rename nixpkgs entry in NIX_PATH
This ensures the local sources are still allowed in restricted mode, but referencing <nixpkgs> in expressions inside nixpkgs is not.
This commit is contained in:
parent
b55535a608
commit
f6c22bfc4f
|
@ -298,7 +298,7 @@ impl Nix {
|
|||
where
|
||||
S: AsRef<OsStr>,
|
||||
{
|
||||
let nixpkgspath = format!("nixpkgs={}", nixpkgs.display());
|
||||
let nixpkgspath = format!("ofborg-nixpkgs-pr={}", nixpkgs.display());
|
||||
let mut nixpath: Vec<String> = safe_paths
|
||||
.iter()
|
||||
.map(|path| format!("{}", path.display()))
|
||||
|
@ -577,7 +577,7 @@ mod tests {
|
|||
Expect::Pass,
|
||||
vec![
|
||||
"HOME=/homeless-shelter",
|
||||
"NIX_PATH=nixpkgs=",
|
||||
"NIX_PATH=ofborg-nixpkgs-pr=",
|
||||
"NIX_REMOTE=",
|
||||
"PATH=",
|
||||
],
|
||||
|
@ -604,7 +604,7 @@ mod tests {
|
|||
Expect::Pass,
|
||||
vec![
|
||||
"HOME=/homeless-shelter",
|
||||
"NIX_PATH=nixpkgs=",
|
||||
"NIX_PATH=ofborg-nixpkgs-pr=",
|
||||
"NIX_REMOTE=",
|
||||
"PATH=",
|
||||
"GC_INITIAL_HEAP_SIZE=4g",
|
||||
|
|
Loading…
Reference in a new issue