NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

devshells.nix (2194B)


      1 # modules/features/pentest/devshells.nix — the toolkit without installing it,
      2 # and one check that the whole thing can coexist in a single profile.
      3 #
      4 #   nix develop ~/NixDaemon#pentest          every category, on PATH, temporarily
      5 #   nix develop ~/NixDaemon#pentest-ad       one category (mkCategory makes these)
      6 #   nix develop github:…/NixDaemon#pentest   the same kit on any machine with Nix
      7 #
      8 # The per-category shells come from _sets.nix. This file adds the union, and
      9 # `checks.pentest-collisions`.
     10 #
     11 # Why that check exists: environment.systemPackages merges everything into ONE
     12 # profile with buildEnv, so two packages owning the same bin/ name is a hard
     13 # failure that stops the system building. The toplevel build catches it only
     14 # for the categories that are ENABLED — dfir, reversing, wireless, cloud,
     15 # osint and mobile ship off, so a collision in one of them would lie dormant
     16 # until the day you enabled it mid-engagement. This merges all of them,
     17 # enabled or not. It is how `pwntools` shipping bin/checksec alongside the
     18 # standalone `checksec` package was caught.
     19 { self, ... }:
     20 {
     21   perSystem =
     22     { pkgs, lib, ... }:
     23     let
     24       sets = self.lib.pentestPackages or { };
     25       # Only what builds on this system: on aarch64-linux a few tools are
     26       # x86-only. On x86_64 nothing is dropped.
     27       allPackages = builtins.filter (lib.meta.availableOn pkgs.stdenv.hostPlatform) (
     28         lib.concatMap (f: f pkgs) (lib.attrValues sets)
     29       );
     30       names = lib.attrNames sets;
     31     in
     32     {
     33       devShells.pentest = pkgs.mkShell {
     34         name = "pentest";
     35         packages = allPackages;
     36         shellHook = ''
     37           echo "pentest: ${toString (lib.length names)} categories — ${lib.concatStringsSep " " names}"
     38           echo "  \$WORDLISTS and \$PAYLOADS are only set on the installed system,"
     39           echo "  not in this shell; use \$(nix build ..#checks..) paths if you need them."
     40         '';
     41       };
     42 
     43       checks.pentest-collisions = pkgs.buildEnv {
     44         name = "pentest-collisions-check";
     45         paths = allPackages;
     46         # The default (false) is the point: a clash fails this derivation.
     47         ignoreCollisions = false;
     48       };
     49     };
     50 }