From 4a6b8fc482de90b96f1290a6a0c687dc4fdadae1 Mon Sep 17 00:00:00 2001 From: Mikhail Klementev Date: Wed, 17 Jul 2019 17:30:19 +0000 Subject: [PATCH] Mount /nix inside docker --- security.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/security.nix b/security.nix index 2a6bf89..4e325a8 100644 --- a/security.nix +++ b/security.nix @@ -2,7 +2,7 @@ let fhs = pkgs.writeShellScriptBin "fhs" - ("${pkgs.docker}/bin/docker run -v /home/user:/home/user "+ + ("${pkgs.docker}/bin/docker run -v /home/user:/home/user -v /nix:/nix "+ "-e \"HOST_PWD=$PWD\" -it fhs"); in { security.allowUserNamespaces = true; @@ -55,7 +55,7 @@ in { (writeShellScriptBin "fhs-ptrace" ("sudo ${pkgs.docker}/bin/docker run -v /home/user:/home/user " + "--cap-add=SYS_PTRACE --security-opt seccomp=unconfined" + - " -e \"HOST_PWD=$PWD\" -it fhs")) + " -e \"HOST_PWD=$PWD\" -v /nix=/nix -it fhs")) ]; security.wrappers = {