[Nix#9761] Derivations Built Without Sandbox Do Not Use a Valid User #69
Labels
No labels
Area/build-packaging
Area/evaluator
Area/flakes
Area/profiles
Area/remote-builds
Area/repl
Area/store
bug
Cross Compilation
devx
docs
Downstream Dependents
E/easy
E/hard
E/help wanted
E/reproducible
E/requires rearchitecture
imported
Needs Langver
OS/Linux
OS/macOS
performance
regression
release-blocker
RFD
stability
Status
blocked
Status
invalid
Status
postponed
Status
wontfix
testing
ux
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: lix-project/lix#69
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Upstream-Issue: NixOS/nix#9761
Describe the bug
When in
sandbox=false
innix.conf
or__nochroot=true
inbuiltins.derivation
, the derivation is built with a non-existent user rather thannixbld
in a normal derivation. This causes programs likepodman
to fail that require a user.Steps To Reproduce
Run
nix build .
For thisflake.nix
output:
Removing
__noChroot = true;
will not cause this issue, aswhoami
will returnnixbld
Expected behavior
With
sandbox=false
or__noChroot = true;
, a user likenixbld
should run the derivation, or the current user running the derivation should be used as the user in the derivation context, or at least setting the user in the derivation should be possible.nix-env --version
outputAdditional context
This causes errors with running any sandbox script with
podman
, aspodman
needs to be run by a user in a group. I also cannot switch to a new user in the derivation builder, assu
requires a terminal andsudo
has been disabled (sudo: The “no new privileges” flag is set, which prevents sudo from running as root.
).Priorities
Add 👍 to issues you find important.
I am pretty sure I accidentally fixed this bug: https://gerrit.lix.systems/c/lix/+/997
Regardless I can't reproduce it.