nixpkgs-suyu/pkgs
Roosembert Palacios 831c700c5d
firejail: fix -overlay and -build functionality on NixOS
- The `-overlay` flag runs the specified binary inside an OverlayFS,
  since the /nix store may be in a different mount point than the user
  home, this patch explicitly bind mounts it so it's available inside
  the overlay.

- profile builder: firejail provides facilities to build a new profiles.
  To do so, it execute the helper binary `fbuilder`, which in turn will
  execute firejail back with different options. This patch makes it use
  the binary available in PATH instead of the one produced at compile time.
  The compiled firejail binary doesn't have the necessary permissions,
  so the firejail NixOS module wraps it in a SUID wrapper available on
  PATH at runtime.

Signed-off-by: Roosembert Palacios <roosemberth@posteo.ch>
2020-11-27 23:14:58 +01:00
..
applications tilt: 0.17.11 -> 0.17.12 2020-11-27 11:34:46 -08:00
build-support make-desktopitem: desktop-file-utils is a nativeBuildInput 2020-11-27 01:17:32 +01:00
common-updater
data marwaita-peppermint: 0.4 -> 0.5 2020-11-26 22:22:21 -03:00
desktops Merge pull request #105146 from r-ryantm/auto-update/evisum 2020-11-27 15:21:11 +01:00
development python3Packages.snowflake-sqlalchemy: Disable running tests 2020-11-27 11:04:14 -08:00
games Merge pull request #104705 from prusnak/voxelands 2020-11-27 09:08:20 +02:00
misc Merge pull request #104719 from avnik/wine-update 2020-11-27 10:36:47 +00:00
os-specific firejail: fix -overlay and -build functionality on NixOS 2020-11-27 23:14:58 +01:00
pkgs-lib
servers Merge pull request #104819 from helsinki-systems/upd/nginx 2020-11-27 18:56:01 +01:00
shells Merge pull request #105037 from r-ryantm/auto-update/nushell 2020-11-26 19:35:17 +01:00
stdenv
test
tools Merge pull request #105145 from r-ryantm/auto-update/broot 2020-11-27 20:26:15 +01:00
top-level perlPackages.Appcpm: init at 0.994 2020-11-27 20:02:27 +08:00