1
1
Fork 0
mirror of https://github.com/NixOS/nix.git synced 2025-12-05 16:41:01 +01:00
nix/src
Andrew Marshall 7043e7311f libstore: fix port binding in __darwinAllowLocalNetworking sandbox
In d60c3f7f7c, this was changed to close a
hole in the sandbox. Unfortunately, this was too restrictive such that it
made local port binding fail, thus making derivations that needed
`__darwinAllowLocalNetworking` gain nearly nothing, and thus largely
fail (as the primary use for it is to enable port binding).

This unfortunately does mean that a sandboxed build process can, in
coordination with an actor outside the sandbox, escape the sandbox by
binding a port and connecting to it externally to send data. I do not
see a way around this with my experimentation and understanding of the
(quite undocumented) macOS sandbox profile API. Notably it seems not
possible to use the sandbox to do any of:

- Restrict the remote IP of inbound network requests
- Restrict the address being bound to

As such, the `(local ip "*:*")` here appears to be functionally no
different than `(local ip "localhost:*")` (however it *should* be
different than removing the filter entirely, as that would make it also
apply to non-IP networking). Doing `(allow network-inbound (require-all
(local ip "localhost:*") (remote ip "localhost:*")))` causes listening
to fail.

Note that `network-inbound` implies `network-bind`.

(cherry picked from commit 00f6db36fd)
2024-08-17 03:17:40 +00:00
..
build-remote Pathlocks Implementation for Windows (#10586) 2024-04-22 15:08:10 +00:00
libcmd nix repl: make runNix() isInteractive is true by default 2024-05-30 19:15:37 +02:00
libexpr Merge pull request #10573 from RCoeurjoly/Rename_SearchPath 2024-04-21 17:33:46 +02:00
libexpr-c C API: Add nix_init_apply 2024-04-18 19:13:38 +02:00
libfetchers Show when we're unpacking an archive into the Git cache 2024-07-29 13:02:55 +00:00
libmain init: Add flag to avoid loading configuration 2024-04-20 01:45:04 +02:00
libstore libstore: fix port binding in __darwinAllowLocalNetworking sandbox 2024-08-17 03:17:40 +00:00
libstore-c init: Add flag to avoid loading configuration 2024-04-20 01:45:04 +02:00
libutil Formatting 2024-06-21 17:16:48 +02:00
libutil-c C API: Use nix_get_string_callback typedef 2024-04-15 12:05:57 +02:00
nix Use proper struct sockpeercred for SO_PEERCRED for OpenBSD 2024-07-03 15:57:13 +00:00
nix-build Merge remote-tracking branch 'origin/master' into finish-value 2024-04-17 16:02:44 +02:00
nix-channel downloadFile(): Remove the "locked" (aka "immutable") flag 2024-04-08 15:56:16 +02:00
nix-collect-garbage Split up util.{hh,cc} 2023-11-05 12:20:02 -05:00
nix-copy-closure Restrict some code to StoreDirConfig 2023-11-04 19:05:36 -04:00
nix-env Build a minimized Nix with MinGW 2024-04-17 12:26:10 -04:00
nix-instantiate Build a minimized Nix with MinGW 2024-04-17 12:26:10 -04:00
nix-store Build a minimized Nix with MinGW 2024-04-17 12:26:10 -04:00
toml11 Replace cpptoml with toml11 2021-12-17 22:03:33 +01:00