New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
singularity: 3.2.1 -> 3.6.1 #93165
singularity: 3.2.1 -> 3.6.1 #93165
Conversation
Is this also broken in 20.03? |
make -C builddir install LOCALSTATEDIR=$out/var | ||
chmod 755 $out/libexec/singularity/bin/starter-suid | ||
wrapProgram $out/bin/singularity --prefix PATH : ${stdenv.lib.makeBinPath propagatedBuildInputs} | ||
runHook postInstall | ||
''; | ||
|
||
postFixup = '' | ||
find $out/libexec/ -type f -executable -exec remove-references-to -t ${go} '{}' + || true |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Different PR, but should we include $out/libexec in buildGoPackage as well for removing references?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think it would be valuable to do so, libexec is part of the FHS so we should expect some binaries to land there.
Partially broken, some functionality works (building images) but running images fails. Would be worth backporting this to 20.03. |
They cut a new release which fixes a security bug and resolves the hardening issues. I've updated and we now don't need to disable hardening. |
Result of 1 package built:- singularity |
Please backport if necessary. |
Motivation for this change
Update to latest release. Resolves #92466 and also a hardening bug.
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)