summaryrefslogtreecommitdiff
path: root/nix
diff options
context:
space:
mode:
Diffstat (limited to 'nix')
-rw-r--r--nix/libstore/build.cc20
1 files changed, 18 insertions, 2 deletions
diff --git a/nix/libstore/build.cc b/nix/libstore/build.cc
index eee3a33a58d..e77869fc3e4 100644
--- a/nix/libstore/build.cc
+++ b/nix/libstore/build.cc
@@ -2219,8 +2219,24 @@ static pid_t spawnSlirp4netns(int tapfd, int notifyReadyFD,
2219 slirpCtx.supplementaryGroups = {}; 2219 slirpCtx.supplementaryGroups = {};
2220 slirpCtx.setSupplementaryGroups = true; 2220 slirpCtx.setSupplementaryGroups = true;
2221 } 2221 }
2222 slirpCtx.seccompFilter = slirpSeccompFilter(); 2222 /* Unless built with '--enable-kernel=4.3.0' or similar, glibc on i686
2223 slirpCtx.addSeccompFilter = true; 2223 uses 'socketcall' instead of dedicated system calls like 'socket' and
2224 'bind'. Since the seccomp filter cannot inspect 'socketcall' arguments
2225 in a meaningful way, it can only prohibit all 'socketcall' calls; the
2226 other option is to disable the seccomp filter entirely, meaning that
2227 slirp4netns would have access to abstract unix sockets in the root
2228 network namespace. */
2229#ifdef __NR_socketcall
2230#ifndef NO_SOCKETCALL_LIBC
2231 if(getenv("GUIX_FORCE_SECCOMP") == NULL)
2232 printMsg(lvlInfo, "warning: seccomp filter for slirp4netns presumed unusable with this libc, disabling it");
2233 else
2234#endif
2235#endif
2236 {
2237 slirpCtx.seccompFilter = slirpSeccompFilter();
2238 slirpCtx.addSeccompFilter = true;
2239 }
2224 2240
2225 /* Silence slirp4netns output unless requested */ 2241 /* Silence slirp4netns output unless requested */
2226 if(verbosity <= lvlInfo) { 2242 if(verbosity <= lvlInfo) {