unofficial mirror of guix-devel@gnu.org 
 help / color / mirror / code / Atom feed
* Daemon update again
@ 2015-06-03 22:07 Ludovic Courtès
  2015-06-05 20:11 ` Andreas Enge
  0 siblings, 1 reply; 7+ messages in thread
From: Ludovic Courtès @ 2015-06-03 22:07 UTC (permalink / raw)
  To: guix-devel

Commit 54c260e updates the daemon again from upstream Nix code.  Few
interesting changes this time; interesting changes include:

  • Fixed-output derivations (such as downloads) are now also run in a
    chroot environment.  The difference with other derivations is that
    they do not get a separate network name space, which allows them to
    access the network, and they get additional files such as
    /etc/resolv.conf.

  • pivot_root(2) is used in addition to chroot(2), which is claimed to
    really prevent getting out of the chroot (though in practice build
    processes are non-root so I don’t see how they could get away.)

  • The ‘verifyStore’ RPC (more on that soon.)

Please report any issues!

Ludo’.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2015-06-09 20:04 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-06-03 22:07 Daemon update again Ludovic Courtès
2015-06-05 20:11 ` Andreas Enge
2015-06-06 17:41   ` Ludovic Courtès
2015-06-08 21:59     ` Andreas Enge
2015-06-09 15:51       ` Ludovic Courtès
2015-06-09 16:49         ` Andreas Enge
2015-06-09 20:04           ` Ludovic Courtès

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).