Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Empty mount source for "ro" section results in mounting everything read-only #10

Open
corpix opened this issue Dec 12, 2022 · 2 comments

Comments

@corpix
Copy link
Owner

corpix commented Dec 12, 2022

{
  "mounts": {
    "rw": [
      "~/code",
      "~/dotfiles",
      "~/.emacs.d",
      "~/.cache/emacs",
      "~/.cache",
      "~/.config",
      "~/.local",
      "/tmp"
    ],
    "ro": [
      "$XAUTHORITY",
      "~/.ssh",
      "~/.gitconfig",
      "/"
    ],
    "tmpfs": [
      "/tmp",
      "/home",
      "/run/user",
      "/run/user/$UID"
    ]
  },
  "environment": {
     "SHELL": "$SHELL",
     "NIX_REMOTE": "daemon",
     "DISPLAY": "$DISPLAY"
  },
  "arguments": {
    "mode": "replace",
    "bwrap": [
      "--die-with-parent"
    ]
  }
}

Reproducible when XAUTHORITY is empty or unset

@coderofsalvation
Copy link

is nix-cage.json a place to configure the cage? (I didn't really understand this from the documentation)

@corpix
Copy link
Owner Author

corpix commented Aug 10, 2023

@coderofsalvation yes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants