diff options
Diffstat (limited to 'nix')
| -rw-r--r-- | nix/libstore/build.cc | 8 |
1 files changed, 6 insertions, 2 deletions
diff --git a/nix/libstore/build.cc b/nix/libstore/build.cc index 3071c8ef10d..9bdf0a78aed 100644 --- a/nix/libstore/build.cc +++ b/nix/libstore/build.cc | |||
| @@ -1972,11 +1972,15 @@ static void prepareSlirpChrootAction(SpawnContext & sctx) | |||
| 1972 | } | 1972 | } |
| 1973 | 1973 | ||
| 1974 | /* Limit /etc to containing just /etc/resolv.conf and /etc/hosts, and | 1974 | /* Limit /etc to containing just /etc/resolv.conf and /etc/hosts, and |
| 1975 | read-only at that */ | 1975 | read-only at that. Resolve symlinks in the source path so that |
| 1976 | bindMount sees a regular file and bind-mounts it, rather than | ||
| 1977 | copying a symlink whose target may not exist in the chroot | ||
| 1978 | (e.g. /etc/resolv.conf -> /run/systemd/resolve/stub-resolv.conf | ||
| 1979 | with /run/ being empty in the chroot). */ | ||
| 1976 | Strings etcFiles = { "/etc/resolv.conf", "/etc/hosts" }; | 1980 | Strings etcFiles = { "/etc/resolv.conf", "/etc/hosts" }; |
| 1977 | for(auto & i : etcFiles) { | 1981 | for(auto & i : etcFiles) { |
| 1978 | if(pathExists(i)) { | 1982 | if(pathExists(i)) { |
| 1979 | ctx.filesInChroot[i] = i; | 1983 | ctx.filesInChroot[i] = canonPath(i, true); |
| 1980 | ctx.readOnlyFilesInChroot.insert(i); | 1984 | ctx.readOnlyFilesInChroot.insert(i); |
| 1981 | } | 1985 | } |
| 1982 | } | 1986 | } |
