c493fb668ef4e7f5d86fba3eb12e2effa0159c63
Two things happens here: - we consider supplementary groups that are known for authentication, fixes #968. - we check supplementary groups if they are our build users group and throw an error if they are (new behavior). Nonetheless, we did not remove the ability for `matchUser` to recurse and check for groups that the user may have but the connection might not have communicated as part of their groups, i.e. if a process reduces its list of groups via a call to setgroups, it will still be authorized. This will come in another commit. The authorization NixOS test has been extended with a store ping test running in systemd with DynamicUser=true *AND* a supplementary group in allowed-users. Co-authored-by: Tom Hubrecht <github@mail.hubrecht.ovh> Change-Id: I25b2b8304d66a04651cea523b5585a5d15ceebe8 Signed-off-by: Raito Bezarius <raito@lix.systems>
Lix
Lix is an implementation of Nix, a powerful package management system for Linux and other Unix systems that makes package management reliable and reproducible.
Read more about us at https://lix.systems.
Installation
On Linux and macOS the easiest way to install Lix is to run the following shell command (as a user other than root):
$ curl -sSf -L https://install.lix.systems/lix | sh -s -- install
For systems that already have a Nix implementation installed, such as NixOS systems, read our install page
Building And Developing
See our Hacking guide in our manual for instruction on how to set up a development environment and build Lix from source.
Additional Resources
- The Lix reference manual:
- Our wiki
- Matrix - #space:lix.systems
License
Lix is released under LGPL-2.1-or-later.
Description
Working fork of Lix - carries the adaptive load-aware build-remote patch. Upstream: gerrit.lix.systems
92 MiB
Languages
C++
74.9%
Python
11.7%
Nix
6.1%
Shell
3.6%
Meson
2%
Other
1.6%