diff --git a/doc/manual/change-authors.yml b/doc/manual/change-authors.yml index 2f9fddf33..da7e58023 100644 --- a/doc/manual/change-authors.yml +++ b/doc/manual/change-authors.yml @@ -36,6 +36,9 @@ Qyriad: SharzyL: github: SharzyL +WeetHet: + forgejo: WeetHet + alois31: forgejo: alois31 github: alois31 diff --git a/doc/manual/rl-next/darwin-ca-certs-sandbox.md b/doc/manual/rl-next/darwin-ca-certs-sandbox.md new file mode 100644 index 000000000..28d7578c7 --- /dev/null +++ b/doc/manual/rl-next/darwin-ca-certs-sandbox.md @@ -0,0 +1,11 @@ +--- +synopsis: "Fix CA certificates access in macOS sandboxed builds" +cls: [2869] +category: Fixes +credits: [WeetHet] +--- + +Fixed an issue on macOS where fixed-output derivations that needed network access could not access the CA certificate. +The sandbox profile now explicitly allows access to the configured CA file when a fixed output derivation is built. + +This fixes `pkgs.fetchgit`, `fetchCargoVendor` and many others when run with `sandbox = true` diff --git a/lix/libstore/build/local-derivation-goal.cc b/lix/libstore/build/local-derivation-goal.cc index d1e1f2cfb..4935303b8 100644 --- a/lix/libstore/build/local-derivation-goal.cc +++ b/lix/libstore/build/local-derivation-goal.cc @@ -1831,10 +1831,14 @@ void LocalDerivationGoal::runChild() #include "sandbox-defaults.sb" ; - if (!derivationType->isSandboxed()) + if (!derivationType->isSandboxed()) { sandboxProfile += #include "sandbox-network.sb" ; + if (settings.caFile != "") { + sandboxProfile += fmt("(allow file-read* %s)\n", settings.caFile); + } + } /* Add the output paths we'll use at build-time to the chroot */ sandboxProfile += "(allow file-read* file-write* process-exec\n";