
Nix 2.21.0 release with Jacek Galowicz
Full Time Nix
00:00
File Descriptor Manipulation in Sandbox Environments
This chapter provides a step-by-step demonstration of a potential attack scenario where an application outside a sandbox modifies a file descriptor to change the Nix store output path, bypassing the sandbox checks. It covers the process of file manipulation, file closure implications, and the handling of output paths within a closed sandbox, emphasizing the technical aspects of the attack and the importance of file descriptors in inter-process communication.
Transcript
Play full episode