we don't remove the entire feature in one go to make review easier. impure derivations are rather unintrusive on their own, at least if we compare them to dynamic or ca derivations in general, so we will be done with this soon. as it stands impure derivations cannot work without ca derivations, and those we *really* want to leave behind. Change-Id: I4f01d8d758b2c85dcd6c3078304b5ee1b52f65b0
77 lines
1.5 KiB
Nix
77 lines
1.5 KiB
Nix
{
|
|
system ? "", # obsolete
|
|
url,
|
|
hash ? "", # an SRI hash
|
|
|
|
# Legacy hash specification
|
|
md5 ? "",
|
|
sha1 ? "",
|
|
sha256 ? "",
|
|
sha512 ? "",
|
|
outputHash ?
|
|
if hash != "" then
|
|
hash
|
|
else if sha512 != "" then
|
|
sha512
|
|
else if sha1 != "" then
|
|
sha1
|
|
else if md5 != "" then
|
|
md5
|
|
else
|
|
sha256,
|
|
outputHashAlgo ?
|
|
if hash != "" then
|
|
""
|
|
else if sha512 != "" then
|
|
"sha512"
|
|
else if sha1 != "" then
|
|
"sha1"
|
|
else if md5 != "" then
|
|
"md5"
|
|
else
|
|
"sha256",
|
|
|
|
executable ? false,
|
|
unpack ? false,
|
|
name ? baseNameOf (toString url),
|
|
# still translates to __impure to trigger derivationStrict error checks.
|
|
impure ? false,
|
|
}:
|
|
|
|
derivation (
|
|
{
|
|
builder = "builtin:fetchurl";
|
|
|
|
# New-style output content requirements.
|
|
outputHashMode = if unpack || executable then "recursive" else "flat";
|
|
|
|
inherit
|
|
name
|
|
url
|
|
executable
|
|
unpack
|
|
;
|
|
|
|
system = "builtin";
|
|
|
|
# No need to double the amount of network traffic
|
|
preferLocalBuild = true;
|
|
|
|
impureEnvVars = [
|
|
# We borrow these environment variables from the caller to allow
|
|
# easy proxy configuration. This is impure, but a fixed-output
|
|
# derivation like fetchurl is allowed to do so since its result is
|
|
# by definition pure.
|
|
"http_proxy"
|
|
"https_proxy"
|
|
"ftp_proxy"
|
|
"all_proxy"
|
|
"no_proxy"
|
|
];
|
|
|
|
# To make "nix-prefetch-url" work.
|
|
urls = [ url ];
|
|
}
|
|
// (if impure then { __impure = true; } else { inherit outputHashAlgo outputHash; })
|
|
)
|