mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Expose the fips daemon as a managed NixOS service so flake consumers
can enable it with a single line instead of hand-rolling a systemd unit.
Flake outputs (system-independent, outside eachDefaultSystem):
- overlays.default — adds pkgs.fips
- nixosModules.default — packaging/nixos/ module providing services.fips.*
Module options (services.fips):
- enable (bool, default false) — main mesh daemon
- package (package, default pkgs.fips via overlay)
- configFile (path, default /share/fips/fips.yaml) — seed source
- openFirewall (bool, default true) — UDP 2121 + TCP 8443
- dns.enable (bool, default true) — route .fips to [::1]:5354 via
systemd-resolved (declarative,
no setup/teardown scripts)
- gateway.enable(bool, default false) — outbound LAN gateway service
Hybrid config pattern: fips.yaml + identity keys live in /var/lib/fips/
(writable, seeded on first run only); hosts/ACL files stay at /etc/fips/
because fips hardcodes those paths on Linux. Launched with --config so
fips never loads /etc/fips/fips.yaml by accident.
flake.nix: ship fips.yaml, hosts, and fips.nft via postInstall so the
module can reference them from /share/fips/ without the source tree.
Also fix deprecated stdenv.isLinux -> stdenv.hostPlatform.isLinux and
platforms.linux ++ darwin -> platforms.unix.
packaging/README.md: document the overlay + module and show a full
flake.nix consumer example.
147 lines
5.2 KiB
Nix
147 lines
5.2 KiB
Nix
{
|
|
description = "FIPS — a distributed, decentralized network routing protocol for mesh nodes connecting over arbitrary transports";
|
|
|
|
inputs = {
|
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
|
|
flake-utils.url = "github:numtide/flake-utils";
|
|
fenix = {
|
|
url = "github:nix-community/fenix";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
};
|
|
|
|
outputs =
|
|
{
|
|
self,
|
|
nixpkgs,
|
|
flake-utils,
|
|
fenix,
|
|
}:
|
|
flake-utils.lib.eachDefaultSystem (
|
|
system:
|
|
let
|
|
pkgs = import nixpkgs { inherit system; };
|
|
|
|
# Honor the toolchain the repo pins in rust-toolchain.toml
|
|
# (channel 1.94.1 + rustfmt, clippy) so Nix builds match CI and the
|
|
# AUR/Debian packaging exactly, including the edition-2024 frontend.
|
|
rustToolchain = fenix.packages.${system}.fromToolchainFile {
|
|
file = ./rust-toolchain.toml;
|
|
sha256 = "sha256-zC8E38iDVJ1oPIzCqTk/Ujo9+9kx9dXq7wAwPMpkpg0=";
|
|
};
|
|
|
|
rustPlatform = pkgs.makeRustPlatform {
|
|
cargo = rustToolchain;
|
|
rustc = rustToolchain;
|
|
};
|
|
|
|
cargoToml = pkgs.lib.importTOML ./Cargo.toml;
|
|
|
|
# libdbus-sys (pulled in transitively by `bluer`, Linux/glibc only)
|
|
# runs `bindgen` against the system D-Bus headers at build time.
|
|
nativeBuildInputs = [
|
|
pkgs.pkg-config
|
|
rustPlatform.bindgenHook # sets LIBCLANG_PATH + clang for bindgen
|
|
];
|
|
|
|
buildInputs = pkgs.lib.optionals pkgs.stdenv.hostPlatform.isLinux [
|
|
pkgs.dbus # libdbus-1.so.3, linked via bluer→libdbus-sys
|
|
pkgs.stdenv.cc.cc.lib # libgcc_s.so.1, needed by every Rust binary
|
|
];
|
|
|
|
fips = rustPlatform.buildRustPackage {
|
|
pname = "fips";
|
|
version = cargoToml.package.version;
|
|
|
|
src = pkgs.lib.cleanSourceWith {
|
|
src = ./.;
|
|
# Drop the build dir and the usual editor/VCS noise so the source
|
|
# hash is stable and unrelated edits don't trigger rebuilds.
|
|
filter = path: type: (pkgs.lib.cleanSourceFilter path type) && (baseNameOf path != "target");
|
|
};
|
|
|
|
cargoLock.lockFile = ./Cargo.lock;
|
|
|
|
inherit buildInputs;
|
|
|
|
# Ship the default config, hosts file, and nftables baseline so
|
|
# the NixOS module can reference them via $out/share/fips/ without
|
|
# needing the source tree. DNS routing is handled declaratively
|
|
# via services.resolved on NixOS (no setup/teardown scripts needed).
|
|
postInstall = ''
|
|
install -Dm 0644 ${./packaging/common/fips.yaml} $out/share/fips/fips.yaml
|
|
install -Dm 0644 ${./packaging/common/hosts} $out/share/fips/hosts
|
|
install -Dm 0644 ${./packaging/common/fips.nft} $out/share/fips/fips.nft
|
|
'';
|
|
|
|
# autoPatchelfHook rewrites the RPATH of the built binaries so the
|
|
# daemon finds libdbus-1.so.3 (linked via bluer→libdbus-sys) in the
|
|
# Nix store at runtime — without it the `fips` binary fails to load
|
|
# on NixOS where there is no global /usr/lib.
|
|
nativeBuildInputs =
|
|
nativeBuildInputs ++ pkgs.lib.optionals pkgs.stdenv.hostPlatform.isLinux [ pkgs.autoPatchelfHook ];
|
|
|
|
# The test suite exercises TUN devices, raw sockets and mDNS, none of
|
|
# which exist in the build sandbox. The AUR/Debian packaging likewise
|
|
# ships the release binaries without running the integration tests
|
|
# here, so keep the package build hermetic and skip them.
|
|
doCheck = false;
|
|
|
|
meta = {
|
|
description = cargoToml.package.description;
|
|
homepage = cargoToml.package.homepage;
|
|
license = pkgs.lib.licenses.mit;
|
|
mainProgram = "fips";
|
|
platforms = pkgs.lib.platforms.unix;
|
|
};
|
|
};
|
|
|
|
mkApp = name: {
|
|
type = "app";
|
|
program = "${fips}/bin/${name}";
|
|
meta.description = "Run the ${name} binary from the FIPS package";
|
|
};
|
|
in
|
|
{
|
|
packages = {
|
|
default = fips;
|
|
fips = fips;
|
|
};
|
|
|
|
apps = {
|
|
default = mkApp "fips";
|
|
fips = mkApp "fips";
|
|
fipsctl = mkApp "fipsctl";
|
|
fips-gateway = mkApp "fips-gateway";
|
|
fipstop = mkApp "fipstop";
|
|
};
|
|
|
|
# `nix flake check` builds the package (and thus validates the flake on
|
|
# the current system).
|
|
checks.fips = fips;
|
|
|
|
devShells.default = pkgs.mkShell {
|
|
inherit buildInputs;
|
|
nativeBuildInputs = nativeBuildInputs ++ [
|
|
rustToolchain
|
|
pkgs.cargo-edit
|
|
];
|
|
# Point rust-analyzer at the matching std sources.
|
|
RUST_SRC_PATH = "${rustToolchain}/lib/rustlib/src/rust/library";
|
|
};
|
|
|
|
formatter = pkgs.nixfmt;
|
|
}
|
|
)
|
|
// {
|
|
# System-independent outputs — outside eachDefaultSystem.
|
|
# Overlay so consumers get pkgs.fips automatically.
|
|
overlays.default = final: prev: {
|
|
fips = self.packages.${final.system}.default;
|
|
};
|
|
|
|
# NixOS module — consumers import this and set services.fips.enable = true.
|
|
nixosModules.default = import ./packaging/nixos;
|
|
};
|
|
}
|