Merge "libexpr: fix checkSourcePath purity regression" into release-2.92

This commit is contained in:
jade
2025-03-17 17:58:29 +00:00
committed by Lix Systems Gerrit
3 changed files with 20 additions and 0 deletions
@@ -0,0 +1,15 @@
---
synopsis: Forbid impure path accesses in pure evaluation mode again
category: Fixes
cls: [2708]
credits: [alois31]
---
Lix 2.92.0 mistakenly started allowing the access to ancestors of allowed paths in pure evaluation mode.
This made it possible to bypass the purity restrictions, for example by copying arbitrary files to the store:
```nix
builtins.path {
path = "/";
filter = ;
}
```
Restore the previous behaviour of prohibiting such impure accesses.
+4
View File
@@ -459,6 +459,10 @@ retry:
}
current = std::move(next);
}
// Downstream users (e.g. `builtins.readDir` or `builtins.path`) will want to descend.
if (level && !level->allowAllChildren) {
goto failed;
}
resolvedPaths.insert_or_assign(path_.canonical().abs(), current);
return current;
+1
View File
@@ -18,6 +18,7 @@ echo "$missingImpureErrorMsg" | grepQuiet -- --impure || \
(! nix eval --expr builtins.currentSystem)
(! nix-instantiate --pure-eval ./simple.nix)
(! nix eval --expr 'builtins.readDir "/"')
[[ $(nix eval --impure --expr "(import (builtins.fetchurl { url = \"file://$(pwd)/pure-eval.nix\"; })).x") == 123 ]]
(! nix eval --expr "(import (builtins.fetchurl { url = \"file://$(pwd)/pure-eval.nix\"; })).x")