Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport release-24.05] guix: backport build user takeover commits #351910

Merged
merged 2 commits into from
Oct 29, 2024

Commits on Oct 28, 2024

  1. guix: format with rfc-style

    Signed-off-by: Christina Sørensen <christina@cafkafk.com>
    (cherry picked from commit 42fee36)
    cafkafk authored and wegank committed Oct 28, 2024
    Configuration menu
    Copy the full SHA
    4fbe49d View commit details
    Browse the repository at this point in the history
  2. guix: build user takeover patch

    guix has recently announced a security vulnerability that allows
    local users to gain priveleges of build users, and further manipulate
    output of any build (including with setguid).
    
    This commit fixes the issue by backporting the remediation commits pushed to
    guix main to 1.4.0 as a patch.
    
    Users will still have to reboot and follow other remediation steps as
    described in the guix blogpost.
    
    Refs: https://guix.gnu.org/en/blog/2024/build-user-takeover-vulnerability/
    Signed-off-by: Christina Sørensen <christina@cafkafk.com>
    (cherry picked from commit 633a3b8)
    cafkafk authored and wegank committed Oct 28, 2024
    Configuration menu
    Copy the full SHA
    0ab5170 View commit details
    Browse the repository at this point in the history