First push!
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
/*
|
||||
* doas — OpenDoas, the portable OpenBSD-style privilege escalation tool.
|
||||
*
|
||||
* A minimal, auditable alternative to sudo. Configured with --without-pam
|
||||
* so it authenticates against /etc/shadow directly (getspnam + libcrypt) —
|
||||
* no PAM configuration to get wrong, no extra runtime dependencies.
|
||||
*
|
||||
* BUILD REQUIREMENTS
|
||||
* ==================
|
||||
* - GNU make (the GNUmakefile is not portable to other make flavours)
|
||||
* - yacc (bison) — parse.y is compiled at build time, not shipped pre-built
|
||||
* - a C toolchain
|
||||
* - libcrypt (libxcrypt on modern glibc) at build AND runtime
|
||||
* - root: the install target chowns doas to root:root and chmods it 4755
|
||||
* (setuid), which fails as a non-root user
|
||||
*
|
||||
* CONFIG
|
||||
* ======
|
||||
* doas.conf is deliberately NOT installed — upstream ships no default and
|
||||
* the format is simple (permit/deny rules). Write /etc/doas.conf by hand.
|
||||
*/
|
||||
package "doas" {
|
||||
const version = "6.8.2"
|
||||
const source = "https://github.com/Duncaen/OpenDoas/releases/download/v${version}/opendoas-${version}.tar.gz"
|
||||
sha256 = "28dca29adec5f4336465812d9e2243f599e62a78903de71c24f0cd6fe667edac"
|
||||
license = "ISC"
|
||||
|
||||
provides = ["doas"]
|
||||
|
||||
// No package-level env: the GNUmakefile already forces -O2 and appends
|
||||
// the user's CFLAGS. Optimization belongs in config.kap, not here.
|
||||
prepare {
|
||||
curl -L -O ${source}
|
||||
echo "28dca29adec5f4336465812d9e2243f599e62a78903de71c24f0cd6fe667edac opendoas-${version}.tar.gz" | sha256sum -c -
|
||||
tar xf opendoas-${version}.tar.gz --strip-components=1
|
||||
}
|
||||
|
||||
build {
|
||||
./configure --prefix=${prefix} --without-pam
|
||||
make -j${jobs}
|
||||
}
|
||||
|
||||
install {
|
||||
make DESTDIR=${destdir} install
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user