1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
|
{ stdenvNoCC
, lib
, fetchFromGitHub
, substituteAll
, makeWrapper
, zsh
, coreutils
, cryptsetup
, e2fsprogs
, file
, gawk
, getent
, gettext
, gnugrep
, gnupg
, libargon2
, lsof
, pinentry
, util-linux
, nix-update-script
}:
stdenvNoCC.mkDerivation rec {
pname = "tomb";
version = "2.10";
src = fetchFromGitHub {
owner = "dyne";
repo = "Tomb";
rev = "refs/tags/v${version}";
hash = "sha256-lLxQJX0P6b6lbXEcrq45EsX9iKiayZ9XkhqgMfpN3/w=";
};
buildInputs = [ zsh pinentry ];
nativeBuildInputs = [ makeWrapper ];
postPatch = ''
# if not, it shows .tomb-wrapped when running
substituteInPlace tomb \
--replace-fail 'TOMBEXEC=$0' 'TOMBEXEC=tomb'
'';
installPhase = ''
install -Dm755 tomb $out/bin/tomb
install -Dm644 doc/tomb.1 $out/share/man/man1/tomb.1
wrapProgram $out/bin/tomb \
--prefix PATH : $out/bin:${lib.makeBinPath [
coreutils
cryptsetup
e2fsprogs
file
gawk
getent
gettext
gnugrep
gnupg
libargon2
lsof
pinentry
util-linux
]}
'';
passthru = {
updateScript = nix-update-script { };
};
meta = with lib; {
description = "File encryption on GNU/Linux";
homepage = "https://www.dyne.org/software/tomb/";
changelog = "https://github.com/dyne/Tomb/blob/v${version}/ChangeLog.md";
license = licenses.gpl3Only;
mainProgram = "tomb";
maintainers = with maintainers; [ peterhoeg anthonyroussel ];
platforms = platforms.linux;
};
}
|