Skip to content

build-fhs-userenv: don't leak file descriptors#11602

Merged
abbradar merged 1 commit intoNixOS:masterfrom
zimbatm:stricter-chroot-user
Dec 10, 2015
Merged

build-fhs-userenv: don't leak file descriptors#11602
abbradar merged 1 commit intoNixOS:masterfrom
zimbatm:stricter-chroot-user

Conversation

@zimbatm
Copy link
Member

@zimbatm zimbatm commented Dec 10, 2015

This re-uses the capabilities documented in Process.spawn to avoid leaking
unecessary file-descriptors to the sandbox

I haven't tested the changes yet

This re-uses the capabilities documented in `Process.spawn` to avoid leaking
unecessary file-descriptors to the sandbox
@mention-bot
Copy link

By analyzing the blame information on this pull request, we identified @abbradar and @lethalman to be potential reviewers

@aristidb
Copy link
Contributor

I added label WIP because you didn't test this yet.

abbradar added a commit that referenced this pull request Dec 10, 2015
build-fhs-userenv: don't leak file descriptors
@abbradar abbradar merged commit 8ec4b45 into NixOS:master Dec 10, 2015
@abbradar
Copy link
Member

Tested with steam, it works. Thank you very much!

@zimbatm zimbatm deleted the stricter-chroot-user branch December 11, 2015 00:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

0.kind: enhancement Add something new or improve an existing system.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants