Full Time Nix cover image

Nix 2.21.0 release with Jacek Galowicz

Full Time Nix

00:00

File Descriptor Manipulation in Sandbox Environments

This chapter provides a step-by-step demonstration of a potential attack scenario where an application outside a sandbox modifies a file descriptor to change the Nix store output path, bypassing the sandbox checks. It covers the process of file manipulation, file closure implications, and the handling of output paths within a closed sandbox, emphasizing the technical aspects of the attack and the importance of file descriptors in inter-process communication.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app