From 692de16113390988f0dc82eb650ec12779958a20 Mon Sep 17 00:00:00 2001 From: WeetHet Date: Fri, 21 Mar 2025 22:46:24 +0200 Subject: [PATCH] fix: allow access to ca-certs in FODs on darwin Change-Id: Id955be88eb5d419d57262d5983841a1e6accee9f --- doc/manual/change-authors.yml | 3 +++ doc/manual/rl-next/darwin-ca-certs-sandbox.md | 11 +++++++++++ lix/libstore/build/local-derivation-goal.cc | 6 +++++- 3 files changed, 19 insertions(+), 1 deletion(-) create mode 100644 doc/manual/rl-next/darwin-ca-certs-sandbox.md diff --git a/doc/manual/change-authors.yml b/doc/manual/change-authors.yml index 2f9fddf33..da7e58023 100644 --- a/doc/manual/change-authors.yml +++ b/doc/manual/change-authors.yml @@ -36,6 +36,9 @@ Qyriad: SharzyL: github: SharzyL +WeetHet: + forgejo: WeetHet + alois31: forgejo: alois31 github: alois31 diff --git a/doc/manual/rl-next/darwin-ca-certs-sandbox.md b/doc/manual/rl-next/darwin-ca-certs-sandbox.md new file mode 100644 index 000000000..28d7578c7 --- /dev/null +++ b/doc/manual/rl-next/darwin-ca-certs-sandbox.md @@ -0,0 +1,11 @@ +--- +synopsis: "Fix CA certificates access in macOS sandboxed builds" +cls: [2869] +category: Fixes +credits: [WeetHet] +--- + +Fixed an issue on macOS where fixed-output derivations that needed network access could not access the CA certificate. +The sandbox profile now explicitly allows access to the configured CA file when a fixed output derivation is built. + +This fixes `pkgs.fetchgit`, `fetchCargoVendor` and many others when run with `sandbox = true` diff --git a/lix/libstore/build/local-derivation-goal.cc b/lix/libstore/build/local-derivation-goal.cc index 869cecec3..27bc442bf 100644 --- a/lix/libstore/build/local-derivation-goal.cc +++ b/lix/libstore/build/local-derivation-goal.cc @@ -1831,10 +1831,14 @@ void LocalDerivationGoal::runChild() #include "sandbox-defaults.sb" ; - if (!derivationType->isSandboxed()) + if (!derivationType->isSandboxed()) { sandboxProfile += #include "sandbox-network.sb" ; + if (settings.caFile != "") { + sandboxProfile += fmt("(allow file-read* %s)\n", settings.caFile); + } + } /* Add the output paths we'll use at build-time to the chroot */ sandboxProfile += "(allow file-read* file-write* process-exec\n";