diff --git a/doc/manual/change-authors.yml b/doc/manual/change-authors.yml index da7e58023..2f9fddf33 100644 --- a/doc/manual/change-authors.yml +++ b/doc/manual/change-authors.yml @@ -36,9 +36,6 @@ Qyriad: SharzyL: github: SharzyL -WeetHet: - forgejo: WeetHet - alois31: forgejo: alois31 github: alois31 diff --git a/doc/manual/rl-next/darwin-ca-certs-sandbox.md b/doc/manual/rl-next/darwin-ca-certs-sandbox.md deleted file mode 100644 index 28d7578c7..000000000 --- a/doc/manual/rl-next/darwin-ca-certs-sandbox.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -synopsis: "Fix CA certificates access in macOS sandboxed builds" -cls: [2869] -category: Fixes -credits: [WeetHet] ---- - -Fixed an issue on macOS where fixed-output derivations that needed network access could not access the CA certificate. -The sandbox profile now explicitly allows access to the configured CA file when a fixed output derivation is built. - -This fixes `pkgs.fetchgit`, `fetchCargoVendor` and many others when run with `sandbox = true` diff --git a/lix/libstore/build/local-derivation-goal.cc b/lix/libstore/build/local-derivation-goal.cc index 4935303b8..d1e1f2cfb 100644 --- a/lix/libstore/build/local-derivation-goal.cc +++ b/lix/libstore/build/local-derivation-goal.cc @@ -1831,14 +1831,10 @@ void LocalDerivationGoal::runChild() #include "sandbox-defaults.sb" ; - if (!derivationType->isSandboxed()) { + if (!derivationType->isSandboxed()) sandboxProfile += #include "sandbox-network.sb" ; - if (settings.caFile != "") { - sandboxProfile += fmt("(allow file-read* %s)\n", settings.caFile); - } - } /* Add the output paths we'll use at build-time to the chroot */ sandboxProfile += "(allow file-read* file-write* process-exec\n";