Add support for restricted downloads
svn path=/nixpkgs/trunk/; revision=21467
This commit is contained in:
@@ -1,4 +1,4 @@
|
|||||||
{stdenv, curl}: # Note that `curl' may be `null', in case of the native stdenv.
|
{stdenv, curl, writeScript}: # Note that `curl' may be `null', in case of the native stdenv.
|
||||||
|
|
||||||
let
|
let
|
||||||
|
|
||||||
@@ -23,7 +23,7 @@ let
|
|||||||
else [] /* backwards compatibility */;
|
else [] /* backwards compatibility */;
|
||||||
|
|
||||||
in
|
in
|
||||||
|
|
||||||
{ # URL to fetch.
|
{ # URL to fetch.
|
||||||
url ? ""
|
url ? ""
|
||||||
|
|
||||||
@@ -45,6 +45,12 @@ in
|
|||||||
, # If set, don't download the file, but write a list of all possible
|
, # If set, don't download the file, but write a list of all possible
|
||||||
# URLs (resulting from resolving mirror:// URLs) to $out.
|
# URLs (resulting from resolving mirror:// URLs) to $out.
|
||||||
showURLs ? false
|
showURLs ? false
|
||||||
|
|
||||||
|
, # If set, down't download file but tell user how to download it.
|
||||||
|
restricted ? false
|
||||||
|
|
||||||
|
, # Used only if restricted. Should contain instructions how to fetch the file.
|
||||||
|
message ? ""
|
||||||
}:
|
}:
|
||||||
|
|
||||||
assert urls != [] -> url == "";
|
assert urls != [] -> url == "";
|
||||||
@@ -56,34 +62,51 @@ assert showURLs || (outputHash != "" && outputHashAlgo != "")
|
|||||||
let
|
let
|
||||||
|
|
||||||
urls_ = if urls != [] then urls else [url];
|
urls_ = if urls != [] then urls else [url];
|
||||||
|
name_ = if showURLs then "urls"
|
||||||
in
|
|
||||||
|
|
||||||
stdenv.mkDerivation {
|
|
||||||
name =
|
|
||||||
if showURLs then "urls"
|
|
||||||
else if name != "" then name
|
else if name != "" then name
|
||||||
else baseNameOf (toString (builtins.head urls_));
|
else baseNameOf (toString (builtins.head urls_));
|
||||||
|
hashAlgo_ = if outputHashAlgo != "" then outputHashAlgo else
|
||||||
|
if sha256 != "" then "sha256" else if sha1 != "" then "sha1" else "md5";
|
||||||
|
hash_ = if outputHash != "" then outputHash else
|
||||||
|
if sha256 != "" then sha256 else if sha1 != "" then sha1 else md5;
|
||||||
|
in
|
||||||
|
|
||||||
|
stdenv.mkDerivation ({
|
||||||
|
name = name_;
|
||||||
|
outputHashAlgo = hashAlgo_;
|
||||||
|
outputHash = hash_;
|
||||||
|
urls = urls_;
|
||||||
|
|
||||||
|
# Compatibility with Nix <= 0.7.
|
||||||
|
id = md5;
|
||||||
|
|
||||||
|
inherit showURLs mirrorsFile;
|
||||||
|
}
|
||||||
|
// (if (!showURLs && restricted) then rec {
|
||||||
|
builder = writeScript "restrict-message" ''
|
||||||
|
source ${stdenv}/setup
|
||||||
|
cat <<_EOF_
|
||||||
|
${message_}
|
||||||
|
_EOF_
|
||||||
|
'';
|
||||||
|
message_ = if message != "" then message else ''
|
||||||
|
You have to download ${name_} from ${stdenv.lib.concatStringsSep " " urls_} yourself,
|
||||||
|
and add it to the store using "nix-store --add-fixed ${hashAlgo_} ${name_}".
|
||||||
|
'';
|
||||||
|
}
|
||||||
|
else {
|
||||||
builder = ./builder.sh;
|
builder = ./builder.sh;
|
||||||
|
|
||||||
buildInputs = [curl];
|
buildInputs = [curl];
|
||||||
|
|
||||||
urls = urls_;
|
|
||||||
|
|
||||||
# If set, prefer the content-addressable mirrors
|
# If set, prefer the content-addressable mirrors
|
||||||
# (http://nixos.org/tarballs) over the original URLs.
|
# (http://nixos.org/tarballs) over the original URLs.
|
||||||
preferHashedMirrors = true;
|
preferHashedMirrors = true;
|
||||||
|
|
||||||
# Compatibility with Nix <= 0.7.
|
|
||||||
id = md5;
|
|
||||||
|
|
||||||
# New-style output content requirements.
|
# New-style output content requirements.
|
||||||
outputHashAlgo = if outputHashAlgo != "" then outputHashAlgo else
|
|
||||||
if sha256 != "" then "sha256" else if sha1 != "" then "sha1" else "md5";
|
|
||||||
outputHash = if outputHash != "" then outputHash else
|
|
||||||
if sha256 != "" then sha256 else if sha1 != "" then sha1 else md5;
|
|
||||||
|
|
||||||
impureEnvVars = [
|
impureEnvVars = [
|
||||||
# We borrow these environment variables from the caller to allow
|
# We borrow these environment variables from the caller to allow
|
||||||
# easy proxy configuration. This is impure, but a fixed-output
|
# easy proxy configuration. This is impure, but a fixed-output
|
||||||
@@ -95,6 +118,5 @@ stdenv.mkDerivation {
|
|||||||
# command-line.
|
# command-line.
|
||||||
"NIX_HASHED_MIRRORS"
|
"NIX_HASHED_MIRRORS"
|
||||||
] ++ (map (site: "NIX_MIRRORS_${site}") sites);
|
] ++ (map (site: "NIX_MIRRORS_${site}") sites);
|
||||||
|
})
|
||||||
inherit showURLs mirrorsFile;
|
)
|
||||||
}
|
|
||||||
@@ -104,6 +104,7 @@ rec {
|
|||||||
fetchurl = import ../../build-support/fetchurl {
|
fetchurl = import ../../build-support/fetchurl {
|
||||||
stdenv = stdenvLinuxBoot0;
|
stdenv = stdenvLinuxBoot0;
|
||||||
curl = bootstrapTools;
|
curl = bootstrapTools;
|
||||||
|
inherit (allPackages) writeScript;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -119,6 +119,7 @@ rec {
|
|||||||
stdenv = stdenvBoot0;
|
stdenv = stdenvBoot0;
|
||||||
# Curl should be in /usr/bin or so.
|
# Curl should be in /usr/bin or so.
|
||||||
curl = null;
|
curl = null;
|
||||||
|
inherit (allPackages) writeScript;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -271,8 +271,7 @@ let
|
|||||||
# from being built.
|
# from being built.
|
||||||
fetchurl = useFromStdenv "fetchurl"
|
fetchurl = useFromStdenv "fetchurl"
|
||||||
(import ../build-support/fetchurl {
|
(import ../build-support/fetchurl {
|
||||||
curl = curl;
|
inherit stdenv curl writeScript;
|
||||||
stdenv = stdenv;
|
|
||||||
});
|
});
|
||||||
|
|
||||||
# fetchurlBoot is used for curl and its dependencies in order to
|
# fetchurlBoot is used for curl and its dependencies in order to
|
||||||
|
|||||||
Reference in New Issue
Block a user