aboutsummaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorJude Taylor <me@jude.bio>2015-11-14 13:52:33 -0800
committerJude Taylor <me@jude.bio>2015-11-14 14:11:03 -0800
commit4876bb012e78e6e397f34fd7fb91f67520cbd744 (patch)
tree8d73becfd9ae25f6f2039fc98c2bd01018bff98d /src
parentd760c2638c9e1f4b8cd9b4ec90d68bf0c76a800b (diff)
simplify build permissions
Diffstat (limited to 'src')
-rw-r--r--src/libstore/build.cc16
1 files changed, 3 insertions, 13 deletions
diff --git a/src/libstore/build.cc b/src/libstore/build.cc
index 5cd695b1c..32325a6b1 100644
--- a/src/libstore/build.cc
+++ b/src/libstore/build.cc
@@ -2498,13 +2498,8 @@ void DerivationGoal::runChild()
}
sandboxProfile += ")\n";
- /* Our inputs (transitive dependencies and any impurities computed above)
- Note that the sandbox profile allows file-write* even though it isn't seemingly necessary. First of all, nix's standard user permissioning
- mechanism still prevents builders from writing to input directories, so no security/purity is lost. The reason we allow file-write* is that
- denying it means the `access` syscall will return EPERM instead of EACCESS, which confuses a few programs that assume (understandably, since
- it appears to be a violation of the POSIX spec) that `access` won't do that, and don't deal with it nicely if it does. The most notable of
- these is the entire GHC Haskell ecosystem. */
- sandboxProfile += "(allow file-read* file-write* process-exec mach-priv-task-port\n";
+ /* Our inputs (transitive dependencies and any impurities computed above) */
+ sandboxProfile += "(allow file-read* process-exec\n";
for (auto & i : dirsInChroot) {
if (i.first != i.second)
throw SysError(format("can't map '%1%' to '%2%': mismatched impure paths not supported on darwin"));
@@ -2520,12 +2515,7 @@ void DerivationGoal::runChild()
}
sandboxProfile += ")\n";
- /* Our ancestry. N.B: this uses literal on folders, instead of subpath. Without that,
- you open up the entire filesystem because you end up with (subpath "/")
- Note: file-read-metadata* is not sufficiently permissive for GHC. file-read* is but may
- be a security hazard.
- TODO: figure out a more appropriate directive.
- */
+ /* Allow file-read* on full directory hierarchy to self. Allows realpath() */
sandboxProfile += "(allow file-read*\n";
for (auto & i : ancestry) {
sandboxProfile += (format("\t(literal \"%1%\")\n") % i.c_str()).str();