diff options
Diffstat (limited to 'nix')
| -rw-r--r-- | nix/libstore/build.cc | 20 |
1 files changed, 18 insertions, 2 deletions
diff --git a/nix/libstore/build.cc b/nix/libstore/build.cc index eee3a33a58d..e77869fc3e4 100644 --- a/nix/libstore/build.cc +++ b/nix/libstore/build.cc | |||
| @@ -2219,8 +2219,24 @@ static pid_t spawnSlirp4netns(int tapfd, int notifyReadyFD, | |||
| 2219 | slirpCtx.supplementaryGroups = {}; | 2219 | slirpCtx.supplementaryGroups = {}; |
| 2220 | slirpCtx.setSupplementaryGroups = true; | 2220 | slirpCtx.setSupplementaryGroups = true; |
| 2221 | } | 2221 | } |
| 2222 | slirpCtx.seccompFilter = slirpSeccompFilter(); | 2222 | /* Unless built with '--enable-kernel=4.3.0' or similar, glibc on i686 |
| 2223 | slirpCtx.addSeccompFilter = true; | 2223 | uses 'socketcall' instead of dedicated system calls like 'socket' and |
| 2224 | 'bind'. Since the seccomp filter cannot inspect 'socketcall' arguments | ||
| 2225 | in a meaningful way, it can only prohibit all 'socketcall' calls; the | ||
| 2226 | other option is to disable the seccomp filter entirely, meaning that | ||
| 2227 | slirp4netns would have access to abstract unix sockets in the root | ||
| 2228 | network namespace. */ | ||
| 2229 | #ifdef __NR_socketcall | ||
| 2230 | #ifndef NO_SOCKETCALL_LIBC | ||
| 2231 | if(getenv("GUIX_FORCE_SECCOMP") == NULL) | ||
| 2232 | printMsg(lvlInfo, "warning: seccomp filter for slirp4netns presumed unusable with this libc, disabling it"); | ||
| 2233 | else | ||
| 2234 | #endif | ||
| 2235 | #endif | ||
| 2236 | { | ||
| 2237 | slirpCtx.seccompFilter = slirpSeccompFilter(); | ||
| 2238 | slirpCtx.addSeccompFilter = true; | ||
| 2239 | } | ||
| 2224 | 2240 | ||
| 2225 | /* Silence slirp4netns output unless requested */ | 2241 | /* Silence slirp4netns output unless requested */ |
| 2226 | if(verbosity <= lvlInfo) { | 2242 | if(verbosity <= lvlInfo) { |
