guix-commits
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

97/118: Introduce allowedRequisites feature


From: Ludovic Courtès
Subject: 97/118: Introduce allowedRequisites feature
Date: Tue, 19 May 2015 14:45:57 +0000

civodul pushed a commit to branch nix
in repository guix.

commit abd9d61e6201ddbde3305dd27c286e883e950bec
Author: Gergely Risko <address@hidden>
Date:   Wed Aug 27 16:46:02 2014 +0200

    Introduce allowedRequisites feature
---
 nix/libstore/build.cc |   19 ++++++++++++++++++-
 1 files changed, 18 insertions(+), 1 deletions(-)

diff --git a/nix/libstore/build.cc b/nix/libstore/build.cc
index 5c605a7..133ea6d 100644
--- a/nix/libstore/build.cc
+++ b/nix/libstore/build.cc
@@ -2358,7 +2358,24 @@ void DerivationGoal::registerOutputs()
             PathSet allowed = parseReferenceSpecifiers(drv, get(drv.env, 
"allowedReferences"));
             foreach (PathSet::iterator, i, references)
                 if (allowed.find(*i) == allowed.end())
-                    throw BuildError(format("output is not allowed to refer to 
path `%1%'") % *i);
+                    throw BuildError(format("output (`%1%') is not allowed to 
refer to path `%2%'") % actualPath % *i);
+        }
+
+        /* If the derivation specifies an `allowedRequisites'
+           attribute (containing a list of paths that the output may
+           refer to), check that all requisites are in that list.  !!!
+           allowedRequisites should really be per-output. */
+        if (drv.env.find("allowedRequisites") != drv.env.end()) {
+            PathSet allowed = parseReferenceSpecifiers(drv, get(drv.env, 
"allowedRequisites"));
+            PathSet requisites;
+            /* Our requisites are the union of the closures of our references. 
*/
+            foreach (PathSet::iterator, i, references)
+                /* Don't call computeFSClosure on ourselves. */
+                if (actualPath != *i)
+                    computeFSClosure(worker.store, *i, requisites);
+            foreach (PathSet::iterator, i, requisites)
+                if (allowed.find(*i) == allowed.end())
+                    throw BuildError(format("output (`%1%') is not allowed to 
refer to requisite path `%2%'") % actualPath % *i);
         }
 
         worker.store.optimisePath(path); // FIXME: combine with 
scanForReferences()



reply via email to

[Prev in Thread] Current Thread [Next in Thread]