Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR makes the libvirt images readable only by their owner/group (i.e. the user/group under which is run qemu, by default root/root on NixOS afaik). It fixes a critical vulnerability in the libvirt backend.
The user does not actually need read/write permissions on that file for nixops to run correctly. If they want access to that file for other reasons, they should configure their libvirt installation to manage permissions accordingly (see e.g. https://libvirt.org/drvqemu.html#securitydac).