2017-01-24 13:49:14 +00:00
|
|
|
{ stdenv, fetchurl, fetchpatch, nspr, perl, zlib, sqlite }:
|
2005-08-24 09:54:42 +00:00
|
|
|
|
2009-07-06 11:42:21 +00:00
|
|
|
let
|
|
|
|
|
2013-08-07 14:17:58 +00:00
|
|
|
nssPEM = fetchurl {
|
2014-02-06 20:15:43 +00:00
|
|
|
url = http://dev.gentoo.org/~polynomial-c/mozilla/nss-3.15.4-pem-support-20140109.patch.xz;
|
|
|
|
sha256 = "10ibz6y0hknac15zr6dw4gv9nb5r5z9ym6gq18j3xqx7v7n3vpdw";
|
2012-08-21 04:10:33 +00:00
|
|
|
};
|
|
|
|
|
2012-08-22 00:46:48 +00:00
|
|
|
in stdenv.mkDerivation rec {
|
2012-08-20 03:41:58 +00:00
|
|
|
name = "nss-${version}";
|
2017-01-24 13:49:14 +00:00
|
|
|
version = "3.28.1";
|
2012-10-31 13:04:58 +00:00
|
|
|
|
|
|
|
src = fetchurl {
|
2017-01-24 13:49:14 +00:00
|
|
|
url = "mirror://mozilla/security/nss/releases/NSS_3_28_1_RTM/src/${name}.tar.gz";
|
|
|
|
sha256 = "58cc0c05c0ed9523e6d820bea74f513538f48c87aac931876e3d3775de1a82ad";
|
2005-08-24 09:54:42 +00:00
|
|
|
};
|
|
|
|
|
2012-08-20 07:39:55 +00:00
|
|
|
buildInputs = [ nspr perl zlib sqlite ];
|
2009-07-06 09:12:44 +00:00
|
|
|
|
2013-08-07 14:17:58 +00:00
|
|
|
prePatch = ''
|
|
|
|
xz -d < ${nssPEM} | patch -p1
|
2012-08-21 04:10:33 +00:00
|
|
|
'';
|
|
|
|
|
2013-08-07 14:17:58 +00:00
|
|
|
patches =
|
2017-01-24 13:49:14 +00:00
|
|
|
[ # FIXME: what is this patch for? Do we still need it?
|
2017-01-24 14:43:53 +00:00
|
|
|
(fetchurl {
|
2017-01-24 13:49:14 +00:00
|
|
|
url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/dev-libs/nss/files/nss-3.28-gentoo-fixups.patch";
|
|
|
|
sha256 = "0z58axd1n7vq4kdp5mrb3dsg6di39a1g40s3shl6n2dzs14c1y2q";
|
|
|
|
})
|
2014-04-22 12:54:36 +00:00
|
|
|
# Based on http://patch-tracker.debian.org/patch/series/dl/nss/2:3.15.4-1/85_security_load.patch
|
2014-01-22 09:46:29 +00:00
|
|
|
./85_security_load.patch
|
2013-08-07 14:17:58 +00:00
|
|
|
];
|
2011-01-03 17:02:58 +00:00
|
|
|
|
2017-01-24 13:49:14 +00:00
|
|
|
patchFlags = "-p0";
|
|
|
|
|
2011-01-03 17:02:58 +00:00
|
|
|
postPatch = ''
|
2013-08-07 14:17:58 +00:00
|
|
|
# Fix up the patch from Gentoo.
|
2013-03-01 08:18:14 +00:00
|
|
|
sed -i \
|
|
|
|
-e "/^PREFIX =/s|= /usr|= $out|" \
|
|
|
|
-e '/@libdir@/s|gentoo/nss|lib|' \
|
|
|
|
-e '/ln -sf/d' \
|
2013-08-07 14:17:58 +00:00
|
|
|
nss/config/Makefile
|
2013-03-01 08:18:14 +00:00
|
|
|
|
|
|
|
# Note for spacing/tab nazis: The TAB characters are intentional!
|
2013-08-07 14:17:58 +00:00
|
|
|
cat >> nss/config/Makefile <<INSTALL_TARGET
|
2013-03-01 08:18:14 +00:00
|
|
|
install:
|
|
|
|
mkdir -p \$(DIST)/lib/pkgconfig
|
|
|
|
cp nss.pc \$(DIST)/lib/pkgconfig
|
|
|
|
INSTALL_TARGET
|
2011-01-03 17:02:58 +00:00
|
|
|
'';
|
|
|
|
|
2016-08-29 00:30:01 +00:00
|
|
|
outputs = [ "out" "dev" "tools" ];
|
2015-10-05 15:45:54 +00:00
|
|
|
|
2013-08-07 14:17:58 +00:00
|
|
|
preConfigure = "cd nss";
|
2009-07-06 09:12:44 +00:00
|
|
|
|
nss: Clean up build/make flags.
First of all, let's remove that redundant BUILD_OPT variable.
This variable already is in makeFlags, so we really don't want it to be lurking
around in the attribute set of the derivation, and it annoys me for being there
for days.
We now state build targets explicitly rather than relying on "nss_build_all".
This makes NSPR_CONFIG_STATUS and the touch of build_nspr stamp obsolete, as
only nss_build_all includes build_nspr.
In addition, we don't need the -lz hack anymore, as this has been fixed in
recent NSS versions, so we can completly remove the postBuild hook.
And while we're at it, we're removing those outdated build instructions as well,
especially because we don't and can't follow official building guidelines
anymore, as those are difficult to apply to Nix.
2012-08-21 08:47:29 +00:00
|
|
|
makeFlags = [
|
2015-10-05 15:45:54 +00:00
|
|
|
"NSPR_INCLUDE_DIR=${nspr.dev}/include/nspr"
|
|
|
|
"NSPR_LIB_DIR=${nspr.out}/lib"
|
nss: Clean up build/make flags.
First of all, let's remove that redundant BUILD_OPT variable.
This variable already is in makeFlags, so we really don't want it to be lurking
around in the attribute set of the derivation, and it annoys me for being there
for days.
We now state build targets explicitly rather than relying on "nss_build_all".
This makes NSPR_CONFIG_STATUS and the touch of build_nspr stamp obsolete, as
only nss_build_all includes build_nspr.
In addition, we don't need the -lz hack anymore, as this has been fixed in
recent NSS versions, so we can completly remove the postBuild hook.
And while we're at it, we're removing those outdated build instructions as well,
especially because we don't and can't follow official building guidelines
anymore, as those are difficult to apply to Nix.
2012-08-21 08:47:29 +00:00
|
|
|
"NSDISTMODE=copy"
|
|
|
|
"BUILD_OPT=1"
|
|
|
|
"SOURCE_PREFIX=\$(out)"
|
|
|
|
"NSS_ENABLE_ECC=1"
|
2015-10-05 15:45:54 +00:00
|
|
|
"USE_SYSTEM_ZLIB=1"
|
nss: Clean up build/make flags.
First of all, let's remove that redundant BUILD_OPT variable.
This variable already is in makeFlags, so we really don't want it to be lurking
around in the attribute set of the derivation, and it annoys me for being there
for days.
We now state build targets explicitly rather than relying on "nss_build_all".
This makes NSPR_CONFIG_STATUS and the touch of build_nspr stamp obsolete, as
only nss_build_all includes build_nspr.
In addition, we don't need the -lz hack anymore, as this has been fixed in
recent NSS versions, so we can completly remove the postBuild hook.
And while we're at it, we're removing those outdated build instructions as well,
especially because we don't and can't follow official building guidelines
anymore, as those are difficult to apply to Nix.
2012-08-21 08:47:29 +00:00
|
|
|
"NSS_USE_SYSTEM_SQLITE=1"
|
|
|
|
] ++ stdenv.lib.optional stdenv.is64bit "USE_64=1";
|
|
|
|
|
2015-12-16 15:18:42 +00:00
|
|
|
NIX_CFLAGS_COMPILE = "-Wno-error";
|
|
|
|
|
2012-08-22 02:22:43 +00:00
|
|
|
postInstall = ''
|
|
|
|
rm -rf $out/private
|
|
|
|
mv $out/public $out/include
|
|
|
|
mv $out/*.OBJ/* $out/
|
|
|
|
rmdir $out/*.OBJ
|
2012-03-06 20:57:39 +00:00
|
|
|
|
2012-08-22 02:22:43 +00:00
|
|
|
cp -av config/nss-config $out/bin/nss-config
|
2013-08-07 14:17:58 +00:00
|
|
|
|
|
|
|
ln -s lib $out/lib64
|
2012-08-22 02:22:43 +00:00
|
|
|
'';
|
2012-08-21 19:35:46 +00:00
|
|
|
|
|
|
|
postFixup = ''
|
|
|
|
for libname in freebl3 nssdbm3 softokn3
|
|
|
|
do
|
|
|
|
libfile="$out/lib/lib$libname.so"
|
|
|
|
LD_LIBRARY_PATH=$out/lib $out/bin/shlibsign -v -i "$libfile"
|
|
|
|
done
|
2015-10-05 15:45:54 +00:00
|
|
|
|
2015-12-02 09:03:23 +00:00
|
|
|
moveToOutput bin "$tools"
|
|
|
|
moveToOutput bin/nss-config "$dev"
|
|
|
|
moveToOutput lib/libcrmf.a "$dev" # needed by firefox, for example
|
2015-10-05 15:45:54 +00:00
|
|
|
rm "$out"/lib/*.a
|
2012-08-21 19:35:46 +00:00
|
|
|
'';
|
2013-08-07 14:17:58 +00:00
|
|
|
|
2015-06-01 18:55:53 +00:00
|
|
|
meta = {
|
2013-08-07 14:17:58 +00:00
|
|
|
homepage = https://developer.mozilla.org/en-US/docs/NSS;
|
|
|
|
description = "A set of libraries for development of security-enabled client and server applications";
|
2015-09-18 20:41:47 +00:00
|
|
|
platforms = stdenv.lib.platforms.all;
|
2013-08-07 14:17:58 +00:00
|
|
|
};
|
2005-08-24 09:54:42 +00:00
|
|
|
}
|