setup.sh: use -exec rather than -execdir #177789
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Note: this is untested. I will undraft when I have verified it. That will take a while (global rebuild).nix build abuild
completed; rebuilding the rest of my userspace (should be done by morning)Description of changes
Busybox's
find
does not support-execdir
, so let's uses-exec
instead, in the spirit of requiring the minimum features needed for the task. The benefit of-execdir
over-exec
is robustness against TOCTOU (Time Of Check Time Of Use) attacks, which I believe are not a concern here.Some packages (e.g. abuild) put
busybox
into theirnativeBuildInputs
, which leads tosetup.sh
usingbusybox find
rather than$findutils/bin/find
(becausebusybox find
is earlier in the$PATH
). This PR will fix those packages, although it really isn't a good thing if they are inadvertently changing whichstdenv
-tools are being used bysetup.sh
. This PR should not be interpreted as encouraging that sort of thing.Things done
sandbox = true
set innix.conf
? (See Nix manual)nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)nixos/doc/manual/md-to-db.sh
to update generated release notes