2018-07-14 07:25:28 +02:00
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
|
|
|
|
with lib;
|
|
|
|
|
|
|
|
let
|
|
|
|
cfg = config.programs.firejail;
|
|
|
|
|
2019-10-05 18:32:22 +02:00
|
|
|
wrappedBins = pkgs.runCommand "firejail-wrapped-binaries"
|
|
|
|
{ preferLocalBuild = true;
|
|
|
|
allowSubstitutes = false;
|
2022-11-30 18:45:16 +01:00
|
|
|
# take precedence over non-firejailed versions
|
|
|
|
meta.priority = -1;
|
2019-10-05 18:32:22 +02:00
|
|
|
}
|
|
|
|
''
|
2018-07-14 07:25:28 +02:00
|
|
|
mkdir -p $out/bin
|
2022-11-30 18:45:16 +01:00
|
|
|
mkdir -p $out/share/applications
|
2020-11-14 13:00:00 +01:00
|
|
|
${lib.concatStringsSep "\n" (lib.mapAttrsToList (command: value:
|
|
|
|
let
|
|
|
|
opts = if builtins.isAttrs value
|
|
|
|
then value
|
2022-11-30 18:45:16 +01:00
|
|
|
else { executable = value; desktop = null; profile = null; extraArgs = []; };
|
2020-11-14 13:00:00 +01:00
|
|
|
args = lib.escapeShellArgs (
|
2022-03-01 12:58:04 +01:00
|
|
|
opts.extraArgs
|
|
|
|
++ (optional (opts.profile != null) "--profile=${toString opts.profile}")
|
2022-11-30 18:45:16 +01:00
|
|
|
);
|
2020-11-14 13:00:00 +01:00
|
|
|
in
|
|
|
|
''
|
2019-10-05 18:32:22 +02:00
|
|
|
cat <<_EOF >$out/bin/${command}
|
|
|
|
#! ${pkgs.runtimeShell} -e
|
2020-11-14 13:00:00 +01:00
|
|
|
exec /run/wrappers/bin/firejail ${args} -- ${toString opts.executable} "\$@"
|
2019-10-05 18:32:22 +02:00
|
|
|
_EOF
|
|
|
|
chmod 0755 $out/bin/${command}
|
2022-11-30 18:45:16 +01:00
|
|
|
|
|
|
|
${lib.optionalString (opts.desktop != null) ''
|
|
|
|
substitute ${opts.desktop} $out/share/applications/$(basename ${opts.desktop}) \
|
|
|
|
--replace ${opts.executable} $out/bin/${command}
|
|
|
|
''}
|
2018-07-14 07:25:28 +02:00
|
|
|
'') cfg.wrappedBinaries)}
|
|
|
|
'';
|
|
|
|
|
|
|
|
in {
|
|
|
|
options.programs.firejail = {
|
2022-08-28 21:18:44 +02:00
|
|
|
enable = mkEnableOption (lib.mdDoc "firejail");
|
2018-07-14 07:25:28 +02:00
|
|
|
|
|
|
|
wrappedBinaries = mkOption {
|
2020-11-14 13:00:00 +01:00
|
|
|
type = types.attrsOf (types.either types.path (types.submodule {
|
|
|
|
options = {
|
|
|
|
executable = mkOption {
|
|
|
|
type = types.path;
|
2022-08-29 19:33:50 +02:00
|
|
|
description = lib.mdDoc "Executable to run sandboxed";
|
2021-10-03 18:06:03 +02:00
|
|
|
example = literalExpression ''"''${lib.getBin pkgs.firefox}/bin/firefox"'';
|
2020-11-14 13:00:00 +01:00
|
|
|
};
|
2022-11-30 18:45:16 +01:00
|
|
|
desktop = mkOption {
|
|
|
|
type = types.nullOr types.path;
|
|
|
|
default = null;
|
|
|
|
description = lib.mkDoc ".desktop file to modify. Only necessary if it uses the absolute path to the executable.";
|
|
|
|
example = literalExpression ''"''${pkgs.firefox}/share/applications/firefox.desktop"'';
|
|
|
|
};
|
2020-11-14 13:00:00 +01:00
|
|
|
profile = mkOption {
|
|
|
|
type = types.nullOr types.path;
|
|
|
|
default = null;
|
2022-08-29 19:33:50 +02:00
|
|
|
description = lib.mdDoc "Profile to use";
|
2021-10-03 18:06:03 +02:00
|
|
|
example = literalExpression ''"''${pkgs.firejail}/etc/firejail/firefox.profile"'';
|
2020-11-14 13:00:00 +01:00
|
|
|
};
|
|
|
|
extraArgs = mkOption {
|
|
|
|
type = types.listOf types.str;
|
|
|
|
default = [];
|
2022-08-29 19:33:50 +02:00
|
|
|
description = lib.mdDoc "Extra arguments to pass to firejail";
|
2020-11-14 13:00:00 +01:00
|
|
|
example = [ "--private=~/.firejail_home" ];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
}));
|
2018-07-14 07:25:28 +02:00
|
|
|
default = {};
|
2021-10-03 18:06:03 +02:00
|
|
|
example = literalExpression ''
|
2020-02-29 18:55:53 +01:00
|
|
|
{
|
2020-11-14 13:00:00 +01:00
|
|
|
firefox = {
|
|
|
|
executable = "''${lib.getBin pkgs.firefox}/bin/firefox";
|
|
|
|
profile = "''${pkgs.firejail}/etc/firejail/firefox.profile";
|
|
|
|
};
|
|
|
|
mpv = {
|
|
|
|
executable = "''${lib.getBin pkgs.mpv}/bin/mpv";
|
|
|
|
profile = "''${pkgs.firejail}/etc/firejail/mpv.profile";
|
|
|
|
};
|
2020-02-29 18:55:53 +01:00
|
|
|
}
|
|
|
|
'';
|
2022-08-03 22:46:41 +02:00
|
|
|
description = lib.mdDoc ''
|
2018-07-14 07:25:28 +02:00
|
|
|
Wrap the binaries in firejail and place them in the global path.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
config = mkIf cfg.enable {
|
2021-09-12 18:53:48 +02:00
|
|
|
security.wrappers.firejail =
|
|
|
|
{ setuid = true;
|
|
|
|
owner = "root";
|
|
|
|
group = "root";
|
|
|
|
source = "${lib.getBin pkgs.firejail}/bin/firejail";
|
|
|
|
};
|
2018-07-14 07:25:28 +02:00
|
|
|
|
2020-02-02 19:21:26 +01:00
|
|
|
environment.systemPackages = [ pkgs.firejail ] ++ [ wrappedBins ];
|
2018-07-14 07:25:28 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
meta.maintainers = with maintainers; [ peterhoeg ];
|
|
|
|
}
|