Historically, Nix would support copying certificate authorities inside the sandbox so you could use them. In addition to that, the primitives consisting of leaking environment variables via `impureEnvVars` and `extra-sandbox-paths` to render paths external to the sandbox visible to the builder would also constitute a mechanism to expose special inodes which should have no influence on the output result, e.g. interception CAs. Unfortunately, in nixpkgs, `lib.fetchers.proxyImpureEnvVars` set `NIX_SSL_CERT_FILE` as an impure environment variable. A confused user may set `ssl-cert-file` via `NIX_SSL_CERT_FILE` outside the builder believing that this will set magically the right `NIX_SSL_CERT_FILE` inside the sandbox, but this is not true. The combination of impure environment variables and setting `caFile` creates a weird interaction where `NIX_SSL_CERT_FILE` points to an "outside the builder's world" inode *AND* `ssl-cert-file` creates this very same certificate file in /etc/ssl/certs/ca-certificates.crt without rewriting the environment variable. This footgun is closed by making these two features mutually incompatible with a warning and forcibly rewriting the SSL family of environment variables even if it was set via impure environment variables. Users who truly meant to use `impureEnvVars` can obtain the right behavior by setting `ssl-cert-file` to an empty string and will have to use `extra-sandbox-paths`. Users who meant to use `ssl-cert-file` will have everything work automatically with a warning hinting at nixpkgs *fixing its own bug*, i.e. passing `NIX_SSL_CERT_FILE` as an impure environment variable and expecting the Nix interpreter to magically reconcile the diverging values or expecting the user to actually do the work to render the path visible available via `extra-sandbox-paths`. Fixes #885. Change-Id: I32f8b5ce20fe9b6a911768114c92f95fc886cc07 Signed-off-by: Raito Bezarius <raito@lix.systems>
51 lines
1.9 KiB
Bash
51 lines
1.9 KiB
Bash
source common.sh
|
|
|
|
needLocalStore "the sandbox only runs on the builder side, so it makes no sense to test it with the daemon"
|
|
|
|
clearStore
|
|
|
|
requireSandboxSupport
|
|
|
|
# Note: we need to bind-mount $SHELL into the chroot. Currently we
|
|
# only support the case where $SHELL is in the Nix store, because
|
|
# otherwise things get complicated (e.g. if it's in /bin, do we need
|
|
# /lib as well?).
|
|
if [[ ! $SHELL =~ /nix/store ]]; then skipTest "Shell is not from Nix store"; fi
|
|
# An alias to automatically bind-mount the $SHELL on nix-build invocations
|
|
nix-sandbox-build () { nix-build --no-out-link --sandbox-paths /nix/store "$@"; }
|
|
|
|
chmod -R u+w $TEST_ROOT/store0 || true
|
|
rm -rf $TEST_ROOT/store0
|
|
|
|
export NIX_STORE_DIR=/my/store
|
|
export NIX_REMOTE=$TEST_ROOT/store0
|
|
|
|
outPath=$(nix-sandbox-build dependencies.nix)
|
|
|
|
[[ $outPath =~ /my/store/.*-dependencies ]]
|
|
|
|
nix path-info -r $outPath | grep input-2
|
|
|
|
nix store ls -R -l $outPath | grep foobar
|
|
|
|
nix store cat $outPath/foobar | grep FOOBAR
|
|
|
|
# Test --check without hash rewriting.
|
|
nix-sandbox-build dependencies.nix --check
|
|
|
|
# Test that sandboxed builds with --check and -K can move .check directory to store
|
|
nix-sandbox-build check.nix -A nondeterministic
|
|
|
|
# `100 + 4` means non-determinstic, see doc/manual/src/command-ref/status-build-failure.md
|
|
expectStderr 104 nix-sandbox-build check.nix -A nondeterministic --check -K > $TEST_ROOT/log
|
|
grepQuietInverse 'error: renaming' $TEST_ROOT/log
|
|
grepQuiet 'may not be deterministic' $TEST_ROOT/log
|
|
|
|
# Test that sandboxed builds cannot write to /etc easily
|
|
# `100` means build failure without extra info, see doc/manual/src/command-ref/status-build-failure.md
|
|
expectStderr 100 nix-sandbox-build -E 'with import ./config.nix; mkDerivation { name = "etc-write"; buildCommand = "echo > /etc/test"; }' |
|
|
grepQuiet "/etc/test: Permission denied"
|
|
|
|
# Symlinks should be added in the sandbox directly and not followed
|
|
nix-sandbox-build symlink-derivation.nix
|