
"--with-libevent=${libevent.dev}"
|
2014-12-23 05:49:51 +00:00
|
|
|
"--localstatedir=/var"
|
2015-04-21 01:50:39 +01:00
|
|
|
"--sysconfdir=/etc"
|
2016-03-06 12:50:41 +00:00
|
|
|
"--sbindir=\${out}/bin"
|
2017-06-16 04:11:56 +01:00
|
|
|
"--with-rootkey-file=${dns-root-data}/root.key"
|
2016-02-15 03:27:49 +00:00
|
|
|
"--enable-pie"
|
|
|
|
"--enable-relro-now"
|
2014-12-23 05:49:51 +00:00
|
|
|
];
|
2010-02-09 07:28:32 +00:00
|
|
|
|
2015-04-21 01:50:39 +01:00
|
|
|
installFlags = [ "configfile=\${out}/etc/unbound/unbound.conf" ];
|
|
|
|
|
2018-01-13 19:06:23 +00:00
|
|
|
preFixup = stdenv.lib.optionalString (stdenv.isLinux && !stdenv.hostPlatform.isMusl) # XXX: revisit
|
2017-02-27 16:41:35 +00:00
|
|
|
# Build libunbound again, but only against nettle instead of openssl.
|
|
|
|
# This avoids gnutls.out -> unbound.lib -> openssl.out.
|
2017-02-28 21:30:09 +00:00
|
|
|
# There was some problem with this on Darwin; let's not complicate non-Linux.
|
2017-02-27 16:41:35 +00:00
|
|
|
''
|
|
|
|
configureFlags="$configureFlags --with-nettle=${nettle.dev} --with-libunbound-only"
|
|
|
|
configurePhase
|
|
|
|
buildPhase
|
|
|
|
installPhase
|
|
|
|
''
|
|
|
|
# get rid of runtime dependencies on $dev outputs
|
|
|
|
+ ''substituteInPlace "$lib/lib/libunbound.la" ''
|
2015-10-15 12:57:38 +01:00
|
|
|
+ stdenv.lib.concatMapStrings
|
2018-06-09 17:56:53 +01:00
|
|
|
(pkg: " --replace '-L${pkg.dev}/lib' '-L${pkg.out}/lib' --replace '-R${pkg.dev}/lib' '-R${pkg.out}/lib'")
|
2017-02-27 16:41:35 +00:00
|
|
|
buildInputs;
|
2015-10-05 09:53:30 +01:00
|
|
|
|
|
|
|
meta = with stdenv.lib; {
|
2013-10-06 10:49:53 +01:00
|
|
|
description = "Validating, recursive, and caching DNS resolver";
|
2015-10-05 09:53:30 +01:00
|
|
|
license = licenses.bsd3;
|
2016-10-22 19:16:20 +01:00
|
|
|
homepage = https://www.unbound.net;
|
2019-08-20 18:36:05 +01:00
|
|
|
maintainers = with maintainers; [ ehmry fpletz globin ];
|
2014-04-20 16:16:36 +01:00
|
|
|
platforms = stdenv.lib.platforms.unix;
|
2010-02-09 07:28:32 +00:00
|
|
|
};
|
|
|
|
}
|