devshells.nix (2194B)
1 # modules/features/pentest/devshells.nix — the toolkit without installing it, 2 # and one check that the whole thing can coexist in a single profile. 3 # 4 # nix develop ~/NixDaemon#pentest every category, on PATH, temporarily 5 # nix develop ~/NixDaemon#pentest-ad one category (mkCategory makes these) 6 # nix develop github:…/NixDaemon#pentest the same kit on any machine with Nix 7 # 8 # The per-category shells come from _sets.nix. This file adds the union, and 9 # `checks.pentest-collisions`. 10 # 11 # Why that check exists: environment.systemPackages merges everything into ONE 12 # profile with buildEnv, so two packages owning the same bin/ name is a hard 13 # failure that stops the system building. The toplevel build catches it only 14 # for the categories that are ENABLED — dfir, reversing, wireless, cloud, 15 # osint and mobile ship off, so a collision in one of them would lie dormant 16 # until the day you enabled it mid-engagement. This merges all of them, 17 # enabled or not. It is how `pwntools` shipping bin/checksec alongside the 18 # standalone `checksec` package was caught. 19 { self, ... }: 20 { 21 perSystem = 22 { pkgs, lib, ... }: 23 let 24 sets = self.lib.pentestPackages or { }; 25 # Only what builds on this system: on aarch64-linux a few tools are 26 # x86-only. On x86_64 nothing is dropped. 27 allPackages = builtins.filter (lib.meta.availableOn pkgs.stdenv.hostPlatform) ( 28 lib.concatMap (f: f pkgs) (lib.attrValues sets) 29 ); 30 names = lib.attrNames sets; 31 in 32 { 33 devShells.pentest = pkgs.mkShell { 34 name = "pentest"; 35 packages = allPackages; 36 shellHook = '' 37 echo "pentest: ${toString (lib.length names)} categories — ${lib.concatStringsSep " " names}" 38 echo " \$WORDLISTS and \$PAYLOADS are only set on the installed system," 39 echo " not in this shell; use \$(nix build ..#checks..) paths if you need them." 40 ''; 41 }; 42 43 checks.pentest-collisions = pkgs.buildEnv { 44 name = "pentest-collisions-check"; 45 paths = allPackages; 46 # The default (false) is the point: a clash fails this derivation. 47 ignoreCollisions = false; 48 }; 49 }; 50 }