Skip to content

Commit

Permalink
Merge pull request #10971 from NixOS/user-sandbox-escape-post
Browse files Browse the repository at this point in the history
Slight fixes to get CI passing again
Ericson2314 authored Jun 27, 2024

Verified

This commit was signed with the committer’s verified signature.
hannojg Hanno J. Gödecke
2 parents 2dd7f8f + 88f9d8c commit ed12926
Showing 2 changed files with 1 addition and 1 deletion.
1 change: 0 additions & 1 deletion doc/manual/rl-next/harden-user-sandboxing.md
Original file line number Diff line number Diff line change
@@ -2,7 +2,6 @@
synopsis: Harden the user sandboxing
significance: significant
issues:
prs: <only provided once merged>
---

The build directory has been hardened against interference with the outside world by nesting it inside another directory owned by (and only readable by) the daemon user.
1 change: 1 addition & 0 deletions maintainers/flake-module.nix
Original file line number Diff line number Diff line change
@@ -429,6 +429,7 @@
''^tests/functional/test-libstoreconsumer/main\.cc''
''^tests/nixos/ca-fd-leak/sender\.c''
''^tests/nixos/ca-fd-leak/smuggler\.c''
''^tests/nixos/user-sandboxing/attacker\.c''
''^tests/unit/libexpr-support/tests/libexpr\.hh''
''^tests/unit/libexpr-support/tests/value/context\.cc''
''^tests/unit/libexpr-support/tests/value/context\.hh''

0 comments on commit ed12926

Please sign in to comment.