From 6e049ae607b53eba3c9c6bed260a0b39a3f73a70 Mon Sep 17 00:00:00 2001 From: Matthew Bauer Date: Thu, 22 Sep 2022 13:59:16 -0500 Subject: [PATCH] Allow pass max-silent-time and build-poll-interval to daemon untrusted These settings seem harmless, they control the same polling functionality that timeout does, but with different behavior. Should be safe for untrusted users to pass in. --- src/libstore/daemon.cc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/libstore/daemon.cc b/src/libstore/daemon.cc index de69b50ee..48dd5c247 100644 --- a/src/libstore/daemon.cc +++ b/src/libstore/daemon.cc @@ -239,6 +239,8 @@ struct ClientSettings else if (trusted || name == settings.buildTimeout.name || name == settings.buildRepeat.name + || name == settings.maxSilentTime.name + || name == settings.pollInterval.name || name == "connect-timeout" || (name == "builders" && value == "")) settings.set(name, value);