Starting with commit0dbfa7b26eaccess would also be allowed to ancestors of allowed paths. This is (ironically) a significant purity regression, since several users of the purity checks will themselves assume that arbitrary descent is allowed. For example, `builtins.readDir` and `builtins.path` could now refer to the filesystem root, breaking purity entirely in the latter case by allowing to read arbitrary files. Restore the previous behaviour of only allowing access to explicitly allowed paths. Change-Id: Ie64180733ab735da9873255e1ccbf95ba7c9161c (cherry picked from commit9d99a7c2cf)
36 lines
1.4 KiB
Bash
36 lines
1.4 KiB
Bash
source common.sh
|
|
|
|
clearStore
|
|
|
|
nix eval --expr 'assert 1 + 2 == 3; true'
|
|
|
|
[[ $(nix eval --impure --expr 'builtins.readFile ./pure-eval.sh') =~ clearStore ]]
|
|
|
|
missingImpureErrorMsg=$(! nix eval --expr 'builtins.readFile ./pure-eval.sh' 2>&1)
|
|
|
|
echo "$missingImpureErrorMsg" | grepQuiet -- --impure || \
|
|
fail "The error message should mention the “--impure” flag to unblock users"
|
|
|
|
[[ $(nix eval --expr 'builtins.pathExists ./pure-eval.sh') == false ]] || \
|
|
fail "Calling 'pathExists' on a non-authorised path should return false"
|
|
|
|
(! nix eval --expr builtins.currentTime)
|
|
(! nix eval --expr builtins.currentSystem)
|
|
|
|
(! nix-instantiate --pure-eval ./simple.nix)
|
|
(! nix eval --expr 'builtins.readDir "/"')
|
|
|
|
[[ $(nix eval --impure --expr "(import (builtins.fetchurl { url = \"file://$(pwd)/pure-eval.nix\"; })).x") == 123 ]]
|
|
(! nix eval --expr "(import (builtins.fetchurl { url = \"file://$(pwd)/pure-eval.nix\"; })).x")
|
|
nix eval --expr "(import (builtins.fetchurl { url = \"file://$(pwd)/pure-eval.nix\"; sha256 = \"$(nix hash file pure-eval.nix --type sha256)\"; })).x"
|
|
|
|
rm -rf $TEST_ROOT/eval-out
|
|
nix eval --store dummy:// --write-to $TEST_ROOT/eval-out --expr '{ x = "foo" + "bar"; y = { z = "bla"; }; }'
|
|
[[ $(cat $TEST_ROOT/eval-out/x) = foobar ]]
|
|
[[ $(cat $TEST_ROOT/eval-out/y/z) = bla ]]
|
|
|
|
rm -rf $TEST_ROOT/eval-out
|
|
(! nix eval --store dummy:// --write-to $TEST_ROOT/eval-out --expr '{ "." = "bla"; }')
|
|
|
|
(! nix eval --expr '~/foo')
|