mirror of
https://github.com/NixOS/nix.git
synced 2025-11-08 19:46:02 +01:00
If a build directory is accessible to other users it is possible to smuggle data in and out of build directories. Usually this is only a build purity problem, but in combination with other issues it can be used to break out of a build sandbox. to prevent this we default to using a subdirectory of nixStateDir (which is more restrictive). (cherry picked from pennae Lix commit 55b416f6897fb0d8a9315a530a9b7f0914458ded) (store setting done by roberth) |
||
|---|---|---|
| .. | ||
| build-dir-mandatory.md | ||
| config | ||
| deprecate__json.md | ||
| eval-profiler.md | ||
| json-logger.md | ||
| nix-profile-add.md | ||
| outpath-and-sourceinfo-fixes.md | ||
| revert-77.md | ||