2015-01-31 21:51:08 +01:00
|
|
|
|
;;; GNU Guix --- Functional package management for GNU
|
|
|
|
|
;;; Copyright © 2015 Taylan Ulrich Bayırlı/Kammer <taylanbayirli@gmail.com>
|
2016-01-20 20:50:09 +01:00
|
|
|
|
;;; Copyright © 2016 Mark H Weaver <mhw@netris.org>
|
2016-01-21 11:20:30 +01:00
|
|
|
|
;;; Copyright © 2016 Ricardo Wurmus <rekado@elephly.net>
|
2016-03-10 08:29:55 +01:00
|
|
|
|
;;; Copyright © 2016 Efraim Flashner <efraim@flashner.co.il>
|
2016-09-11 00:03:10 +02:00
|
|
|
|
;;; Copyright © 2016 John Darrington <jmd@gnu.org>
|
2016-09-06 19:10:18 +02:00
|
|
|
|
;;; Copyright © 2016 ng0 <ng0@we.make.ritual.n0.is>
|
2017-03-16 15:30:15 +01:00
|
|
|
|
;;; Copyright © 2016, 2017 Tobias Geerinckx-Rice <me@tobias.gr>
|
2016-11-26 13:51:01 +01:00
|
|
|
|
;;; Copyright © 2016 Marius Bakke <mbakke@fastmail.com>
|
2017-05-02 14:34:28 +02:00
|
|
|
|
;;; Copyright © 2017 Vasile Dumitrascu <va511e@yahoo.com>
|
2017-06-18 14:27:34 +02:00
|
|
|
|
;;; Copyright © 2017 Gregor Giesen <giesen@zaehlwerk.net>
|
2015-01-31 21:51:08 +01:00
|
|
|
|
;;;
|
|
|
|
|
;;; This file is part of GNU Guix.
|
|
|
|
|
;;;
|
|
|
|
|
;;; GNU Guix is free software; you can redistribute it and/or modify it
|
|
|
|
|
;;; under the terms of the GNU General Public License as published by
|
|
|
|
|
;;; the Free Software Foundation; either version 3 of the License, or (at
|
|
|
|
|
;;; your option) any later version.
|
|
|
|
|
;;;
|
|
|
|
|
;;; GNU Guix is distributed in the hope that it will be useful, but
|
|
|
|
|
;;; WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
;;; GNU General Public License for more details.
|
|
|
|
|
;;;
|
|
|
|
|
;;; You should have received a copy of the GNU General Public License
|
|
|
|
|
;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
|
2015-03-13 12:06:19 +01:00
|
|
|
|
(define-module (gnu packages dns)
|
2017-03-16 15:30:15 +01:00
|
|
|
|
#:use-module (gnu packages admin)
|
2016-09-06 19:10:18 +02:00
|
|
|
|
#:use-module (gnu packages autotools)
|
2016-09-21 03:45:18 +02:00
|
|
|
|
#:use-module (gnu packages base)
|
2015-03-14 00:23:24 +01:00
|
|
|
|
#:use-module (gnu packages databases)
|
2016-11-26 13:51:01 +01:00
|
|
|
|
#:use-module (gnu packages crypto)
|
2017-03-16 15:30:15 +01:00
|
|
|
|
#:use-module (gnu packages datastructures)
|
2017-06-18 14:27:34 +02:00
|
|
|
|
#:use-module (gnu packages flex)
|
2017-01-19 07:55:38 +01:00
|
|
|
|
#:use-module (gnu packages glib)
|
2016-09-06 19:10:18 +02:00
|
|
|
|
#:use-module (gnu packages groff)
|
2017-03-16 15:30:15 +01:00
|
|
|
|
#:use-module (gnu packages groff)
|
|
|
|
|
#:use-module (gnu packages libedit)
|
2016-11-26 13:51:01 +01:00
|
|
|
|
#:use-module (gnu packages libevent)
|
2017-03-16 15:30:15 +01:00
|
|
|
|
#:use-module (gnu packages libidn)
|
2015-03-14 00:23:24 +01:00
|
|
|
|
#:use-module (gnu packages linux)
|
2017-03-16 15:30:15 +01:00
|
|
|
|
#:use-module (gnu packages ncurses)
|
|
|
|
|
#:use-module (gnu packages nettle)
|
2015-03-14 00:23:24 +01:00
|
|
|
|
#:use-module (gnu packages perl)
|
2016-09-06 19:10:18 +02:00
|
|
|
|
#:use-module (gnu packages pkg-config)
|
2017-06-18 14:27:34 +02:00
|
|
|
|
#:use-module (gnu packages protobuf)
|
|
|
|
|
#:use-module (gnu packages python)
|
|
|
|
|
#:use-module (gnu packages swig)
|
gnu: Rename module gnutls to tls.
* gnu/packages/gnutls.scm: Rename to...
* gnu/packages/tls.scm: ... this. Change module name accordingly.
* gnu/packages/{admin.scm, cups.scm, curl.scm, dc.scm, dns.scm, emacs.scm,
ftp.scm, gnome.scm, gnunet.scm, gnupg.scm, gsasl.scm, lynx.scm,
mail.scm, messaging.scm, package-management.scm, shishi.scm,
task-management.scm, version-control.scm, video.scm, vpn.scm,
webkit.scm, weechat.scm, wget.scm, wine.scm, xml.scm}: Adapt module
import to new name.
* gnu-system.am (GNU_SYSTEM_MODULES): Rename gnutls module to tls.
2015-07-03 21:41:22 +02:00
|
|
|
|
#:use-module (gnu packages tls)
|
2017-03-16 15:30:15 +01:00
|
|
|
|
#:use-module (gnu packages web)
|
2015-03-14 00:23:24 +01:00
|
|
|
|
#:use-module (gnu packages xml)
|
|
|
|
|
#:use-module ((guix licenses) #:prefix license:)
|
2015-01-31 21:51:08 +01:00
|
|
|
|
#:use-module (guix packages)
|
|
|
|
|
#:use-module (guix download)
|
2017-06-18 14:27:34 +02:00
|
|
|
|
#:use-module (guix utils)
|
2015-01-31 21:51:08 +01:00
|
|
|
|
#:use-module (guix build-system gnu))
|
|
|
|
|
|
|
|
|
|
(define-public dnsmasq
|
|
|
|
|
(package
|
|
|
|
|
(name "dnsmasq")
|
2016-05-25 08:23:14 +02:00
|
|
|
|
(version "2.76")
|
2015-01-31 21:51:08 +01:00
|
|
|
|
(source (origin
|
|
|
|
|
(method url-fetch)
|
|
|
|
|
(uri (string-append
|
|
|
|
|
"http://www.thekelleys.org.uk/dnsmasq/dnsmasq-"
|
|
|
|
|
version ".tar.xz"))
|
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
2016-05-25 08:23:14 +02:00
|
|
|
|
"15lzih6671gh9knzpl8mxchiml7z5lfqzr7jm2r0rjhrxs6nk4jb"))))
|
2015-01-31 21:51:08 +01:00
|
|
|
|
(build-system gnu-build-system)
|
2017-01-19 07:55:38 +01:00
|
|
|
|
(native-inputs
|
|
|
|
|
`(("pkg-config" ,pkg-config)))
|
|
|
|
|
(inputs
|
|
|
|
|
`(("dbus" ,dbus)))
|
2015-01-31 21:51:08 +01:00
|
|
|
|
(arguments
|
|
|
|
|
`(#:phases
|
|
|
|
|
(alist-delete 'configure %standard-phases)
|
|
|
|
|
#:make-flags (list (string-append "PREFIX=" (assoc-ref %outputs "out"))
|
2017-01-19 07:55:38 +01:00
|
|
|
|
"CC=gcc"
|
|
|
|
|
"COPTS=\"-DHAVE_DBUS\"")
|
2015-01-31 21:51:08 +01:00
|
|
|
|
;; No 'check' target.
|
|
|
|
|
#:tests? #f))
|
|
|
|
|
(home-page "http://www.thekelleys.org.uk/dnsmasq/doc.html")
|
|
|
|
|
(synopsis "Small caching DNS proxy and DHCP/TFTP server")
|
|
|
|
|
(description
|
|
|
|
|
"Dnsmasq is a lightweight DNS forwarder and DHCP server. It is designed
|
|
|
|
|
to provide DNS and optionally, DHCP, to a small network. It can serve the
|
|
|
|
|
names of local machines which are not in the global DNS. The DHCP server
|
|
|
|
|
integrates with the DNS server and allows machines with DHCP-allocated
|
|
|
|
|
addresses to appear in the DNS with names configured either in each host or in
|
|
|
|
|
a central configuration file. Dnsmasq supports static and dynamic DHCP leases
|
|
|
|
|
and BOOTP/TFTP for network booting of diskless machines.")
|
|
|
|
|
;; Source files only say GPL2 and GPL3 are allowed.
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(license (list license:gpl2 license:gpl3))))
|
|
|
|
|
|
2017-05-16 00:00:03 +02:00
|
|
|
|
;; 'bind' is the name of a built-in Guile procedure, which is why we choose a
|
|
|
|
|
;; different name here.
|
|
|
|
|
(define-public isc-bind
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(package
|
2016-09-11 00:03:10 +02:00
|
|
|
|
(name "bind")
|
2017-06-15 18:03:14 +02:00
|
|
|
|
(version "9.11.1-P1")
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(source (origin
|
|
|
|
|
(method url-fetch)
|
2016-09-11 00:03:10 +02:00
|
|
|
|
(uri (string-append
|
|
|
|
|
"ftp://ftp.isc.org/isc/bind9/" version "/" name "-"
|
|
|
|
|
version ".tar.gz"))
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
2017-06-15 18:03:14 +02:00
|
|
|
|
"0f56bhkxx7bga3f1a4whlm8fh5q8lz7ah97fdayp310vsn43w6vb"))))
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(build-system gnu-build-system)
|
2016-09-11 00:03:10 +02:00
|
|
|
|
(outputs `("out" "utils"))
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(inputs
|
|
|
|
|
;; it would be nice to add GeoIP and gssapi once there is package
|
|
|
|
|
`(("libcap" ,libcap)
|
|
|
|
|
("libxml2" ,libxml2)
|
|
|
|
|
("openssl" ,openssl)
|
|
|
|
|
("p11-kit" ,p11-kit)))
|
2016-09-11 00:03:10 +02:00
|
|
|
|
(native-inputs `(("perl" ,perl)
|
|
|
|
|
("net-tools" ,net-tools)))
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(arguments
|
2016-09-11 00:03:10 +02:00
|
|
|
|
`(#:configure-flags
|
2015-03-14 00:23:24 +01:00
|
|
|
|
(list (string-append "--with-openssl="
|
|
|
|
|
(assoc-ref %build-inputs "openssl"))
|
|
|
|
|
(string-append "--with-pkcs11="
|
|
|
|
|
(assoc-ref %build-inputs "p11-kit")))
|
|
|
|
|
#:phases
|
2016-09-11 00:03:10 +02:00
|
|
|
|
(modify-phases %standard-phases
|
|
|
|
|
(add-after 'strip 'move-to-utils
|
|
|
|
|
(lambda _
|
|
|
|
|
(for-each
|
|
|
|
|
(lambda (file)
|
|
|
|
|
(let ((target (string-append (assoc-ref %outputs "utils") file))
|
|
|
|
|
(src (string-append (assoc-ref %outputs "out") file)))
|
|
|
|
|
(mkdir-p (dirname target))
|
|
|
|
|
(link src target)
|
|
|
|
|
(delete-file src)))
|
|
|
|
|
'("/bin/dig" "/bin/delv" "/bin/nslookup" "/bin/host" "/bin/nsupdate"
|
|
|
|
|
"/share/man/man1/dig.1"
|
|
|
|
|
"/share/man/man1/host.1"
|
|
|
|
|
"/share/man/man1/nslookup.1"
|
|
|
|
|
"/share/man/man1/nsupdate.1"))))
|
|
|
|
|
;; When and if guix provides user namespaces for the build process,
|
|
|
|
|
;; then the following can be uncommented and the subsequent "force-test"
|
|
|
|
|
;; will not be necessary.
|
|
|
|
|
;;
|
|
|
|
|
;; (add-before 'check 'set-up-loopback
|
|
|
|
|
;; (lambda _
|
|
|
|
|
;; (system "bin/tests/system/ifconfig.sh up")))
|
|
|
|
|
(replace 'check
|
|
|
|
|
(lambda _
|
|
|
|
|
(zero? (system* "make" "force-test")))))))
|
|
|
|
|
(synopsis "An implementation of the Domain Name System")
|
2017-03-16 16:08:42 +01:00
|
|
|
|
(description "BIND is an implementation of the @dfn{Domain Name System}
|
|
|
|
|
(DNS) protocols for the Internet. It is a reference implementation of those
|
2016-09-11 00:03:10 +02:00
|
|
|
|
protocols, but it is also production-grade software, suitable for use in
|
|
|
|
|
high-volume and high-reliability applications. The name BIND stands for
|
|
|
|
|
\"Berkeley Internet Name Domain\", because the software originated in the early
|
|
|
|
|
1980s at the University of California at Berkeley.")
|
|
|
|
|
(home-page "https://www.isc.org/downloads/bind")
|
2017-05-02 14:34:28 +02:00
|
|
|
|
(license (list license:mpl2.0))))
|
2016-09-11 00:03:10 +02:00
|
|
|
|
|
2016-11-26 16:24:18 +01:00
|
|
|
|
(define-public dnscrypt-proxy
|
|
|
|
|
(package
|
|
|
|
|
(name "dnscrypt-proxy")
|
2017-05-08 12:19:55 +02:00
|
|
|
|
(version "1.9.5")
|
2016-11-26 16:24:18 +01:00
|
|
|
|
(source (origin
|
|
|
|
|
(method url-fetch)
|
|
|
|
|
(uri (string-append
|
|
|
|
|
"https://download.dnscrypt.org/dnscrypt-proxy/"
|
|
|
|
|
"dnscrypt-proxy-" version ".tar.bz2"))
|
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
2017-05-08 12:19:55 +02:00
|
|
|
|
"1dhvklr4dg2vlw108n11xbamacaryyg3dbrg629b76lp7685p7z8"))
|
2016-11-26 16:24:18 +01:00
|
|
|
|
(modules '((guix build utils)))
|
|
|
|
|
(snippet
|
|
|
|
|
;; Delete bundled libltdl. XXX: This package also bundles
|
|
|
|
|
;; a modified libevent that cannot currently be removed.
|
|
|
|
|
'(delete-file-recursively "libltdl"))))
|
|
|
|
|
(build-system gnu-build-system)
|
|
|
|
|
(arguments
|
|
|
|
|
`(#:phases
|
|
|
|
|
(modify-phases %standard-phases
|
|
|
|
|
(add-before 'configure 'autoreconf
|
|
|
|
|
(lambda _
|
|
|
|
|
;; Re-generate build files due to unbundling ltdl.
|
|
|
|
|
;; TODO: Prevent generating new libltdl and building it.
|
|
|
|
|
;; The system version is still favored and referenced.
|
|
|
|
|
(zero? (system* "autoreconf" "-vif")))))))
|
|
|
|
|
(native-inputs
|
|
|
|
|
`(("pkg-config" ,pkg-config)
|
|
|
|
|
("automake" ,automake)
|
|
|
|
|
("autoconf" ,autoconf)
|
|
|
|
|
("libtool" ,libtool)))
|
|
|
|
|
(inputs
|
|
|
|
|
`(("libltdl" ,libltdl)
|
|
|
|
|
("libsodium" ,libsodium)))
|
|
|
|
|
(home-page "https://www.dnscrypt.org/")
|
|
|
|
|
(synopsis "Securely send DNS requests to a remote server")
|
|
|
|
|
(description
|
|
|
|
|
"@command{dnscrypt-proxy} is a tool for securing communications
|
|
|
|
|
between a client and a DNS resolver. It verifies that responses you get
|
|
|
|
|
from a DNS provider was actually sent by that provider, and haven't been
|
|
|
|
|
tampered with. For optimal performance it is recommended to use this as
|
|
|
|
|
a forwarder for a caching DNS resolver such as @command{dnsmasq}, but it
|
|
|
|
|
can also be used as a normal DNS \"server\". A list of public dnscrypt
|
|
|
|
|
servers is included, and an up-to-date version is available at
|
|
|
|
|
@url{https://download.dnscrypt.org/dnscrypt-proxy/dnscrypt-resolvers.csv}.")
|
|
|
|
|
(license (list license:isc
|
|
|
|
|
;; Libevent and src/ext/queue.h is 3-clause BSD.
|
|
|
|
|
license:bsd-3))))
|
|
|
|
|
|
2016-11-26 13:51:01 +01:00
|
|
|
|
(define-public dnscrypt-wrapper
|
|
|
|
|
(package
|
|
|
|
|
(name "dnscrypt-wrapper")
|
|
|
|
|
(version "0.2.2")
|
|
|
|
|
(source (origin
|
|
|
|
|
(method url-fetch)
|
|
|
|
|
(uri (string-append
|
|
|
|
|
"https://github.com/cofyc/dnscrypt-wrapper/releases"
|
|
|
|
|
"/download/v" version "/" name "-v" version ".tar.bz2"))
|
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
|
|
|
|
"1vhg4g0r687f51wcdn7z9w1hxapazx6vyh5rsr8wa48sljzd583g"))))
|
|
|
|
|
(build-system gnu-build-system)
|
|
|
|
|
(arguments
|
|
|
|
|
`(#:make-flags '("CC=gcc")
|
|
|
|
|
;; TODO: Tests require ruby-cucumber and ruby-aruba.
|
|
|
|
|
#:tests? #f
|
|
|
|
|
#:phases
|
|
|
|
|
(modify-phases %standard-phases
|
|
|
|
|
(add-before 'configure 'create-configure
|
|
|
|
|
(lambda _
|
|
|
|
|
(zero? (system* "make" "configure")))))))
|
|
|
|
|
(native-inputs
|
|
|
|
|
`(("autoconf" ,autoconf)))
|
|
|
|
|
(inputs
|
|
|
|
|
`(("libevent" ,libevent)
|
|
|
|
|
("libsodium" ,libsodium)))
|
|
|
|
|
(home-page "https://github.com/Cofyc/dnscrypt-wrapper")
|
|
|
|
|
(synopsis "Server-side dnscrypt proxy")
|
|
|
|
|
(description
|
|
|
|
|
"@command{dnscrypt-wrapper} is a tool to expose a name server over
|
|
|
|
|
the @code{dnscrypt} protocol. It can be used as an endpoint for the
|
|
|
|
|
@command{dnscrypt-proxy} client to securely tunnel DNS requests between
|
|
|
|
|
the two.")
|
|
|
|
|
(license (list license:isc
|
|
|
|
|
;; Bundled argparse is MIT. TODO: package and unbundle.
|
|
|
|
|
license:expat
|
|
|
|
|
;; dns-protocol.h and rfc1035.{c,h} is gpl2 or gpl3 (either).
|
|
|
|
|
license:gpl2
|
|
|
|
|
license:gpl3))))
|
|
|
|
|
|
2016-09-06 19:10:18 +02:00
|
|
|
|
(define-public libasr
|
|
|
|
|
(package
|
|
|
|
|
(name "libasr")
|
|
|
|
|
(version "201602131606")
|
|
|
|
|
(source
|
|
|
|
|
(origin
|
|
|
|
|
(method url-fetch)
|
|
|
|
|
(uri (string-append "https://www.opensmtpd.org/archives/"
|
|
|
|
|
name "-" version ".tar.gz"))
|
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
|
|
|
|
"18kdmbjsxrfai16d66qslp48b1zf7gr8him2jj5dcqgbsl44ls75"))))
|
|
|
|
|
(build-system gnu-build-system)
|
|
|
|
|
(native-inputs
|
|
|
|
|
`(("autoconf" ,autoconf)
|
|
|
|
|
("automake" ,automake)
|
|
|
|
|
("pkg-config" ,pkg-config)
|
|
|
|
|
("groff" ,groff)))
|
|
|
|
|
(home-page "https://www.opensmtpd.org")
|
|
|
|
|
(synopsis "Asynchronous resolver library by the OpenBSD project")
|
|
|
|
|
(description
|
|
|
|
|
"libasr is a free, simple and portable asynchronous resolver library.
|
|
|
|
|
It allows to run DNS queries and perform hostname resolutions in a fully
|
|
|
|
|
asynchronous fashion.")
|
|
|
|
|
(license (list license:isc
|
|
|
|
|
license:bsd-2 ; last part of getrrsetbyname_async.c
|
|
|
|
|
license:bsd-3
|
|
|
|
|
(license:non-copyleft "file://LICENSE") ; includes.h
|
|
|
|
|
license:openssl))))
|
2016-09-21 03:45:18 +02:00
|
|
|
|
|
2017-06-18 14:27:34 +02:00
|
|
|
|
(define-public unbound
|
|
|
|
|
(package
|
|
|
|
|
(name "unbound")
|
|
|
|
|
(version "1.6.3")
|
|
|
|
|
(source
|
|
|
|
|
(origin
|
|
|
|
|
(method url-fetch)
|
|
|
|
|
(uri (string-append "https://www.unbound.net/downloads/unbound-"
|
|
|
|
|
version ".tar.gz"))
|
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
|
|
|
|
"0pw4m4z5qspsagxzbjb61xq5bhd57amw26xqvqzi6b8d3mf6azjc"))))
|
|
|
|
|
(build-system gnu-build-system)
|
|
|
|
|
(outputs '("out" "python"))
|
|
|
|
|
(native-inputs
|
|
|
|
|
`(("flex" ,flex)
|
|
|
|
|
("swig" ,swig)))
|
|
|
|
|
(inputs
|
|
|
|
|
`(("expat" ,expat)
|
|
|
|
|
("libevent" ,libevent)
|
|
|
|
|
("protobuf" ,protobuf)
|
|
|
|
|
("python" ,python-3)
|
|
|
|
|
("python-wrapper" ,python-wrapper)
|
|
|
|
|
("openssl" ,openssl)))
|
|
|
|
|
(arguments
|
|
|
|
|
`(#:configure-flags
|
2017-06-21 10:19:47 +02:00
|
|
|
|
(list "--disable-static" ;save space and non-determinism in libunbound.a
|
|
|
|
|
(string-append
|
2017-06-18 14:27:34 +02:00
|
|
|
|
"--with-ssl=" (assoc-ref %build-inputs "openssl"))
|
|
|
|
|
(string-append
|
|
|
|
|
"--with-libevent=" (assoc-ref %build-inputs "libevent"))
|
|
|
|
|
(string-append
|
|
|
|
|
"--with-libexpat=" (assoc-ref %build-inputs "expat"))
|
|
|
|
|
"--with-pythonmodule" "--with-pyunbound")
|
|
|
|
|
#:phases
|
|
|
|
|
(modify-phases %standard-phases
|
|
|
|
|
(add-after 'configure 'fix-python-site-package-path
|
|
|
|
|
;; Move python modules into their own output.
|
|
|
|
|
(lambda* (#:key outputs #:allow-other-keys)
|
|
|
|
|
(let ((pyout (assoc-ref outputs "python"))
|
|
|
|
|
(ver ,(version-major+minor (package-version python))))
|
|
|
|
|
(substitute* "Makefile"
|
|
|
|
|
(("^PYTHON_SITE_PKG=.*$")
|
|
|
|
|
(string-append
|
|
|
|
|
"PYTHON_SITE_PKG="
|
|
|
|
|
pyout "/lib/python-" ver "/site-packages\n"))))
|
|
|
|
|
#t))
|
|
|
|
|
(add-before 'check 'fix-missing-nss-for-tests
|
|
|
|
|
;; Unfortunately, the package's unittests involve some checks
|
|
|
|
|
;; looking up protocols and services which are not provided
|
|
|
|
|
;; by the minimalistic build environment, in particular,
|
|
|
|
|
;; /etc/protocols and /etc/services are missing.
|
|
|
|
|
;; Also, after plain substitution of protocol and service names
|
|
|
|
|
;; in the test data, the tests still fail because the
|
|
|
|
|
;; corresponding Resource Records have been signed by
|
|
|
|
|
;; RRSIG records.
|
|
|
|
|
;; The following LD_PRELOAD library overwrites the glibc
|
|
|
|
|
;; functions ‘get{proto,serv}byname’, ‘getprotobynumber’ and
|
|
|
|
|
;; ‘getservbyport’ providing the few records required for the
|
|
|
|
|
;; unit tests to pass.
|
|
|
|
|
(lambda* (#:key inputs outputs #:allow-other-keys)
|
|
|
|
|
(let* ((source (assoc-ref %build-inputs "source"))
|
|
|
|
|
(gcc (assoc-ref %build-inputs "gcc")))
|
|
|
|
|
(call-with-output-file "/tmp/nss_preload.c"
|
|
|
|
|
(lambda (port)
|
|
|
|
|
(display "#include <stdlib.h>
|
|
|
|
|
#include <string.h>
|
|
|
|
|
#include <strings.h>
|
|
|
|
|
|
|
|
|
|
#include <netdb.h>
|
|
|
|
|
|
|
|
|
|
struct protoent *getprotobyname(const char *name) {
|
|
|
|
|
struct protoent *p = malloc(sizeof(struct protoent));
|
|
|
|
|
p->p_aliases = malloc(sizeof(char*));
|
|
|
|
|
if (strcasecmp(name, \"tcp\") == 0) {
|
|
|
|
|
p->p_name = \"tcp\";
|
|
|
|
|
p->p_proto = 6;
|
|
|
|
|
p->p_aliases[0] = \"TCP\";
|
|
|
|
|
} else if (strcasecmp(name, \"udp\") == 0) {
|
|
|
|
|
p->p_name = \"udp\";
|
|
|
|
|
p->p_proto = 17;
|
|
|
|
|
p->p_aliases[0] = \"UDP\";
|
|
|
|
|
} else
|
|
|
|
|
p = NULL;
|
|
|
|
|
return p;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
struct protoent *getprotobynumber(int proto) {
|
|
|
|
|
struct protoent *p = malloc(sizeof(struct protoent));
|
|
|
|
|
p->p_aliases = malloc(sizeof(char*));
|
|
|
|
|
switch(proto) {
|
|
|
|
|
case 6:
|
|
|
|
|
p->p_name = \"tcp\";
|
|
|
|
|
p->p_proto = 6;
|
|
|
|
|
p->p_aliases[0] = \"TCP\";
|
|
|
|
|
break;
|
|
|
|
|
case 17:
|
|
|
|
|
p->p_name = \"udp\";
|
|
|
|
|
p->p_proto = 17;
|
|
|
|
|
p->p_aliases[0] = \"UDP\";
|
|
|
|
|
break;
|
|
|
|
|
default:
|
|
|
|
|
p = NULL;
|
|
|
|
|
break;
|
|
|
|
|
}
|
|
|
|
|
return p;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
struct servent *getservbyname(const char *name, const char *proto) {
|
|
|
|
|
struct servent *s = malloc(sizeof(struct servent));
|
|
|
|
|
char* buf = malloc((strlen(proto)+1)*sizeof(char));
|
|
|
|
|
strcpy(buf, proto);
|
|
|
|
|
s->s_aliases = malloc(sizeof(char*));
|
|
|
|
|
s->s_aliases[0] = NULL;
|
|
|
|
|
if (strcasecmp(name, \"domain\") == 0) {
|
|
|
|
|
s->s_name = \"domain\";
|
|
|
|
|
s->s_port = htons(53);
|
|
|
|
|
s->s_proto = buf;
|
|
|
|
|
} else
|
|
|
|
|
s = NULL;
|
|
|
|
|
return s;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
struct servent *getservbyport(int port, const char *proto) {
|
|
|
|
|
char buf[32];
|
|
|
|
|
struct servent *s = malloc(sizeof(struct servent));
|
|
|
|
|
strcpy(buf, proto);
|
|
|
|
|
s->s_aliases = malloc(sizeof(char*));
|
|
|
|
|
s->s_aliases[0] = NULL;
|
|
|
|
|
switch(port) {
|
|
|
|
|
case 53:
|
|
|
|
|
s->s_name = \"domain\";
|
|
|
|
|
s->s_port = 53;
|
|
|
|
|
s->s_proto = \"udp\";
|
|
|
|
|
break;
|
|
|
|
|
default:
|
|
|
|
|
s = NULL;
|
|
|
|
|
break;
|
|
|
|
|
}
|
|
|
|
|
return s;
|
|
|
|
|
}" port)))
|
|
|
|
|
(system* (string-append gcc "/bin/gcc")
|
|
|
|
|
"-shared" "-fPIC" "-o" "/tmp/nss_preload.so"
|
|
|
|
|
"/tmp/nss_preload.c")
|
|
|
|
|
;; The preload library only affects the unittests.
|
|
|
|
|
(substitute* "Makefile"
|
|
|
|
|
(("./unittest")
|
|
|
|
|
"LD_PRELOAD=/tmp/nss_preload.so ./unittest")))
|
|
|
|
|
#t)))))
|
|
|
|
|
(home-page "https://www.unbound.net")
|
|
|
|
|
(synopsis "Validating, recursive, and caching DNS resolver")
|
|
|
|
|
(description
|
|
|
|
|
"Unbound is a recursive-only caching DNS server which can perform DNSSEC
|
|
|
|
|
validation of results. It implements only a minimal amount of authoritative
|
|
|
|
|
service to prevent leakage to the root nameservers: forward lookups for
|
|
|
|
|
localhost, reverse for @code{127.0.0.1} and @code{::1}, and NXDOMAIN for zones
|
|
|
|
|
served by AS112. Stub and forward zones are supported.")
|
|
|
|
|
(license license:bsd-4)))
|
|
|
|
|
|
2016-09-21 03:45:18 +02:00
|
|
|
|
(define-public yadifa
|
|
|
|
|
(package
|
|
|
|
|
(name "yadifa")
|
2017-04-17 01:35:23 +02:00
|
|
|
|
(version "2.2.4")
|
2016-09-21 03:45:18 +02:00
|
|
|
|
(source
|
2017-04-17 01:35:23 +02:00
|
|
|
|
(let ((revision "6924"))
|
2016-12-23 23:46:53 +01:00
|
|
|
|
(origin
|
|
|
|
|
(method url-fetch)
|
|
|
|
|
(uri
|
|
|
|
|
(string-append "http://cdn.yadifa.eu/sites/default/files/releases/"
|
|
|
|
|
name "-" version "-" revision ".tar.gz"))
|
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
2017-04-17 01:35:23 +02:00
|
|
|
|
"060ydcfn9876bs6p5xi3p1k20ca547f4jck25r5x1hnxjlv7ss03")))))
|
2016-09-21 03:45:18 +02:00
|
|
|
|
(build-system gnu-build-system)
|
|
|
|
|
(native-inputs
|
|
|
|
|
`(("which" ,which)))
|
|
|
|
|
(inputs
|
|
|
|
|
`(("openssl" ,openssl)))
|
|
|
|
|
(arguments
|
|
|
|
|
`(#:phases (modify-phases %standard-phases
|
|
|
|
|
(add-before 'configure 'omit-example-configurations
|
2017-03-21 07:55:49 +01:00
|
|
|
|
(lambda _
|
|
|
|
|
(substitute* "Makefile.in"
|
|
|
|
|
((" (etc|var)") ""))
|
|
|
|
|
#t)))
|
2016-09-21 03:45:18 +02:00
|
|
|
|
#:configure-flags (list "--sysconfdir=/etc" "--localstatedir=/var"
|
|
|
|
|
"--enable-shared" "--disable-static"
|
|
|
|
|
"--enable-messages" "--enable-ctrl"
|
2016-12-23 23:52:27 +01:00
|
|
|
|
"--enable-nsec" "--enable-nsec3"
|
|
|
|
|
"--enable-tsig" "--enable-caching"
|
2016-09-21 03:45:18 +02:00
|
|
|
|
;; NSID is a rarely-used debugging aid, that also
|
|
|
|
|
;; causes the build to fail. Just disable it.
|
|
|
|
|
"--disable-nsid")))
|
|
|
|
|
(home-page "http://www.yadifa.eu/")
|
|
|
|
|
(synopsis "Authoritative DNS name server")
|
2017-03-16 16:08:42 +01:00
|
|
|
|
(description "YADIFA is an authoritative name server for the @dfn{Domain
|
|
|
|
|
Name System} (DNS). It aims for both higher performance and a smaller memory
|
2016-09-21 03:45:18 +02:00
|
|
|
|
footprint than other implementations, while remaining fully RFC-compliant.
|
2017-03-16 16:08:42 +01:00
|
|
|
|
YADIFA supports dynamic record updates and the @dfn{Domain Name System Security
|
|
|
|
|
Extensions} (DNSSEC).")
|
2016-09-21 03:45:18 +02:00
|
|
|
|
(license license:bsd-3)))
|
2017-03-16 15:30:15 +01:00
|
|
|
|
|
|
|
|
|
(define-public knot
|
|
|
|
|
(package
|
|
|
|
|
(name "knot")
|
2017-06-23 17:04:07 +02:00
|
|
|
|
(version "2.5.2")
|
2017-03-16 15:30:15 +01:00
|
|
|
|
(source (origin
|
|
|
|
|
(method url-fetch)
|
|
|
|
|
(uri (string-append "https://secure.nic.cz/files/knot-dns/"
|
|
|
|
|
name "-" version ".tar.xz"))
|
|
|
|
|
(sha256
|
|
|
|
|
(base32
|
2017-06-23 17:04:07 +02:00
|
|
|
|
"1sgmw8k9qccc7bgxbwrvahdinj1bjq90iza55rxj199mxsj72ri8"))
|
2017-03-16 15:30:15 +01:00
|
|
|
|
(modules '((guix build utils)))
|
|
|
|
|
(snippet
|
|
|
|
|
'(begin
|
|
|
|
|
;; Remove bundled libraries and dependencies on them.
|
|
|
|
|
(substitute* "configure"
|
|
|
|
|
(("src/contrib/dnstap/Makefile") ""))
|
|
|
|
|
(substitute* "src/Makefile.in"
|
|
|
|
|
(("contrib/dnstap ") ""))
|
|
|
|
|
(with-directory-excursion "src/contrib"
|
|
|
|
|
(for-each delete-file-recursively
|
2017-03-21 07:55:49 +01:00
|
|
|
|
(list "dnstap" "lmdb")))
|
|
|
|
|
#t))))
|
2017-03-16 15:30:15 +01:00
|
|
|
|
(build-system gnu-build-system)
|
|
|
|
|
(native-inputs
|
|
|
|
|
`(("pkg-config" ,pkg-config)))
|
|
|
|
|
(inputs
|
|
|
|
|
`(("gnutls" ,gnutls)
|
|
|
|
|
("jansson" ,jansson)
|
|
|
|
|
("libcap-ng" ,libcap-ng)
|
|
|
|
|
("libedit" ,libedit)
|
|
|
|
|
("libidn" ,libidn)
|
|
|
|
|
("liburcu" ,liburcu)
|
|
|
|
|
("lmdb" ,lmdb)
|
|
|
|
|
("ncurses" ,ncurses)
|
2017-06-09 21:57:53 +02:00
|
|
|
|
("nettle" ,nettle)
|
|
|
|
|
|
|
|
|
|
;; For ‘pykeymgr’, needed to migrate keys from versions <= 2.4.
|
|
|
|
|
("python" ,python-2)
|
|
|
|
|
("python-lmdb" ,python2-lmdb)))
|
2017-03-16 15:30:15 +01:00
|
|
|
|
(arguments
|
|
|
|
|
`(#:phases
|
|
|
|
|
(modify-phases %standard-phases
|
|
|
|
|
(add-before 'configure 'disable-directory-pre-creation
|
|
|
|
|
(lambda _
|
|
|
|
|
;; Don't install empty directories like ‘/etc’ outside the store.
|
2017-03-21 07:55:49 +01:00
|
|
|
|
(substitute* "src/Makefile.in" (("\\$\\(INSTALL\\) -d") "true"))
|
|
|
|
|
#t))
|
2017-03-16 15:30:15 +01:00
|
|
|
|
(replace 'install
|
|
|
|
|
(lambda* (#:key outputs #:allow-other-keys)
|
|
|
|
|
(let* ((out (assoc-ref outputs "out"))
|
|
|
|
|
(doc (string-append out "/share/doc/knot"))
|
|
|
|
|
(etc (string-append doc "/examples/etc")))
|
|
|
|
|
(zero?
|
|
|
|
|
(system* "make"
|
|
|
|
|
(string-append "config_dir=" etc)
|
2017-06-09 21:57:53 +02:00
|
|
|
|
"install")))))
|
|
|
|
|
(add-after 'install 'wrap-python-scripts
|
|
|
|
|
(lambda* (#:key outputs #:allow-other-keys)
|
|
|
|
|
(let* ((out (assoc-ref outputs "out"))
|
|
|
|
|
(path (getenv "PYTHONPATH")))
|
|
|
|
|
(wrap-program (string-append out "/sbin/pykeymgr")
|
|
|
|
|
`("PYTHONPATH" ":" prefix (,path))))
|
|
|
|
|
#t)))
|
2017-03-16 15:30:15 +01:00
|
|
|
|
#:configure-flags
|
|
|
|
|
(list "--sysconfdir=/etc"
|
|
|
|
|
"--localstatedir=/var"
|
2017-06-09 21:57:53 +02:00
|
|
|
|
"--with-module-rosedb=yes" ; serve static records from a database
|
2017-03-16 15:30:15 +01:00
|
|
|
|
(string-append "--with-bash-completions="
|
|
|
|
|
(assoc-ref %outputs "out")
|
|
|
|
|
"/etc/bash_completion.d"))))
|
|
|
|
|
(home-page "https://www.knot-dns.cz/")
|
|
|
|
|
(synopsis "Authoritative DNS name server")
|
2017-04-16 18:06:57 +02:00
|
|
|
|
(description "Knot DNS is an authoritative name server for the @dfn{Domain
|
2017-03-16 15:30:15 +01:00
|
|
|
|
Name System} (DNS), designed to meet the needs of root and @dfn{top-level
|
|
|
|
|
domain} (TLD) name servers. It is implemented as a threaded daemon and uses a
|
|
|
|
|
number of programming techniques to improve speed. For example, the responder
|
|
|
|
|
is completely lock-free, resulting in a very high response rate. Other features
|
|
|
|
|
include automatic @dfn{DNS Security Extensions} (DNSSEC) signing, dynamic record
|
|
|
|
|
synthesis, and on-the-fly re-configuration.")
|
|
|
|
|
(license (list license:expat ; src/contrib/{hat-trie,murmurhash3}
|
|
|
|
|
license:lgpl2.0+ ; parts of scr/contrib/ucw
|
|
|
|
|
license:gpl3+)))) ; everything else
|