mirror of
https://github.com/NixOS/nix
synced 2025-06-25 10:41:16 +02:00
If a build directory is accessible to other users it is possible to smuggle data in and out of build directories. Usually this is only a build purity problem, but in combination with other issues it can be used to break out of a build sandbox. to prevent this we default to using a subdirectory of nixStateDir (which is more restrictive). (cherry picked from pennae Lix commit 55b416f6897fb0d8a9315a530a9b7f0914458ded) (store setting done by roberth) |
||
---|---|---|
.. | ||
rl-next | ||
source | ||
theme | ||
.version | ||
anchors.jq | ||
book.toml.in | ||
custom.css | ||
generate-builtins.nix | ||
generate-deps.py | ||
generate-manpage.nix | ||
generate-settings.nix | ||
generate-store-info.nix | ||
generate-store-types.nix | ||
generate-xp-features-shortlist.nix | ||
generate-xp-features.nix | ||
meson.build | ||
package.nix | ||
quote-literals.xsl | ||
redirects.js | ||
remove_before_wrapper.py | ||
render-manpage.sh | ||
substitute.py | ||
utils.nix |