bind: disable seccomp by default

Fixes #25645 & #23431.

Changed files
+5 -3
pkgs
servers
dns
+5 -3
pkgs/servers/dns/bind/default.nix
···
{ stdenv, lib, fetchurl, openssl, libtool, perl, libxml2
-
, libseccomp ? null }:
let version = "9.10.4-P6"; in
···
stdenv.lib.optional stdenv.isDarwin ./darwin-openssl-linking-fix.patch;
buildInputs = [ openssl libtool perl libxml2 ] ++
-
stdenv.lib.optional stdenv.isLinux libseccomp;
STD_CDEFINES = [ "-DDIG_SIGCHASE=1" ]; # support +sigchase
···
"--without-pkcs11"
"--without-purify"
"--without-python"
-
] ++ lib.optional (stdenv.isi686 || stdenv.isx86_64) "--enable-seccomp";
postInstall = ''
moveToOutput bin/bind9-config $dev
···
{ stdenv, lib, fetchurl, openssl, libtool, perl, libxml2
+
, enableSeccomp ? false, libseccomp ? null }:
+
+
assert enableSeccomp -> libseccomp != null;
let version = "9.10.4-P6"; in
···
stdenv.lib.optional stdenv.isDarwin ./darwin-openssl-linking-fix.patch;
buildInputs = [ openssl libtool perl libxml2 ] ++
+
stdenv.lib.optional enableSeccomp libseccomp;
STD_CDEFINES = [ "-DDIG_SIGCHASE=1" ]; # support +sigchase
···
"--without-pkcs11"
"--without-purify"
"--without-python"
+
] ++ lib.optional enableSeccomp "--enable-seccomp";
postInstall = ''
moveToOutput bin/bind9-config $dev