Hi,

Marc Weber <[EMAIL PROTECTED]> writes:

> What happens if a user subscribes to a channel which contains malicious
> packages? I mean if the user installs a malicious package this way and
> the sysadmin does so as well but maybe two days later. Then the sysadmin
> won't install anything but reuse the existing (manipulated) store path..
>
> Am I missing a point here?

Yes, `nix-pull' must be run as root currently, since
`/nix/var/nix/manifests' is not world-writable.

Thanks,
Ludo'.

_______________________________________________
nix-dev mailing list
[email protected]
https://mail.cs.uu.nl/mailman/listinfo/nix-dev

Reply via email to