libstore: fallback on creating a safe space in the default tempdir
If `settings.buildDir` cannot be written to, because we are in a chroot store, unprivileged or anything. We can and should always gracefully fallback to a *secure* location inside of /tmp, i.e. `/tmp/<a directory under 0700>/<our temporary directory for build under 0700>/...`. This does not reintroduce CVE-2025-52991 because we are creating a directory in-between compared to creating only ONE level of directory. Under macOS, the first level of directory has actually mode 0755 instead of 0700 as macOS often do not possess the right primitives to chroot inside of these directories, leading to https://github.com/NixOS/nix/pull/11031. Thanks to Emily for the heads-up on this type of matter. Fixes #876. Change-Id: Ie521202923f763225e1901ab1b9b6c6132aaf548 Signed-off-by: Raito Bezarius <raito@lix.systems>
This commit is contained in:
@@ -475,17 +475,47 @@ void LocalDerivationGoal::startBuilder()
|
||||
settings.thisSystem,
|
||||
concatStringsSep<StringSet>(", ", worker.store.systemFeatures));
|
||||
|
||||
createDirs(settings.buildDir.get());
|
||||
try {
|
||||
auto buildDir = worker.buildDirOverride.value_or(settings.buildDir.get());
|
||||
|
||||
/* Create a temporary directory where the build will take
|
||||
place. */
|
||||
tmpDir = createTempDir(
|
||||
settings.buildDir.get(),
|
||||
"nix-build-" + std::string(drvPath.name()),
|
||||
false,
|
||||
false,
|
||||
0700
|
||||
);
|
||||
createDirs(buildDir);
|
||||
|
||||
/* Create a temporary directory where the build will take
|
||||
place. */
|
||||
tmpDir =
|
||||
createTempDir(buildDir, "nix-build-" + std::string(drvPath.name()), false, false, 0700);
|
||||
} catch (SysError & e) {
|
||||
/*
|
||||
* Fallback to the global tmpdir and create a safe space there
|
||||
* only if it's a permission error.
|
||||
*/
|
||||
if (e.errNo != EACCES) {
|
||||
throw;
|
||||
}
|
||||
|
||||
auto globalTmp = defaultTempDir();
|
||||
createDirs(globalTmp);
|
||||
#if __APPLE__
|
||||
/* macOS filesystem namespacing does not exist, to avoid breaking builds, we need to weaken
|
||||
* the mode bits on the top-level directory. This avoids issues like
|
||||
* https://github.com/NixOS/nix/pull/11031. */
|
||||
constexpr int toplevelDirMode = 0755;
|
||||
#else
|
||||
constexpr int toplevelDirMode = 0700;
|
||||
#endif
|
||||
auto nixBuildsTmp =
|
||||
createTempDir(globalTmp, fmt("nix-builds-%s", geteuid()), false, false, toplevelDirMode);
|
||||
warn(
|
||||
"Failed to use the system-wide build directory '%s', falling back to a temporary "
|
||||
"directory inside '%s'",
|
||||
settings.buildDir.get(),
|
||||
nixBuildsTmp
|
||||
);
|
||||
worker.buildDirOverride = nixBuildsTmp;
|
||||
tmpDir = createTempDir(
|
||||
nixBuildsTmp, "nix-build-" + std::string(drvPath.name()), false, false, 0700
|
||||
);
|
||||
}
|
||||
/* The TOCTOU between the previous mkdir call and this open call is unavoidable due to
|
||||
* POSIX semantics.*/
|
||||
tmpDirFd = AutoCloseFD{open(tmpDir.c_str(), O_RDONLY | O_NOFOLLOW | O_DIRECTORY)};
|
||||
|
||||
@@ -161,6 +161,7 @@ public:
|
||||
|
||||
Store & store;
|
||||
Store & evalStore;
|
||||
std::optional<Path> buildDirOverride;
|
||||
|
||||
struct HookState {
|
||||
std::unique_ptr<HookInstance> instance;
|
||||
|
||||
Reference in New Issue
Block a user