Skip to content
Snippets Groups Projects
  1. May 11, 2017
  2. May 10, 2017
  3. May 08, 2017
  4. May 05, 2017
  5. May 04, 2017
    • Eelco Dolstra's avatar
      Linux sandbox: Use /build instead of /tmp as $TMPDIR · eba840c8
      Eelco Dolstra authored
      There is a security issue when a build accidentally stores its $TMPDIR
      in some critical place, such as an RPATH. If
      TMPDIR=/tmp/nix-build-..., then any user on the system can recreate
      that directory and inject libraries into the RPATH of programs
      executed by other users. Since /build probably doesn't exist (or isn't
      world-writable), this mitigates the issue.
      eba840c8
    • Eelco Dolstra's avatar
      nix dump-path: Add · 2da6a424
      Eelco Dolstra authored
      This is primarily useful for extracting NARs from other stores (like
      binary caches), which "nix-store --dump" cannot do.
      2da6a424
  6. May 03, 2017
  7. May 02, 2017
  8. May 01, 2017
Loading