From df7ecf34cc68bc9f1d03057381a56c193255049a Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Thu, 1 Aug 2024 19:26:05 +0200 Subject: [PATCH 1/2] stdenv: make sure the `env-vars` file created is not world readable Under some circumstances this file might contain private information that should not be accessible to everybody. (cherry picked from commit c47a1e701df7f00352b8cf401fa79c0d2f5fcc59) --- pkgs/stdenv/generic/setup.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/stdenv/generic/setup.sh b/pkgs/stdenv/generic/setup.sh index d7521b1ad5da..07f584ff22ac 100644 --- a/pkgs/stdenv/generic/setup.sh +++ b/pkgs/stdenv/generic/setup.sh @@ -981,7 +981,7 @@ substituteAllInPlace() { # the environment used for building. dumpVars() { if [ "${noDumpEnvVars:-0}" != 1 ]; then - export 2>/dev/null >| "$NIX_BUILD_TOP/env-vars" || true + install -m 0600 <(export 2>/dev/null) "$NIX_BUILD_TOP/env-vars" || true fi } From 0ab819db177151e74180b37c8f25f2b2db8ea7be Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Sun, 18 Aug 2024 14:18:02 +0200 Subject: [PATCH 2/2] stdenv: create `env-vars` file before writing data to it This fixes the regression introduced by c47a1e701df7f00352b8cf401fa79c0d2f5fcc59 on Darwin. The creation of the file using `install` and process substitution does not work on Darwin, you get the following complain: ``` install: skipping file '/dev/fd/63', as it was replaced while being copied ``` Fixes #335016 (cherry picked from commit d00775c1d9a3acbff2d121fbae54691a7f07d18a) --- pkgs/stdenv/generic/setup.sh | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/pkgs/stdenv/generic/setup.sh b/pkgs/stdenv/generic/setup.sh index 07f584ff22ac..e46c3c61ee68 100644 --- a/pkgs/stdenv/generic/setup.sh +++ b/pkgs/stdenv/generic/setup.sh @@ -981,7 +981,13 @@ substituteAllInPlace() { # the environment used for building. dumpVars() { if [ "${noDumpEnvVars:-0}" != 1 ]; then - install -m 0600 <(export 2>/dev/null) "$NIX_BUILD_TOP/env-vars" || true + # On darwin, install(1) cannot be called with /dev/stdin or fd from process substitution + # so first we create the file and then write to it + # See https://github.com/NixOS/nixpkgs/issues/335016 + { + install -m 0600 /dev/null "$NIX_BUILD_TOP/env-vars" && + export 2>/dev/null >| "$NIX_BUILD_TOP/env-vars" + } || true fi }