1
0
Fork 0
mirror of https://github.com/NixOS/nix synced 2025-06-27 04:21:16 +02:00

* Disallow the Nix store or any of its parents from being symlinks.

This is because the contents of these symlinks are not incorporated
  into the hashes of derivations, and could therefore cause a mismatch
  between the build system and the target system.  E.g., if
  `/nix/store' is a symlink to `/data/nix/store', then a builder could
  expand this path and store the result.  If on the target system
  `/nix/store' is not a symlink, or is a symlink that points somewhere
  else, we have a dangling pointer.

  The trigger for this change is that gcc 3.3.3 does exactly that (it
  applies realpath() to some files, such as libraries, which causes
  our impurity checker to bail out.)

  An annoying side-effect of this change is that it makes it harder to
  move the Nix store to a different file system.  On Linux, bind
  mounts can be used instead of symlink for this purpose (e.g., `mount
  -o bind /data/nix/store /nix/store').
This commit is contained in:
Eelco Dolstra 2004-03-27 17:58:04 +00:00
parent f0f7a9f299
commit f8cd904e05
2 changed files with 37 additions and 11 deletions

View file

@ -1,7 +1,10 @@
#include <iostream>
#include <cctype>
#include <sys/types.h>
#include <sys/stat.h>
#include <unistd.h>
extern "C" {
#include <aterm2.h>
}
@ -27,6 +30,22 @@ void setLogType(string lt)
}
void checkStoreNotSymlink(Path path)
{
struct stat st;
while (path.size()) {
if (lstat(path.c_str(), &st))
throw SysError(format("getting status of `%1%'") % path);
if (S_ISLNK(st.st_mode))
throw Error(format(
"the path `%1%' is a symlink; "
"this is not allowed for the Nix store and its parent directories")
% path);
path = dirOf(path);
}
}
/* Initialize and reorder arguments, then call the actual argument
processor. */
static void initAndRun(int argc, char * * argv)
@ -39,11 +58,15 @@ static void initAndRun(int argc, char * * argv)
}
/* Setup Nix paths. */
nixStore = NIX_STORE_DIR;
nixDataDir = NIX_DATA_DIR;
nixLogDir = NIX_LOG_DIR;
nixStateDir = (string) NIX_STATE_DIR;
nixDBPath = (string) NIX_STATE_DIR + "/db";
nixStore = canonPath(NIX_STORE_DIR);
nixDataDir = canonPath(NIX_DATA_DIR);
nixLogDir = canonPath(NIX_LOG_DIR);
nixStateDir = canonPath(NIX_STATE_DIR);
nixDBPath = canonPath(NIX_STATE_DIR) + "/db";
/* Check that the store directory and its parent are not
symlinks. */
checkStoreNotSymlink(nixStore);
/* Catch SIGINT. */
struct sigaction act, oact;