oci-tools: Adds additional arguments and fixes a bug #93923
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Motivation for this change
This improves the
pkgs.ociTools.buildContainer
with some additional arguments. It also formats the file and fixes a bug where one of the arguments was unused.Assuming the new arguments are left with default values, the derivation is almost identical to what it was before this commit. The only different is that the key
process.env
inconfig.json
was not present before, while after this commit it will be an empty dictionary.I am currently using this improved
ociTools
on my machine to build an ephemeral tor-browser inside a container, which is then started withrunc
.The added arguments are:
uid
=> put intoprocess.user.uid
inconfig.json
gid
=> put intoprocess.user.gid
inconfig.json
processEnv
=> mapped to the right format and put intoprocess.env
inconfig.json
.namespaces
=> mapped to the right format and put intolinux.namespaces
inconfig.json
.shm-size
=> put into the mount options for the/dev/shm
mount entry inconfig.json
.extraConfig
=> merged with the existing attributes inconfig.json
.extraSetupCommands
=> run as part of the command to build the derivation. Useful for e.g. creating extra directories in the resulting rootfs.Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)