lix-releng-staging/src
Eelco Dolstra 6cc6c15a2d
Add a seccomp filter to prevent creating setuid/setgid binaries
This prevents builders from setting the S_ISUID or S_ISGID bits,
preventing users from using a nixbld* user to create a setuid/setgid
binary to interfere with subsequent builds under the same nixbld* uid.

This is based on aszlig's seccomp code
(47f587700d).

Reported by Linus Heckemann.
2017-05-29 16:14:10 +02:00
..
boost Shut up some warnings 2017-04-14 14:42:20 +02:00
build-remote build-remote: Check remote build status 2017-05-08 14:27:12 +02:00
buildenv Fix Fedora build 2016-08-30 13:56:22 +02:00
libexpr builtins.match: Improve error message for bad regular expression 2017-05-17 11:58:01 +02:00
libmain Factor out --json 2017-04-24 14:21:36 +02:00
libstore Add a seccomp filter to prevent creating setuid/setgid binaries 2017-05-29 16:14:10 +02:00
libutil Fix build failure on Debian/Ubuntu 2017-05-29 15:59:18 +02:00
linenoise Replace readline by linenoise 2017-05-10 18:37:42 +02:00
nix Fix build failure on Debian/Ubuntu 2017-05-29 15:59:18 +02:00
nix-build Fix #1314 2017-05-24 11:33:42 +02:00
nix-channel Improve progress indicator 2017-05-16 16:09:57 +02:00
nix-collect-garbage printMsg(lvlError, ...) -> printError(...) etc. 2016-09-21 16:54:53 +02:00
nix-copy-closure build-remote: Don't require signatures 2017-05-01 20:03:25 +02:00
nix-daemon Improve progress indicator 2017-05-16 16:09:57 +02:00
nix-env Improve progress indicator 2017-05-16 16:09:57 +02:00
nix-instantiate Improve progress indicator 2017-05-16 16:09:57 +02:00
nix-prefetch-url runProgram(): Distinguish between empty input and no input 2017-03-15 16:50:19 +01:00
nix-store Doh 2017-04-26 17:58:09 +02:00
resolve-system-dependencies printMsg(lvlError, ...) -> printError(...) etc. 2016-09-21 16:54:53 +02:00