Commit d267ea87 authored by Patrick Steinhardt's avatar Patrick Steinhardt
Browse files

nixos/wrappers: add per-wrapper enable option

While it is possible to globally enable or disable security wrappers, it
isn't possible to disable only a subset of them. Consequently, users
will have to overwrite the security wrappers completely and re-add the
desired subset in case they want to disable a subset of those set up by
the NixOS modules.

Address this usecase by adding a new per-wrapper enable option.
parent 5757bbb8
Loading
Loading
Loading
Loading
+8 −1
Original line number Diff line number Diff line
{ config, lib, pkgs, ... }:
let

  inherit (config.security) wrapperDir wrappers;
  inherit (config.security) wrapperDir;

  wrappers = lib.filterAttrs (name: value: value.enable) config.security.wrappers;

  parentWrapperDir = dirOf wrapperDir;

@@ -41,6 +43,11 @@ let
     // { description = "file mode string"; };

  wrapperType = lib.types.submodule ({ name, config, ... }: {
    options.enable = lib.mkOption
      { type = lib.types.bool;
        default = true;
        description = "Whether to enable the wrapper.";
      };
    options.source = lib.mkOption
      { type = lib.types.path;
        description = "The absolute path to the program to be wrapped.";
+11 −0
Original line number Diff line number Diff line
@@ -29,6 +29,14 @@ import ./make-test-python.nix (
        security.apparmor.enable = true;

        security.wrappers = {
          disabled = {
            enable = false;
            owner = "root";
            group = "root";
            setuid = true;
            source = "${busybox pkgs}/bin/busybox";
            program = "disabled_busybox";
          };
          suidRoot = {
            owner = "root";
            group = "root";
@@ -112,6 +120,9 @@ import ./make-test-python.nix (
      # actually makes the apparmor policy for ping, but there's no convenient
      # test for that one.
      machine.succeed("ping -c 1 127.0.0.1")

      # Test that the disabled wrapper is not present.
      machine.fail("test -e /run/wrappers/bin/disabled_busybox")
    '';
  }
)