diff options
| author | Rickard Nilsson <rickynils@gmail.com> | 2016-07-14 20:54:06 +0200 |
|---|---|---|
| committer | Rickard Nilsson <rickynils@gmail.com> | 2016-07-14 20:54:06 +0200 |
| commit | a927709a35cee56f878f0f57a932e1a6e2ebe23b (patch) | |
| tree | a6f3fa20b48b96d74a8836eda008ead1ef62beda /pkgs/development/python-modules/python-sql | |
| parent | c1a600e8dfd5b114ec19a7b5699985f87691651b (diff) | |
openssh: Use the default privilege separation dir (/var/empty)
If running NixOS inside a container where the host's root-owned files
and directories have been mapped to some other uid (like nobody), the
ssh daemon fails to start, producing this error message:
fatal: /nix/store/...-openssh-7.2p2/empty must be owned by root and not group or world-writable.
The reason for this is that when openssh is built, we explicitly set
`--with-privsep-path=$out/empty`. This commit removes that flag which
causes the default directory /var/empty to be used instead. Since NixOS'
activation script correctly sets up that directory, the ssh daemon now
also works within containers that have a non-root-owned nix store.
Diffstat (limited to 'pkgs/development/python-modules/python-sql')
0 files changed, 0 insertions, 0 deletions
