Browse Source

daemon: Flush the sink upon 'exportPath' errors.

Prior to this change, errors such as wrong permissions on
/etc/guix/signing-key.sec would give:

  guix-daemon: nix/libutil/serialise.cc:15: virtual nix::BufferedSink::~BufferedSink(): Assertion `!bufPos' failed.

This patch correctly propagates the error to the client and thus changes
that to:

  error: build failed: file `/etc/guix/signing-key.sec' should be secret (inaccessible to everybody else)!

* nix/nix-daemon/nix-daemon.cc (performOp): Wrap 'exportPath' call in
'try' block.

Co-authored-by: Ludovic Courtès <ludo@gnu.org>
python-updates
Jan Nieuwenhuizen 5 years ago
committed by Ludovic Courtès
parent
commit
2e009ae7cd
No known key found for this signature in database GPG Key ID: 90B11993D9AEBB5
  1. 10
      nix/nix-daemon/nix-daemon.cc

10
nix/nix-daemon/nix-daemon.cc

@ -436,7 +436,15 @@ static void performOp(bool trusted, unsigned int clientVersion,
bool sign = readInt(from) == 1;
startWork();
TunnelSink sink(to);
store->exportPath(path, sign, sink);
try {
store->exportPath(path, sign, sink);
}
catch (Error &e) {
/* Flush SINK beforehand or its destructor will rightfully trigger
an assertion failure. */
sink.flush();
throw e;
}
sink.flush();
stopWork();
writeInt(1, to);

Loading…
Cancel
Save