mirror of
https://github.com/NixOS/nix
synced 2025-07-07 10:11:47 +02:00
Add release notes
Co-authored-by: Theophane Hufschmitt <theophane.hufschmitt@tweag.io>
This commit is contained in:
parent
4bc5a3510f
commit
9e7065bef5
1 changed files with 8 additions and 0 deletions
|
@ -1 +1,9 @@
|
||||||
# Release X.Y (202?-??-??)
|
# Release X.Y (202?-??-??)
|
||||||
|
|
||||||
|
- Fix a FOD sandbox escape:
|
||||||
|
Cooperating Nix derivations could send file descriptors to files in the Nix
|
||||||
|
store to each other via Unix domain sockets in the abstract namespace. This
|
||||||
|
allowed one derivation to modify the output of the other derivation, after Nix
|
||||||
|
has registered the path as "valid" and immutable in the Nix database.
|
||||||
|
In particular, this allowed the output of fixed-output derivations to be
|
||||||
|
modified from their expected content. This isn't the case any more.
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue