-
Notifications
You must be signed in to change notification settings - Fork 7
Expand file tree
/
Copy pathflake.nix
More file actions
100 lines (92 loc) · 2.38 KB
/
Copy pathflake.nix
File metadata and controls
100 lines (92 loc) · 2.38 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
{
description = "Sandboxed environments with bwrap and nix-shell";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
flake-utils.url = "github:numtide/flake-utils";
};
outputs =
{ self, nixpkgs, flake-utils }:
let
nixCageModule = import ./nix/module.nix {
lib = nixpkgs.lib;
};
mkNixCageConfiguration =
{ modules ? [ ] }:
let
evaluated = nixpkgs.lib.evalModules {
modules = [
nixCageModule
] ++ modules;
};
in
evaluated
// {
config = evaluated.config.renderedConfig;
moduleConfig = builtins.removeAttrs evaluated.config [ "renderedConfig" ];
};
mkSandboxedDevShell =
{
system,
modules ? [ ],
pkgs ? nixpkgs.legacyPackages.${system},
packages ? [ ],
shellHook ? "",
}:
let
configuration = mkNixCageConfiguration {
modules = modules ++ [
{
launcher = nixpkgs.lib.mkForce "direct";
}
];
};
configFile = pkgs.writeText "nix-cage.json" (builtins.toJSON configuration.config);
in
pkgs.mkShell {
packages = with pkgs; [
bashInteractive
] ++ packages;
shellHook = ''
if [ -z "''${NIX_CAGE_ACTIVE:-}" ]; then
export NIX_CAGE_ACTIVE=1
exec ${self.packages.${system}.default}/bin/nix-cage --config ${configFile} --launcher direct
fi
${shellHook}
'';
};
in
{
lib = {
inherit nixCageModule mkNixCageConfiguration mkSandboxedDevShell;
};
}
// flake-utils.lib.eachDefaultSystem (
system:
let
pkgs = nixpkgs.legacyPackages.${system};
nix-cage = pkgs.callPackage ./nix/package.nix {
src = self;
};
in
{
packages = {
default = nix-cage;
};
nixosTests = import ./nix/vm/tests.nix {
inherit nixpkgs system self;
};
devShells = {
default = pkgs.mkShell {
packages = with pkgs; [
bashInteractive
bubblewrap
gnumake
jq
nix
python3
];
};
};
}
);
}