Skip to content
This repository has been archived by the owner on Apr 12, 2021. It is now read-only.
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: NixOS/nixpkgs-channels
base: a6f277f9ffb2
Choose a base ref
...
head repository: NixOS/nixpkgs-channels
compare: ad246fb87458
Choose a head ref
  • 1 commit
  • 1 file changed
  • 1 contributor

Commits on Sep 28, 2020

  1. nixos/security/wrapper: ensure the tmpfs is not world writeable

    The /run/wrapper directory is a tmpfs. Unfortunately, it's mounted with
    its root directory has the standard (for tmpfs) mode: 1777 (world writeable,
    sticky -- the standard mode of shared temporary directories). This means that
    every user can create new files and subdirectories there, but can't
    move/delete/rename files that belong to other users.
    andir committed Sep 28, 2020
    Copy the full SHA
    ad246fb View commit details
    Browse the repository at this point in the history