nixos/wrappers: add per-wrapper enable option (#376196)

This commit is contained in:
Aleksana 2025-02-12 20:02:52 +08:00 committed by GitHub
commit ece0ac9a7f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 19 additions and 1 deletions

View file

@ -1,7 +1,9 @@
{ config, lib, pkgs, ... }:
let
inherit (config.security) wrapperDir wrappers;
inherit (config.security) wrapperDir;
wrappers = lib.filterAttrs (name: value: value.enable) config.security.wrappers;
parentWrapperDir = dirOf wrapperDir;
@ -41,6 +43,11 @@ let
// { description = "file mode string"; };
wrapperType = lib.types.submodule ({ name, config, ... }: {
options.enable = lib.mkOption
{ type = lib.types.bool;
default = true;
description = "Whether to enable the wrapper.";
};
options.source = lib.mkOption
{ type = lib.types.path;
description = "The absolute path to the program to be wrapped.";

View file

@ -29,6 +29,14 @@ import ./make-test-python.nix (
security.apparmor.enable = true;
security.wrappers = {
disabled = {
enable = false;
owner = "root";
group = "root";
setuid = true;
source = "${busybox pkgs}/bin/busybox";
program = "disabled_busybox";
};
suidRoot = {
owner = "root";
group = "root";
@ -112,6 +120,9 @@ import ./make-test-python.nix (
# actually makes the apparmor policy for ping, but there's no convenient
# test for that one.
machine.succeed("ping -c 1 127.0.0.1")
# Test that the disabled wrapper is not present.
machine.fail("test -e /run/wrappers/bin/disabled_busybox")
'';
}
)