From unknown Tue Jun 17 22:28:47 2025 X-Loop: help-debbugs@gnu.org Subject: bug#46297: nix-service-configuration is missing the default /bin/sh Resent-From: John Soo Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Thu, 04 Feb 2021 16:02:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 46297 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: 46297@debbugs.gnu.org X-Debbugs-Original-To: Bug Guix Received: via spool by submit@debbugs.gnu.org id=B.161245448521619 (code B ref -1); Thu, 04 Feb 2021 16:02:01 +0000 Received: (at submit) by debbugs.gnu.org; 4 Feb 2021 16:01:25 +0000 Received: from localhost ([127.0.0.1]:42053 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1l7h4O-0005cZ-P1 for submit@debbugs.gnu.org; Thu, 04 Feb 2021 11:01:25 -0500 Received: from lists.gnu.org ([209.51.188.17]:53196) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1l7h4J-0005cM-9X for submit@debbugs.gnu.org; Thu, 04 Feb 2021 11:01:22 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:57798) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1l7h3z-0008T0-07 for bug-guix@gnu.org; Thu, 04 Feb 2021 11:01:03 -0500 Received: from mail-pf1-x436.google.com ([2607:f8b0:4864:20::436]:47044) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1l7h3n-0002y5-OE for bug-guix@gnu.org; Thu, 04 Feb 2021 11:00:53 -0500 Received: by mail-pf1-x436.google.com with SMTP id f63so2348883pfa.13 for ; Thu, 04 Feb 2021 08:00:38 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=asu-edu.20150623.gappssmtp.com; s=20150623; h=date:from:to:message-id:subject:mime-version; bh=6ADlUnk3uab9fOVaEo4W3s/wf2g6d9Vn8vEwVsK6By8=; b=WoiCjUeNLZ5l+Vp9B/dvwzKdVcUlkOs+9ZQh09TC8v28aLZAOmY+kTCJC+1OBIJevS d8+5L0J32ha8oKEWhzCr8Wxv0tY1BAcqGyE3HZrrpgGbPH0cqKSq4oi836yaJVyEnEv5 ldZ8qq8KNIUgUdoxb1i/OBv2FVOmDLkZ2QAKmP/nE6SEQ5RKzAAYnxnS/jw2/m/RdpBU l6MEFzPBOOCJLmPfZQhnCIg+NzgZT1tSF3jscxC5OyR1TBb7iIW8H1zrWqdfZ2oUPlX0 qfjJPcPB98Ii2JU/J3mGh3eQkjvvKkCT/0ZWUDDWyppZjrS279rxzCL3foudA0Te1DiL /bjA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:message-id:subject:mime-version; bh=6ADlUnk3uab9fOVaEo4W3s/wf2g6d9Vn8vEwVsK6By8=; b=ipuT5V47cozo9tiZp5ClzGRHCWATDAPAl49QvhH3uIf8JdkiF8t3OYG9f2Ug929Bmb ekcYsAK12i7HjBhk3MW1dM1aR+1L9LH+YBVXzcInq1hhEGRzXgJz+7a1Sfkf8TuNLb+X lhMa64q4mCOyR85gs5M877jF00r/BHvwiAF1UcS717m164iv165v0oCVGwRxFrvQndic i7rp6CSTO/E1YbNCv5DjAGEPLVdLWA4Z2GkfP2xVXd6Yy3+Qo/3yE0EreT4HbtN86xEr mtarv70PLbPr4ISWan/ALTuNYVFw7Rc6vM4yvzXuWRdZtVpTagZrQ54p5f10QEU5rouN jHGQ== X-Gm-Message-State: AOAM533+egqVxW8Tuu3/24/1+1GGddFoSm5xsLVztUbnEcwXmZez1jND qgzl508K0I8qQIsT8/SFVUbQfc3V10zn+w== X-Google-Smtp-Source: ABdhPJyXRD31nKAauGcfpaEDpid6I+L7EHrn3Vm1vt9821cT4+x7BFuYzzvkcaMDk1yysAFK9kFm9A== X-Received: by 2002:a63:5309:: with SMTP id h9mr9500029pgb.19.1612454436717; Thu, 04 Feb 2021 08:00:36 -0800 (PST) Received: from [2600:1700:83b0:8bd0:c0f9:5883:200:0] ([2600:1700:83b0:8bd0:4c5b:c297:c10a:ac59]) by smtp.gmail.com with ESMTPSA id e17sm5763919pjh.39.2021.02.04.08.00.35 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 04 Feb 2021 08:00:35 -0800 (PST) Date: Thu, 4 Feb 2021 08:00:34 -0800 From: John Soo Message-ID: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="601c1a22_6b8b4567_e691" Received-SPF: pass client-ip=2607:f8b0:4864:20::436; envelope-from=jsoo1@asu.edu; helo=mail-pf1-x436.google.com X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) --601c1a22_6b8b4567_e691 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Content-Disposition: inline Hi guix, I am working with nix at work and I found some issues with the sandbox configuration for nix. The docs say that the default sandbox-paths should have a default mount for /bin/sh https://nixos.org/manual/nix/unstable/command-ref/conf-file.html?highlight=Sandbox-paths#description Default:/bin/sh=/nix/store/zi90rxslsm4mlr46l2xws1rm94g7pk8p-busybox-1.31.1-x86_64-unknown-linux-musl/bin/busybox I think that means we should add that option to the configuration file. Thanks! John --601c1a22_6b8b4567_e691 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline

Hi gu= ix,

I am working wi= th nix at work and I found some issues with the sandbox configuration for= nix.  The docs say that the default sandbox-paths should have a def= ault mount for /bin/sh 



Default:/bin/sh=3D/nix/store/zi90rxslsm4mlr46l2xws1rm94g7pk8p-busybox-= 1.31.1-x86=5F64-unknown-linux-musl/bin/busybox
I think that means we should add that option= to the configuration file.

Thanks=21

John
= --601c1a22_6b8b4567_e691-- From unknown Tue Jun 17 22:28:47 2025 X-Loop: help-debbugs@gnu.org Subject: bug#46297: nix-service-configuration is missing the default /bin/sh Resent-From: John Soo Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Thu, 04 Feb 2021 18:56:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 46297 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: 46297@debbugs.gnu.org Received: via spool by 46297-submit@debbugs.gnu.org id=B46297.161246491130020 (code B ref 46297); Thu, 04 Feb 2021 18:56:01 +0000 Received: (at 46297) by debbugs.gnu.org; 4 Feb 2021 18:55:11 +0000 Received: from localhost ([127.0.0.1]:42234 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1l7jmZ-0007o7-9j for submit@debbugs.gnu.org; Thu, 04 Feb 2021 13:55:11 -0500 Received: from mail-pf1-f173.google.com ([209.85.210.173]:42160) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1l7jmU-0007nR-EC for 46297@debbugs.gnu.org; Thu, 04 Feb 2021 13:55:10 -0500 Received: by mail-pf1-f173.google.com with SMTP id w18so2678277pfu.9 for <46297@debbugs.gnu.org>; Thu, 04 Feb 2021 10:55:06 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=asu-edu.20150623.gappssmtp.com; s=20150623; h=from:to:subject:references:date:in-reply-to:message-id:user-agent :mime-version; bh=avEB5AjNhn/LNNPhQeUZJpp36QCG+FQvHdqptdSUbSU=; b=lI0rf9C47kAlkldiYqfziO7jHh3hjNr7cARxZGbz2PCzyIP09LFxpMOBg2K1bgm2Fq mZDrgJdrCJgov/He0YzouOSJdhz4GlHePmvDQGV3skv9JfOOzsjZ0fyL5i9LdfrrMro2 fnV06Jw9XLKQ3e2sJP15Fg4u+D+NfwsLHijk92Tm3le13vUIXvYG3oHfeYDQtLlqGIA1 22c7qXVIBiq3FDXsO5SpvFQ86Bm5j10Mmu15kNWMJ2O9lQG37K/dQsuEkDOSpTaFIHAi +SQrAmoTtGSiL7Et16GmPRAAFeNaP7zu3XE+ovPWBA2vINB3zULCfDCpYKmMR5ufUycV EqIA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:references:date:in-reply-to :message-id:user-agent:mime-version; bh=avEB5AjNhn/LNNPhQeUZJpp36QCG+FQvHdqptdSUbSU=; b=Q3BTgezQsGeuxsznT632V8Ox02zneVpCUew6uatuw+wlBt0ctJW9lKOC/64wwdfgjB 4Y71nqJtXg1TOFWQ24vx/8kShNEhZE6mKY0bfZmPmEj1UKG6v6xuY7wVmTNzoJ+Oa1Gx CurBVFqSZKGUSADDOYqbKLHG1KZJBirQyXEJRA7VJqsB6devtRe5qnPVPoqOf3ubGEuj F+Bc7uvtPra5d+QAImxbA7EkqXm18WbP+ikqGUvuLG4cuEl40x4YcVwLhdHzXn6V2R3/ IgNVj69eZqQ+s4JJEYgYv3jDlCZaS67NUjb/RxnU1dyJ5lqBHFLKnxHpPlorL8udSwpt AvfQ== X-Gm-Message-State: AOAM530q0z/HHoAiU8eSY+NwenTzo0xiPwUCcA2+Fikj4WwjxHFFkYRq lGLHke+qBxCtygNfN5gS3EPT6Q9nev950w== X-Google-Smtp-Source: ABdhPJzb+kcgpHQhJ7OaFFMNJmYvLk1/rJ7/F8nKJFNvEJCVviuaGZNY18hUDoFlWzYdiVJfqY/u2g== X-Received: by 2002:a62:6d06:0:b029:1d0:f7ca:59d0 with SMTP id i6-20020a626d060000b02901d0f7ca59d0mr819000pfc.75.1612464900118; Thu, 04 Feb 2021 10:55:00 -0800 (PST) Received: from ecenter ([2600:1700:83b0:8bd0::7a8]) by smtp.gmail.com with ESMTPSA id np7sm5446609pjb.10.2021.02.04.10.54.59 for <46297@debbugs.gnu.org> (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Thu, 04 Feb 2021 10:54:59 -0800 (PST) From: John Soo References: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> Date: Thu, 04 Feb 2021 10:54:58 -0800 In-Reply-To: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> (John Soo's message of "Thu, 4 Feb 2021 08:00:34 -0800") Message-ID: <87im77pssd.fsf@asu.edu> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain X-Spam-Score: 0.0 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) After some review and testing, I am not sure we need build-sandbox-paths either. From unknown Tue Jun 17 22:28:47 2025 X-Loop: help-debbugs@gnu.org Subject: bug#46297: nix-service-configuration is missing the default /bin/sh Resent-From: pukkamustard Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Wed, 21 Apr 2021 15:42:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 46297 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: John Soo Cc: go.wigust@gmail.com, 46297@debbugs.gnu.org X-Debbugs-Original-Cc: go.wigust@gmail.com, bug-guix@gnu.org, 46297@debbugs.gnu.org Received: via spool by submit@debbugs.gnu.org id=B.161901971819157 (code B ref -1); Wed, 21 Apr 2021 15:42:02 +0000 Received: (at submit) by debbugs.gnu.org; 21 Apr 2021 15:41:58 +0000 Received: from localhost ([127.0.0.1]:59528 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZEzG-0004yv-Hs for submit@debbugs.gnu.org; Wed, 21 Apr 2021 11:41:58 -0400 Received: from lists.gnu.org ([209.51.188.17]:34352) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZEzF-0004yg-4Z for submit@debbugs.gnu.org; Wed, 21 Apr 2021 11:41:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:44164) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lZEzE-0007aO-OD for bug-guix@gnu.org; Wed, 21 Apr 2021 11:41:56 -0400 Received: from mout02.posteo.de ([185.67.36.66]:36919) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lZEzA-0005qg-AK for bug-guix@gnu.org; Wed, 21 Apr 2021 11:41:56 -0400 Received: from submission (posteo.de [89.146.220.130]) by mout02.posteo.de (Postfix) with ESMTPS id 4C138240101 for ; Wed, 21 Apr 2021 17:41:46 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.net; s=2017; t=1619019706; bh=O7Sj2+WUuaQYEVI+fWh78CBeLNjYFazSBcNI7y1I4jw=; h=From:To:Cc:Subject:Date:From; b=Hulq+giNDUttnrXiYFqptetULhTrHW7J7IowWcepu/RvReBlYj8A0SR90dg2HGwU9 9HLFrEcNIJswMMojiXB1HEenaJ+s8XS0hFGIgh4a+wWJRpv5s47TOcMnoJk4uuxajW rPbNjLdMP0WwkCGEWpkCVy4F8wf12SJdOoCIvooxwZDCbQqzH7yjkcVObFQ9TadC9M EmOjmPSP9jxRTxiZadMNSSotpknsP8rN0f6qW9790SorCebBeOjAayjSlKiUbz6ox7 VWea+A3UNsNCmIOX7896h3S2Gu7VH6dZvk6jmN8Piz/Ji7pU5H5dq+VPKH6LEviHj9 7sQTnTbFBSdTw== Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4FQPtJ4pwMz9rxN; Wed, 21 Apr 2021 17:41:44 +0200 (CEST) References: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> <87im77pssd.fsf@asu.edu> From: pukkamustard Date: Wed, 21 Apr 2021 15:00:09 +0000 In-reply-to: <87im77pssd.fsf@asu.edu> Message-ID: <864kfzir0q.fsf@posteo.net> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="=-=-=" Received-SPF: pass client-ip=185.67.36.66; envelope-from=pukkamustard@posteo.net; helo=mout02.posteo.de X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) --=-=-= Content-Type: text/plain; format=flowed I ran into the same issue and agree with your conclusion that we may not need build-sandbox-paths. Attached a patch that removes the `build-sandbox-paths` option. This causes nix to use the default value which seems to work fine. --=-=-= Content-Type: text/x-patch Content-Disposition: attachment; filename=0001-services-nix-Remove-build-sandbox-items-configuratio.patch >From 886410216c7b1fb6572e7cfdd83dcbd6836e78e4 Mon Sep 17 00:00:00 2001 From: pukkamustard Date: Wed, 21 Apr 2021 17:19:36 +0200 Subject: [PATCH] services: nix: Remove build-sandbox-items configuration. * gnu/services/nix.scm ()[build-sandbox-items]: Remove field. * doc/guix.texi (Miscellaneous Services)[Nix service]: Remove build-sandbox-items. --- doc/guix.texi | 4 ---- gnu/services/nix.scm | 30 ++++++++++-------------------- 2 files changed, 10 insertions(+), 24 deletions(-) diff --git a/doc/guix.texi b/doc/guix.texi index b9019d5550..44e545952f 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -31993,10 +31993,6 @@ The Nix package to use. @item @code{sandbox} (default: @code{#t}) Specifies whether builds are sandboxed by default. -@item @code{build-sandbox-items} (default: @code{'()}) -This is a list of strings or objects appended to the -@code{build-sandbox-items} field of the configuration file. - @item @code{extra-config} (default: @code{'()}) This is a list of strings or objects appended to the configuration file. It is used to pass extra text to be added verbatim to the configuration diff --git a/gnu/services/nix.scm b/gnu/services/nix.scm index 1aef47db0a..537555596c 100644 --- a/gnu/services/nix.scm +++ b/gnu/services/nix.scm @@ -53,8 +53,6 @@ (default nix)) (sandbox nix-configuration-sandbox ;boolean (default #t)) - (build-sandbox-items nix-configuration-build-sandbox-items ;list of strings - (default '())) (extra-config nix-configuration-extra-config ;list of strings (default '())) (extra-options nix-configuration-extra-options ;list of strings @@ -106,24 +104,16 @@ GID." (define nix-service-etc (match-lambda (($ package sandbox build-sandbox-items extra-config) - (let ((ref-file (references-file package))) - `(("nix/nix.conf" - ,(computed-file - "nix.conf" - #~(begin - (use-modules (srfi srfi-26) - (ice-9 format)) - (with-output-to-file #$output - (lambda _ - (define internal-sandbox-paths - (call-with-input-file #$ref-file read)) - - (format #t "sandbox = ~a~%" (if #$sandbox "true" "false")) - ;; config.nix captures store file names. - (format #t "build-sandbox-paths = ~{~a ~}~%" - (append internal-sandbox-paths - '#$build-sandbox-items)) - (for-each (cut display <>) '#$extra-config))))))))))) + `(("nix/nix.conf" + ,(computed-file + "nix.conf" + #~(begin + (use-modules (srfi srfi-26) + (ice-9 format)) + (with-output-to-file #$output + (lambda _ + (format #t "sandbox = ~a~%" (if #$sandbox "true" "false")) + (for-each (cut display <>) '#$extra-config)))))))))) (define nix-shepherd-service ;; Return a for Nix. -- 2.31.1 --=-=-= Content-Type: text/plain; format=flowed CC: Oleg Pykhalov who seems to have worked on this. Thanks, pukkamustard --=-=-=-- From unknown Tue Jun 17 22:28:47 2025 X-Loop: help-debbugs@gnu.org Subject: bug#46297: nix-service-configuration is missing the default /bin/sh Resent-From: Oleg Pykhalov Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Thu, 22 Apr 2021 07:00:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 46297 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: pukkamustard Cc: John Soo , 46297@debbugs.gnu.org Received: via spool by 46297-submit@debbugs.gnu.org id=B46297.161907476826108 (code B ref 46297); Thu, 22 Apr 2021 07:00:02 +0000 Received: (at 46297) by debbugs.gnu.org; 22 Apr 2021 06:59:28 +0000 Received: from localhost ([127.0.0.1]:60589 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZTJA-0006n2-1H for submit@debbugs.gnu.org; Thu, 22 Apr 2021 02:59:28 -0400 Received: from mail-lj1-f179.google.com ([209.85.208.179]:44021) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZTJ5-0006mj-Hu for 46297@debbugs.gnu.org; Thu, 22 Apr 2021 02:59:26 -0400 Received: by mail-lj1-f179.google.com with SMTP id m7so39776860ljp.10 for <46297@debbugs.gnu.org>; Wed, 21 Apr 2021 23:59:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:in-reply-to:references:user-agent:date :message-id:mime-version; bh=3LImTYvKSTViLv7AS2z7j5UYaiOS+LMwQrKWddOyGkI=; b=smMmhNbvsbhrLTcwPmVXx8XH4t+BWm4pD8Kr3gR3iqEf03/9PkgLYaPVm+T7Id3d43 VHqkHEOhaf1y54NJlcscuOPlWt1C0sl8/8+jj2CMwGcwcf31cG1I4LNLV6cZiesL1MkU 6LjeNuE9adU/LUParvpc5325dzokl/zZi9P2LF+/OT+0qOUPvmYl9BO5/JDDbMsjJL0p 1s/VA//hjSKQNEkYDiqV1DC5m0w7DEwDWiyEGtWJQqrzmeEVSjwsrlbjCxU1/ZpB9RIc mZUsDAFDwvU35EBsSf9UROZHyeBKfO3diaXLWVWP3Z9S5Z5HjoghwL9GIfbpgM10ehzH PzdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:in-reply-to:references :user-agent:date:message-id:mime-version; bh=3LImTYvKSTViLv7AS2z7j5UYaiOS+LMwQrKWddOyGkI=; b=D9ygc5BkTHCPW5j6O9zLctnafl9idZMG7x42FvXyYA2VbXLeF4DFVorZZYWzy37SPK RA1nA54inH1WSu9KDmse7BmFkV/T+WO+LRmI2SUMcc0HG5rFDWhNV62WJywg+SK1Y2+4 VLfBnWpBohW63XRlS782gh0niPYoWKDJBspguVSuD3PMys5pfTwFdhTJCi6zfeZU+kwb 45SliJWUlz7H83lTF9F4K0Hyx2UhWmEkXadc1aMpNnLqFqdTK3+pqKYKXosj367D47eu JgPjH/1QHexpvI1Ui2gxSN8i+pHlQH8xo1T8aD8T3Uo/01AcfaNLlmwlWYPxm2mVoplW ulmA== X-Gm-Message-State: AOAM533RjIjjOiZb2PXwGxZIr7rjH/OgbuYOGQVqjj3vgJxlREdHjvyq J9C12bW0M7ovinsaV5tqo2pLdsiW2kE= X-Google-Smtp-Source: ABdhPJyfDhNlYe8+bp2bnEjoymHlZ8lJ0PGH++w+ljn0NmzRawuYUZ143bvinGBO3l8ajPGA1cyMUA== X-Received: by 2002:a05:651c:548:: with SMTP id q8mr1461331ljp.355.1619074756878; Wed, 21 Apr 2021 23:59:16 -0700 (PDT) Received: from guixsd ([88.201.161.72]) by smtp.gmail.com with ESMTPSA id g24sm82762ljl.44.2021.04.21.23.59.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 21 Apr 2021 23:59:16 -0700 (PDT) From: Oleg Pykhalov In-Reply-To: <864kfzir0q.fsf@posteo.net> (pukkamustard@posteo.net's message of "Wed, 21 Apr 2021 15:00:09 +0000") References: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> <87im77pssd.fsf@asu.edu> <864kfzir0q.fsf@posteo.net> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) Date: Thu, 22 Apr 2021 09:59:12 +0300 Message-ID: <874kfy7qkf.fsf@gmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-Spam-Score: 0.0 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hi, The =E2=80=98make check-system TESTS=3Dnix=E2=80=99 doesn't succeeded with = patch applied on 13c4a377f5a2e1240790679f3d5643385b6d7635: =2D-8<---------------cut here---------------start------------->8--- building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': wo= ken up substitution of '/nix/store/30xf8m13vrk3n8hfi9q4mkjmxvhqi4g4-guix-test': go= al destroyed building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': al= l outputs substituted (maybe) building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': al= l inputs realised building path '/nix/store/30xf8m13vrk3n8hfi9q4mkjmxvhqi4g4-guix-test' added input paths=20 building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': wo= ken up building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': tr= ying to build locking path '/nix/store/30xf8m13vrk3n8hfi9q4mkjmxvhqi4g4-guix-test' lock acquired on '/nix/store/30xf8m13vrk3n8hfi9q4mkjmxvhqi4g4-guix-test.loc= k' removing invalid path '/nix/store/30xf8m13vrk3n8hfi9q4mkjmxvhqi4g4-guix-tes= t' starting build hook '/gnu/store/0xgj4bz1ac973pw9wr8rhg3z1qc0phf8-nix-2.3.10= /libexec/nix/build-remote' cannot find machines file '/etc/nix/machines' got 0 remote builders hook reply is 'decline-permanently' killing process 186 found build user 'nixbld01' found build user 'nixbld02' found build user 'nixbld03' found build user 'nixbld04' found build user 'nixbld05' found build user 'nixbld06' found build user 'nixbld07' found build user 'nixbld08' found build user 'nixbld09' found build user 'nixbld10' trying user 'nixbld01' killing all processes running under uid '989' setting up chroot environment in '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3n= zh-guix-test.drv.chroot' executing builder '/gnu/store/pwcp239kjf7lnj5i4lkdzcfcxwcfyk72-bash-minimal= -5.0.16/bin/bash' bind mounting '/tmp/nix-build-guix-test.drv-0' to '/nix/store/nvx13nribwnd4= 7hs6frbq61vlq2n3nzh-guix-test.drv.chroot/build' bind mounting '/dev/full' to '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-g= uix-test.drv.chroot/dev/full' bind mounting '/dev/null' to '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-g= uix-test.drv.chroot/dev/null' bind mounting '/dev/random' to '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh= -guix-test.drv.chroot/dev/random' bind mounting '/dev/tty' to '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-gu= ix-test.drv.chroot/dev/tty' bind mounting '/dev/urandom' to '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nz= h-guix-test.drv.chroot/dev/urandom' bind mounting '/dev/zero' to '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-g= uix-test.drv.chroot/dev/zero' closing leaked FD 3 closing leaked FD 4 closing leaked FD 5 closing leaked FD 6 closing leaked FD 7 closing leaked FD 8 closing leaked FD 9 closing leaked FD 10 closing leaked FD 11 closing leaked FD 12 closing leaked FD 13 building '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv'... while setting up the build environment: executing '/gnu/store/pwcp239kjf7ln= j5i4lkdzcfcxwcfyk72-bash-minimal-5.0.16/bin/bash': No such file or directory building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': go= t EOF building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': wo= ken up building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': bu= ild done killing process 190 builder process for '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.= drv' finished killing all processes running under uid '989' builder for '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv' fai= led with exit code 1 lock released on '/nix/store/30xf8m13vrk3n8hfi9q4mkjmxvhqi4g4-guix-test.loc= k' building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': do= ne building of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv': go= al destroyed error: build of '/nix/store/nvx13nribwnd47hs6frbq61vlq2n3nzh-guix-test.drv'= failed QEMU runs as PID 14 connected to QEMU's monitor read QEMU monitor prompt connected to guest REPL %%%% Starting test nix (Writing full log to "nix.log") marionette is ready /gnu/store/xmnqlhxlbywkp688im5kpwr6q4mbil4g-nix-test-builder:1: FAIL Nix da= emon running # of expected passes 1 # of unexpected failures 1 note: keeping build directory `/tmp/guix-build-nix-test.drv-0' builder for `/gnu/store/bl5gryai81zxmdhs6zzkb17nbpypyhsw-nix-test.drv' fail= ed with exit code 1 build of /gnu/store/bl5gryai81zxmdhs6zzkb17nbpypyhsw-nix-test.drv failed View build log at '/var/log/guix/drvs/bl/5gryai81zxmdhs6zzkb17nbpypyhsw-nix= -test.drv.bz2'. guix build: error: build of `/gnu/store/bl5gryai81zxmdhs6zzkb17nbpypyhsw-ni= x-test.drv' failed make: *** [Makefile:6894: check-system] Error 1 =2D-8<---------------cut here---------------end--------------->8--- It doens't fail without the patch. Could I ask what issue the build-sandbox-paths introduce for you? Also it would be helpful if you provide terminal output with an error you occurred. Thanks, Oleg. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEcjhxI46s62NFSFhXFn+OpQAa+pwFAmCBHsAUHGdvLndpZ3Vz dEBnbWFpbC5jb20ACgkQFn+OpQAa+pzMBQ//e+OqppdtTZS/dIsZ1OrO1DqwECAp 8hYyWog4YS2XtTcF3VROme59Q06qZXYMamah8blLqJUnHe1rnfXVv4m332GmeIE5 GKujwrqFKRcaJgoPFUCg8GwssXtvoYiRToLACms1+1c99yqg51LD9NANNaf6Ikl8 hGFwd17gVHQvpAPHqyiC1hZYQ70YcVmgSgnSxcz8679IjBwr2dR42QQUkzIKvgzn l51Hm3rmJs3N6f9gkQQzYWp8FHPirpG6ViZ8rznXiXrVm+e50zlsLUWsb11wldWf 4NOM2kwSplRwZqA5VeY2ZdUgqtxzKmRWwD0Eq23D5fbD9c1usDGvKXW0zTDYHGjO IYCqwTcySfIeJ4eQtQJM6nUv/HTSKO0QXcD1CWRJ/yf6Lc/fokhDv1hgZyybfAiN 6pPBl29yMRani8Ewojfl/0xEAiy2ORj0ixDfjeNDXp7MEPfYU1iVUnSl6SDKqjdb vmH7PWKjptNQOS2XsRaXfNo6B8VoY9HZ4bfEEUoLKuqs+blVb1QLM5et2IRddIHT l91MnBinAJPn56RGlBKQEgf06u4e17HK4B+5yK7HwNm32z5490XSwaxfcKAOFoOB UEZq33gw0qCApkSG4BbLADyvDJBSAdgoawyfK3SlkO9OnTi7cpmQhbtehl3zxEY6 KSqSPXhsCzuTpxs= =MYiQ -----END PGP SIGNATURE----- --=-=-=-- From unknown Tue Jun 17 22:28:47 2025 X-Loop: help-debbugs@gnu.org Subject: bug#46297: nix-service-configuration is missing the default /bin/sh Resent-From: pukkamustard Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Thu, 22 Apr 2021 07:59:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 46297 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: Oleg Pykhalov Cc: John Soo , 46297@debbugs.gnu.org Received: via spool by 46297-submit@debbugs.gnu.org id=B46297.161907833631516 (code B ref 46297); Thu, 22 Apr 2021 07:59:01 +0000 Received: (at 46297) by debbugs.gnu.org; 22 Apr 2021 07:58:56 +0000 Received: from localhost ([127.0.0.1]:60636 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZUEh-0008CG-MZ for submit@debbugs.gnu.org; Thu, 22 Apr 2021 03:58:55 -0400 Received: from mout02.posteo.de ([185.67.36.66]:36597) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZUEd-0008Bz-96 for 46297@debbugs.gnu.org; Thu, 22 Apr 2021 03:58:54 -0400 Received: from submission (posteo.de [89.146.220.130]) by mout02.posteo.de (Postfix) with ESMTPS id AECFC240100 for <46297@debbugs.gnu.org>; Thu, 22 Apr 2021 09:58:44 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.net; s=2017; t=1619078324; bh=P9GzVF3bKgUbPEWLSBLLk5KtRudV18QECmM2bDZZCDM=; h=From:To:Cc:Subject:Date:From; b=kS00k0c+AVdOuMNqYabil0tQ0vtIGqD/RxqHwMSd6dXzdouPrRnq1Jajt4jb5dsVO aFBXZHhcGeO02+ry8beQZCvmksMIWC3HSS1KLVHlMjuVD+xZtGsiHzgwps/lWawV/m RBOhYtNDP8kXjOczI06Labc3EsUiVBJmwzDda1yiw3JviI3t+dJggo7dG1kcfkjEFd ngz0AjwPIMARJLcfoRAGrwXkacIvQC654GCuI6axBZJ5pwjPvbbdY/zBUk7HKhM1G/ 3L6wP9cZcYCFn2sx+cyCEyBjfaiZETciEeStcXaBG3ZFzqInufcD9rsN+eEBC4xRY3 mtwhiD/RxrXag== Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4FQqYb5tdnz9rxV; Thu, 22 Apr 2021 09:58:43 +0200 (CEST) References: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> <87im77pssd.fsf@asu.edu> <864kfzir0q.fsf@posteo.net> <874kfy7qkf.fsf@gmail.com> From: pukkamustard Date: Thu, 22 Apr 2021 07:30:58 +0000 In-reply-to: <874kfy7qkf.fsf@gmail.com> Message-ID: <8635viiwcs.fsf@posteo.net> MIME-Version: 1.0 Content-Type: text/plain; format=flowed X-Spam-Score: -0.7 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) Oleg Pykhalov writes: > It doens't fail without the patch. Could I ask what issue the > build-sandbox-paths introduce for you? Also it would be helpful > if you > provide terminal output with an error you occurred. Ah, sorry I didn't see that there where system tests. This is how I ran into the issue (nixpkgs/ folder is a checkout of the nixpkgs repo). ``` $ nix-build nixpkgs/ -A ocaml-ng.ocamlPackages_4_11.ocaml building '/nix/store/075nqnnbsgz2frmg5fzhj3ql8lajvgq3-ocaml-4.11.2.tar.xz.drv'... trying http://caml.inria.fr/pub/distrib/ocaml-4.11/ocaml-4.11.2.tar.xz % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 3418k 100 3418k 0 0 2553k 0 0:00:01 0:00:01 --:--:-- 2555k building '/nix/store/p4b4shz2alnb2zpiyx44rf7yn5k30m32-ocaml-4.11.2.drv'... unpacking sources unpacking source archive /nix/store/9harmbwn44004ylalfnvlic4qp5ppvi4-ocaml-4.11.2.tar.xz source root is ocaml-4.11.2 setting SOURCE_DATE_EPOCH to timestamp 1614163229 of file ocaml-4.11.2/yacc/wstr.c patching sources configuring fixing libtool script ./build-aux/ltmain.sh configure flags: --disable-static -prefix /nix/store/gvwnh8wn0ib40fd6k3wa4xf7ja1y17l9-ocaml-4.11.2 /nix/store/bmnhfb10m2s3whl6478dmqhcrkjwk77y-stdenv-linux/setup: ./configure: /bin/sh: bad interpreter: No such file or directory builder for '/nix/store/p4b4shz2alnb2zpiyx44rf7yn5k30m32-ocaml-4.11.2.drv' failed with exit code 126 error: build of '/nix/store/p4b4shz2alnb2zpiyx44rf7yn5k30m32-ocaml-4.11.2.drv' failed ```` The build succeeds if I do following: ``` $ sudo nix-build nixpkgs/ -A ocaml-ng.ocamlPackages_4_11.ocaml --option build-sandbox-paths "/bin/sh=//nix/store/0xrjvxvh3wvdbf8pc2850jry1fcx292g-busybox-1.32.1/bin/busybox" these derivations will be built: /nix/store/p4b4shz2alnb2zpiyx44rf7yn5k30m32-ocaml-4.11.2.drv building '/nix/store/p4b4shz2alnb2zpiyx44rf7yn5k30m32-ocaml-4.11.2.drv'... unpacking sources unpacking source archive /nix/store/9harmbwn44004ylalfnvlic4qp5ppvi4-ocaml-4.11.2.tar.xz source root is ocaml-4.11.2 setting SOURCE_DATE_EPOCH to timestamp 1614163229 of file ocaml-4.11.2/yacc/wstr.c patching sources configuring fixing libtool script ./build-aux/ltmain.sh configure flags: --disable-static -prefix /nix/store/gvwnh8wn0ib40fd6k3wa4xf7ja1y17l9-ocaml-4.11.2 configure: Configuring OCaml version 4.11.2 checking build system type... x86_64-pc-linux-gnu checking host system type... x86_64-pc-linux-gnu checking target system type... x86_64-pc-linux-gnu checking how to print strings... printf checking for gcc... gcc checking whether the C compiler works... yes . . . /nix/store/gvwnh8wn0ib40fd6k3wa4xf7ja1y17l9-ocaml-4.11.2 ``` Note that I need to use sudo as otherwise Nix would simply ignore my request to override system configurations. And I had to run `nix-build -A busybox` to make sure busybox was in the /nix/store. The build-sandbox-paths I manually supplied seem to be the defaults (as stated in documentation linked in John Soo's mail), so I assumed that just removing the build-sandbox-path setting from the nix.conf would solve the issue. I was a bit sloppy with testing it completely... This might be an upstream issue with how OCaml is built in Nix. I think Nix builders should use ${stdenv.shell} instead of /bin/sh (https://github.com/NixOS/nixpkgs/issues/183). But maybe good if we can fix it in the Guix nix-service as well. -pukkamustard From unknown Tue Jun 17 22:28:47 2025 X-Loop: help-debbugs@gnu.org Subject: bug#46297: nix-service-configuration is missing the default /bin/sh Resent-From: Oleg Pykhalov Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Thu, 22 Apr 2021 16:51:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 46297 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: pukkamustard Cc: John Soo , 46297@debbugs.gnu.org Received: via spool by 46297-submit@debbugs.gnu.org id=B46297.161911023723610 (code B ref 46297); Thu, 22 Apr 2021 16:51:02 +0000 Received: (at 46297) by debbugs.gnu.org; 22 Apr 2021 16:50:37 +0000 Received: from localhost ([127.0.0.1]:35416 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZcXF-00068k-1H for submit@debbugs.gnu.org; Thu, 22 Apr 2021 12:50:37 -0400 Received: from mail-lf1-f42.google.com ([209.85.167.42]:40778) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lZcXD-00068W-R3 for 46297@debbugs.gnu.org; Thu, 22 Apr 2021 12:50:36 -0400 Received: by mail-lf1-f42.google.com with SMTP id h36so19042857lfv.7 for <46297@debbugs.gnu.org>; Thu, 22 Apr 2021 09:50:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version; bh=o73QoLfndWTNL6t1dsoZOWvUTcRv0SwOFjhusQR0VpY=; b=Zouw5Dl5n065mPtNnaO1vFd+ZO+D5d8Sqgjg6odMjH+J+pkQgvu1klfk5WoAxn4mGg VbH8FktzppFi0QXpXa5dDcGwqQhLxyspJeH8mDbwQ/SqBPsDdjLD8i/qo0pbXZLtAOyH URvbe8aix6QKH29swi/MJRqwuLhia0/wA+DrHG/+P6+Kv5gS2wkA6N8khC5ym++0SQHI 0zlUAXSpKqZzLTKqRirFW559rmTxhi6YvWGTZAwVaWtbFh2JmmMVP5tL31TbpqRck3aA s7B5SXICf7XOBDdFKpYF/NnJERDZo1XQq53jw0oft4Ykej6Qepqs0jTE63ABnLtJ1REL 91yw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:user-agent:mime-version; bh=o73QoLfndWTNL6t1dsoZOWvUTcRv0SwOFjhusQR0VpY=; b=LJ1/dcNnQH//edaZ8ZSA1Izy3f8hdxER/vTf4En6i6kbbYXa1yeKbKfNB2RaEht73p pFZrPnPNmRgFemUBGoFjWOADGgau2yOlCEQScwRCr1cTwnYBOiLTuZWwaNINNgkoz+sJ yip/KJaDP2rG43wkQX0VY9cBned6RlE7rjxkDO0BGKLesB2xWbyu4XX27HVCScfUM+96 dHlKJ/2LTTWyNxZliR2Xk2PjKUAo3esc+w27NrLQHCuFP7FwZF8ZssNZ773TkV2iHrQI 5G6pIugCS3pPyZBDCbE6fTnltNDOUVwQLF2KPa3/Czd2TGYO9fTwQ12LBmrTDxO5YQdj Hyww== X-Gm-Message-State: AOAM5315B48MF0JTTok//r9ALhi8Vmi3f66lUmLWxB3DSgDOYRJ/iHrm /j+ZXCE2NqGjzS09MOFR7kDT3GuPeVg= X-Google-Smtp-Source: ABdhPJykJvA5qrsfO78wGo/OAWtc1vgNWDJ30/MM28vdkrLiyP2vWvC6pyOIvoh5vJEe0WM+Pa7ZVA== X-Received: by 2002:ac2:5feb:: with SMTP id s11mr3033697lfg.558.1619110229285; Thu, 22 Apr 2021 09:50:29 -0700 (PDT) Received: from guixsd ([88.201.161.72]) by smtp.gmail.com with ESMTPSA id u6sm324698ljj.82.2021.04.22.09.50.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 22 Apr 2021 09:50:28 -0700 (PDT) From: Oleg Pykhalov References: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> <87im77pssd.fsf@asu.edu> <864kfzir0q.fsf@posteo.net> <874kfy7qkf.fsf@gmail.com> <8635viiwcs.fsf@posteo.net> Date: Thu, 22 Apr 2021 19:50:25 +0300 In-Reply-To: <8635viiwcs.fsf@posteo.net> (pukkamustard@posteo.net's message of "Thu, 22 Apr 2021 07:30:58 +0000") Message-ID: <87zgxquuum.fsf@gmail.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="==-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-Spam-Score: 0.0 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --==-=-= Content-Type: multipart/mixed; boundary="=-=-=" --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable pukkamustard writes: [=E2=80=A6] > The build succeeds if I do following: > > ``` > $ sudo nix-build nixpkgs/ -A ocaml-ng.ocamlPackages_4_11.ocaml --option > build-sandbox-paths > "/bin/sh=3D//nix/store/0xrjvxvh3wvdbf8pc2850jry1fcx292g-busybox-1.32.1/bi= n/busybox" Could you apply the following patch on 13c4a377f5a2e1240790679f3d5643385b6d7635 and run the command again, please? --=-=-= Content-Type: text/x-patch; charset=utf-8 Content-Disposition: inline; filename=0001-services-nix-Add-bin-sh-to-build-sandbox-paths.patch Content-Transfer-Encoding: quoted-printable Content-Description: [PATCH] services: nix: Add /bin/sh to build-sandbox-paths. From=201aa675482fa1aaba02ac1d8599198ec0aa8c2201 Mon Sep 17 00:00:00 2001 From: Oleg Pykhalov Date: Thu, 22 Apr 2021 19:46:23 +0300 Subject: [PATCH] services: nix: Add /bin/sh to build-sandbox-paths. * gnu/services/nix.scm (nix-service-etc): Add /bin/sh to build-sandbox-path= s. =2D-- gnu/services/nix.scm | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/gnu/services/nix.scm b/gnu/services/nix.scm index 1aef47db0a..619e3cae54 100644 =2D-- a/gnu/services/nix.scm +++ b/gnu/services/nix.scm @@ -1,5 +1,5 @@ ;;; GNU Guix --- Functional package management for GNU =2D;;; Copyright =C2=A9 2019, 2020 Oleg Pykhalov +;;; Copyright =C2=A9 2019, 2020, 2021 Oleg Pykhalov ;;; Copyright =C2=A9 2020 Peng Mei Yu ;;; ;;; This file is part of GNU Guix. @@ -19,6 +19,7 @@ =20 (define-module (gnu services nix) #:use-module (gnu packages admin) + #:use-module (gnu packages bash) #:use-module (gnu packages package-management) #:use-module (gnu services base) #:use-module (gnu services configuration) @@ -121,7 +122,8 @@ GID." (format #t "sandbox =3D ~a~%" (if #$sandbox "true" "fa= lse")) ;; config.nix captures store file names. (format #t "build-sandbox-paths =3D ~{~a ~}~%" =2D (append internal-sandbox-paths + (append (list (string-append "/bin/sh=3D" #$ba= sh-minimal "/bin/sh")) + internal-sandbox-paths '#$build-sandbox-items)) (for-each (cut display <>) '#$extra-config))))))))))) =20 =2D-=20 2.31.1 --=-=-=-- --==-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEcjhxI46s62NFSFhXFn+OpQAa+pwFAmCBqVEUHGdvLndpZ3Vz dEBnbWFpbC5jb20ACgkQFn+OpQAa+py2Fg//U6jv44y65KbTZIckvPN2IIiQzXxh cZA9BUvAmLY9RXHZBlM2bPHLzfNVp22m8dsVcqxt/cjwKbeOpiG1ATJbx6h/XVHT MzhIln2HnF/fLAvxU2RrdJ3Z4yu9O87+WNcCA12DfUOXDOy6JskNlAQphTCIlX/c PQCb1GSmIkF8mLvuEGUUxREnWwdo0Eiw64JUVRFpcRMWKIBhTrM2jkRHEPPOUl7I 20AtcOnnzC/z+PS7ulJpVU46taNbRQUiIHZ/RfnwOKbj6DdJfkc6+lbm1jRvicCS jhuSzIWmMrU3NaP72J0WFnobdeddfY6X5p01YJWVE1Wbmb7EDZ7JRfRtxDM5RBzF ePG8YPyHyOII1ssI6WkCY5kk0QridEJIjmMUnorVOYSNtfFFlpDDEHtuqvLVtU9B Pq5dakpjWKiI4fznyRWo2QBi8fq0NjdeRR7v68bZs/JPX8G2MozI7NnCC9iMAsrm z8rL/ImdK/VieYCa9R8nUBqHiWB4Xp7mjaU/5fBXCikWrXwdKCsvIvf60IDuxHfH XxFPH5QwmMHT1wPDgVwubVbNgAiDk9yJMkULv2MXNNlNGSX/vFexqe/FfAHVl/1v Wq/s43lLVGcDJgaQvkyX55vFtOcpsRICs5Olr/7DuzDuNqOMXogYGFud/+nBsgcm gNONUc76292hPRI= =8AKo -----END PGP SIGNATURE----- --==-=-=-- From unknown Tue Jun 17 22:28:47 2025 X-Loop: help-debbugs@gnu.org Subject: bug#46297: nix-service-configuration is missing the default /bin/sh Resent-From: pukkamustard Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Mon, 26 Apr 2021 07:37:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 46297 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: Oleg Pykhalov Cc: John Soo , 46297@debbugs.gnu.org Received: via spool by 46297-submit@debbugs.gnu.org id=B46297.161942261231295 (code B ref 46297); Mon, 26 Apr 2021 07:37:02 +0000 Received: (at 46297) by debbugs.gnu.org; 26 Apr 2021 07:36:52 +0000 Received: from localhost ([127.0.0.1]:44326 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lavnY-00088g-5y for submit@debbugs.gnu.org; Mon, 26 Apr 2021 03:36:52 -0400 Received: from mout01.posteo.de ([185.67.36.65]:35877) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lavnV-00088O-K4 for 46297@debbugs.gnu.org; Mon, 26 Apr 2021 03:36:50 -0400 Received: from submission (posteo.de [89.146.220.130]) by mout01.posteo.de (Postfix) with ESMTPS id E3E58240028 for <46297@debbugs.gnu.org>; Mon, 26 Apr 2021 09:36:42 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.net; s=2017; t=1619422602; bh=RwO6FIcaAhyzCM2ocr8tN7N4SM5rgKVyCwKiiB1aL0c=; h=From:To:Cc:Subject:Date:From; b=Bf+8M9O5mqUiSu0ByASnO5YfuhpbX+BoTCnNjZSbwgVFz3c9tqIzcUlTpRx8HYe8D Pz5bJpf7Gn78tOXwEOrqtOsIINiVxBUWr0bAjS24BSDNuloU3TRiul7dlkZoNtdt37 Vg7SwEkJaIaunPM1u0BLe8QIXnV0VXwrOLvQdMzXiluJOOibpa5vasXT+LJMRNzT4O BqPhmRDl6hdQowAGGqATmx4n+x6+cf1iZW1fqOR4qCQJVcMDrY+c2RyAyiCeqsw4wl oGaqDVsA24H/kDk0/DA55aME1Sikm91ai6+TVW60GGXLrTWYvQbfSjj0b8y+jlHt29 +RG9/0brDjWYw== Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4FTGtK4TRwz9rxM; Mon, 26 Apr 2021 09:36:41 +0200 (CEST) References: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> <87im77pssd.fsf@asu.edu> <864kfzir0q.fsf@posteo.net> <874kfy7qkf.fsf@gmail.com> <8635viiwcs.fsf@posteo.net> <87zgxquuum.fsf@gmail.com> From: pukkamustard Date: Mon, 26 Apr 2021 07:21:40 +0000 In-reply-to: <87zgxquuum.fsf@gmail.com> Message-ID: <861rax4hvb.fsf@posteo.net> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable X-Spam-Score: -0.7 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) Oleg Pykhalov writes: [=E2=80=A6] > Could you apply the following patch on > 13c4a377f5a2e1240790679f3d5643385b6d7635 and run the command=20 > again, > please? Applied and tested in a virtual machine. Your patch seems to fix=20 the issue I was having. Thank you! Also tested again in a VM without your patches and was able to=20 reproduce the error as reported. For completeness the commands I ran in the VM: ``` $ nix-channel add https://nixos.org/channels/nixpkgs-unstable=20 nixpkgs $ nix-channel --update $ nix-build '' -I .nix-defexpr/channels -A=20 ocaml-ng.ocamlPackages_4_11.ocaml /nix/store/gvwnh8wn0ib40fd6k3wa4xf7ja1y17l9-ocaml-4.11.2 ``` -pukkamustard From unknown Tue Jun 17 22:28:47 2025 MIME-Version: 1.0 X-Mailer: MIME-tools 5.505 (Entity 5.505) X-Loop: help-debbugs@gnu.org From: help-debbugs@gnu.org (GNU bug Tracking System) To: John Soo Subject: bug#46297: closed (Re: bug#46297: nix-service-configuration is missing the default /bin/sh) Message-ID: References: <875z092cxj.fsf@gmail.com> <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> X-Gnu-PR-Message: they-closed 46297 X-Gnu-PR-Package: guix Reply-To: 46297@debbugs.gnu.org Date: Mon, 26 Apr 2021 17:07:01 +0000 Content-Type: multipart/mixed; boundary="----------=_1619456821-565-1" This is a multi-part message in MIME format... ------------=_1619456821-565-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your bug report #46297: nix-service-configuration is missing the default /bin/sh which was filed against the guix package, has been closed. The explanation is attached below, along with your original report. If you require more details, please reply to 46297@debbugs.gnu.org. --=20 46297: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=3D46297 GNU Bug Tracking System Contact help-debbugs@gnu.org with problems ------------=_1619456821-565-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 46297-done) by debbugs.gnu.org; 26 Apr 2021 17:06:28 +0000 Received: from localhost ([127.0.0.1]:47013 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lb4gm-00008K-Bx for submit@debbugs.gnu.org; Mon, 26 Apr 2021 13:06:28 -0400 Received: from mail-lf1-f45.google.com ([209.85.167.45]:39606) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lb4gj-000086-Kv for 46297-done@debbugs.gnu.org; Mon, 26 Apr 2021 13:06:27 -0400 Received: by mail-lf1-f45.google.com with SMTP id x20so59065607lfu.6 for <46297-done@debbugs.gnu.org>; Mon, 26 Apr 2021 10:06:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version; bh=t155VYoSJhI80hSx14kwDDjKfCtL/mR26RIEoa1TWas=; b=QxI7Ezlf/fG65mYn+uxdtkPw9jbCbgjeeaijY3urnUNmP6sejezlAu/8k+nH51pK85 iK8sasqeXZp52QTikGwn9XLzhSB1q/o6pYPqmymlNiXtFHH+qAhCkGiQhn212U39R1Oz dA5n8fMwy52YwM80XR0NaSxn+KLon06g1X5Y4GzzD6ygQh7aYiDDHiqY25TOAE9uOjtO eYYY408NI1Iqk9LDXqW6Umq4AR8Rftc1V2spY9VsTbSxWA8GWlx9KRJi1ddeQyLfsR1B KIRATb+IJuI7skekD01ZVCtWBCM+xNlPzyDChjK25afUp2QJM1uWSXu9YhJnEmC5bDQO FI7w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:user-agent:mime-version; bh=t155VYoSJhI80hSx14kwDDjKfCtL/mR26RIEoa1TWas=; b=QEn6bQ2iADwP9kan7HU6f5ggWhx5/VgkhGDgoosf2NK0c3vSbw6x1dtjNDm3ijZvzF h17TpxbVz+mvBqViEq5SwvyhI2RTATqq8px8Hk0B5ljEQ9Nr9mRRCRI5K82IRdngDW7s ZAhGkunvvxgRbHUBtJgZ1JQgBCnUjYygjEM/RolroYYrA2CRLvrhqdukp225qR4KOoBJ DMkq0G2UhVvdFE3GD/lnFLQkcZXFHhRzx6sXkk/gH65E5Arh7c3ZoHwE0IbDKnx9zQVe ASzj7Y6BynLyLCTqvDXZtVFF3lTd/2W9uVkdub2MGc3+Rwjg1tw/CXmQCe5T5XUwzyvf f9uQ== X-Gm-Message-State: AOAM530/7rBvjngZ8gwvMCPOGnkxcPzsK22I8l5CMwMwxFIQikjHDZvA iC/eIJojWZxlNbziBMZMYQQ= X-Google-Smtp-Source: ABdhPJzne7r+EN2O9Y8TvamvWYWFbFeVOSuyTawG4sIhTyndF2EPukJeWLZesBdeYqx+HMVpMqslVg== X-Received: by 2002:a05:6512:38c1:: with SMTP id p1mr8357592lft.481.1619456779628; Mon, 26 Apr 2021 10:06:19 -0700 (PDT) Received: from guixsd ([88.201.161.72]) by smtp.gmail.com with ESMTPSA id v17sm1464231lfr.35.2021.04.26.10.06.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 26 Apr 2021 10:06:18 -0700 (PDT) From: Oleg Pykhalov To: 46297-done@debbugs.gnu.org Subject: Re: bug#46297: nix-service-configuration is missing the default /bin/sh References: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> <87im77pssd.fsf@asu.edu> <864kfzir0q.fsf@posteo.net> <874kfy7qkf.fsf@gmail.com> <8635viiwcs.fsf@posteo.net> <87zgxquuum.fsf@gmail.com> <861rax4hvb.fsf@posteo.net> Date: Mon, 26 Apr 2021 20:06:16 +0300 In-Reply-To: <861rax4hvb.fsf@posteo.net> (pukkamustard@posteo.net's message of "Mon, 26 Apr 2021 07:21:40 +0000") Message-ID: <875z092cxj.fsf@gmail.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 46297-done Cc: pukkamustard , John Soo X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable pukkamustard writes: [=E2=80=A6] >> Could you apply the following patch on >> 13c4a377f5a2e1240790679f3d5643385b6d7635 and run the command again, >> please? > > Applied and tested in a virtual machine. Your patch seems to fix the issu= e I > was having. Thank you! > > Also tested again in a VM without your patches and was able to reproduce = the > error as reported. > > For completeness the commands I ran in the VM: > > ``` > $ nix-channel add https://nixos.org/channels/nixpkgs-unstable nixpkgs > $ nix-channel --update > $ nix-build '' -I .nix-defexpr/channels -A > ocaml-ng.ocamlPackages_4_11.ocaml > /nix/store/gvwnh8wn0ib40fd6k3wa4xf7ja1y17l9-ocaml-4.11.2 > ``` Thank yoo for the test. Pushed to master as 43a7724040560d35e9e3a19bd1cfdb7e5c4c4711 Oleg. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEcjhxI46s62NFSFhXFn+OpQAa+pwFAmCG8wgUHGdvLndpZ3Vz dEBnbWFpbC5jb20ACgkQFn+OpQAa+pyaThAAtLe/M29qTrAcF6TV7MR9jSl7R2Wq tZ60TA9yrILhgYdhjpqurWKloOlLOPKRUh6ig8ALIMyLrqp6f27J2AcJncl/27/K jd40QqS5qE4gQ0E9gwNZCaLz75l60KObkGc52BHsEG4SpRQc24NTI6xKc8eIqgfw /5oBWI05+cY+INvA9B89T8RHEPr7mDE2iE1Hat630tc6LtPCM+/zY4SuYaB/tcRz 5A+PwUdBuhaVhjfZCCzsL7SLIU7pOhqtul0oi1QFjqSfoKZOrxK5ajBDG4J+6zvY S9qaGT9dLMs634V43BMWSQ0UFlaIZmeHSN7Yq4p/U8pER6nvCgq50A8SIzLijRWz RfzbW1Mp3KEX/SeDlgfSjVaCb3bT21JChy6MwkAIL7qWFqEbswW6Gdz7Ms+lnKYR o+kCmPakC7d5woAOO62fgN37qZE945vl2PYwwTqL3NSCMs95aLhIzH9raxpHvhVb 2L86U9o4Tr2Jb1zl+KTeGtLoHM/hAOIwPcQ6LS53O6Lfzy+p678joLIxVDAZUh3a J0qk+wquqQ9fG8nIe7elZuqwEUGWWuzB6QwXXsNXwJRNrt28zT8gSqfLtZ1Wm1le 2M+IikBkROk8d953l8mP50h7+CjI5hbgHRH4zo4IZGOlIkdUcG/2P9+rfU+Hspdd +JWSWanfRsr2hPc= =gDF9 -----END PGP SIGNATURE----- --=-=-=-- ------------=_1619456821-565-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by debbugs.gnu.org; 4 Feb 2021 16:01:25 +0000 Received: from localhost ([127.0.0.1]:42053 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1l7h4O-0005cZ-P1 for submit@debbugs.gnu.org; Thu, 04 Feb 2021 11:01:25 -0500 Received: from lists.gnu.org ([209.51.188.17]:53196) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1l7h4J-0005cM-9X for submit@debbugs.gnu.org; Thu, 04 Feb 2021 11:01:22 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:57798) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1l7h3z-0008T0-07 for bug-guix@gnu.org; Thu, 04 Feb 2021 11:01:03 -0500 Received: from mail-pf1-x436.google.com ([2607:f8b0:4864:20::436]:47044) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1l7h3n-0002y5-OE for bug-guix@gnu.org; Thu, 04 Feb 2021 11:00:53 -0500 Received: by mail-pf1-x436.google.com with SMTP id f63so2348883pfa.13 for ; Thu, 04 Feb 2021 08:00:38 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=asu-edu.20150623.gappssmtp.com; s=20150623; h=date:from:to:message-id:subject:mime-version; bh=6ADlUnk3uab9fOVaEo4W3s/wf2g6d9Vn8vEwVsK6By8=; b=WoiCjUeNLZ5l+Vp9B/dvwzKdVcUlkOs+9ZQh09TC8v28aLZAOmY+kTCJC+1OBIJevS d8+5L0J32ha8oKEWhzCr8Wxv0tY1BAcqGyE3HZrrpgGbPH0cqKSq4oi836yaJVyEnEv5 ldZ8qq8KNIUgUdoxb1i/OBv2FVOmDLkZ2QAKmP/nE6SEQ5RKzAAYnxnS/jw2/m/RdpBU l6MEFzPBOOCJLmPfZQhnCIg+NzgZT1tSF3jscxC5OyR1TBb7iIW8H1zrWqdfZ2oUPlX0 qfjJPcPB98Ii2JU/J3mGh3eQkjvvKkCT/0ZWUDDWyppZjrS279rxzCL3foudA0Te1DiL /bjA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:message-id:subject:mime-version; bh=6ADlUnk3uab9fOVaEo4W3s/wf2g6d9Vn8vEwVsK6By8=; b=ipuT5V47cozo9tiZp5ClzGRHCWATDAPAl49QvhH3uIf8JdkiF8t3OYG9f2Ug929Bmb ekcYsAK12i7HjBhk3MW1dM1aR+1L9LH+YBVXzcInq1hhEGRzXgJz+7a1Sfkf8TuNLb+X lhMa64q4mCOyR85gs5M877jF00r/BHvwiAF1UcS717m164iv165v0oCVGwRxFrvQndic i7rp6CSTO/E1YbNCv5DjAGEPLVdLWA4Z2GkfP2xVXd6Yy3+Qo/3yE0EreT4HbtN86xEr mtarv70PLbPr4ISWan/ALTuNYVFw7Rc6vM4yvzXuWRdZtVpTagZrQ54p5f10QEU5rouN jHGQ== X-Gm-Message-State: AOAM533+egqVxW8Tuu3/24/1+1GGddFoSm5xsLVztUbnEcwXmZez1jND qgzl508K0I8qQIsT8/SFVUbQfc3V10zn+w== X-Google-Smtp-Source: ABdhPJyXRD31nKAauGcfpaEDpid6I+L7EHrn3Vm1vt9821cT4+x7BFuYzzvkcaMDk1yysAFK9kFm9A== X-Received: by 2002:a63:5309:: with SMTP id h9mr9500029pgb.19.1612454436717; Thu, 04 Feb 2021 08:00:36 -0800 (PST) Received: from [2600:1700:83b0:8bd0:c0f9:5883:200:0] ([2600:1700:83b0:8bd0:4c5b:c297:c10a:ac59]) by smtp.gmail.com with ESMTPSA id e17sm5763919pjh.39.2021.02.04.08.00.35 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 04 Feb 2021 08:00:35 -0800 (PST) Date: Thu, 4 Feb 2021 08:00:34 -0800 From: John Soo To: Bug Guix Message-ID: <5112f89b-ac41-45bd-931c-bd8a9bde4836@Johns-iPhone> Subject: nix-service-configuration is missing the default /bin/sh MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="601c1a22_6b8b4567_e691" Received-SPF: pass client-ip=2607:f8b0:4864:20::436; envelope-from=jsoo1@asu.edu; helo=mail-pf1-x436.google.com X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) --601c1a22_6b8b4567_e691 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Content-Disposition: inline Hi guix, I am working with nix at work and I found some issues with the sandbox configuration for nix. The docs say that the default sandbox-paths should have a default mount for /bin/sh https://nixos.org/manual/nix/unstable/command-ref/conf-file.html?highlight=Sandbox-paths#description Default:/bin/sh=/nix/store/zi90rxslsm4mlr46l2xws1rm94g7pk8p-busybox-1.31.1-x86_64-unknown-linux-musl/bin/busybox I think that means we should add that option to the configuration file. Thanks! John --601c1a22_6b8b4567_e691 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline

Hi gu= ix,

I am working wi= th nix at work and I found some issues with the sandbox configuration for= nix.  The docs say that the default sandbox-paths should have a def= ault mount for /bin/sh 



Default:/bin/sh=3D/nix/store/zi90rxslsm4mlr46l2xws1rm94g7pk8p-busybox-= 1.31.1-x86=5F64-unknown-linux-musl/bin/busybox
I think that means we should add that option= to the configuration file.

Thanks=21

John
= --601c1a22_6b8b4567_e691-- ------------=_1619456821-565-1--