summaryrefslogtreecommitdiffstats
path: root/pkgs/misc/signed-packages/default.nix
blob: 248eb703d9483df9ad861a06d99c017135887fcc (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
let
  autoCalledPackages = import ../../top-level/by-name-overlay.nix ./by-name;
in

{
  lib,
  newScope,
}:

{
  uefiSigningKey,
  uefiCertificate,
}:

let
  inherit (lib)
    extends
    functionArgs
    isFunction
    makeScope
    setFunctionArgs
    ;
in

makeScope newScope (
  self:
  let
    # This allows packages in this scope to take `uefiSigningKey` as an
    # argument without leaking it outside of the scope.
    withSigningKey =
      fn:
      let
        f = if isFunction fn then fn else import fn;
        fArgs = functionArgs f;
      in
      if fArgs ? uefiSigningKey then
        setFunctionArgs (args: f (args // { inherit uefiSigningKey; })) (
          removeAttrs fArgs [ "uefiSigningKey" ]
        )
      else
        f;

    private =
      extends autoCalledPackages
        (_self: {
          inherit uefiCertificate;
        })
        (
          private
          // self
          // {
            callPackage =
              assert self.uefiCertificate.verificationKey == uefiSigningKey.verificationKey;
              fn: self.callPackage (withSigningKey fn);
          }
        );
  in
  removeAttrs private [
    "_internalCallByNamePackageFile"
    "callPackage"
  ]
)