about summary refs log tree commit diff
path: root/nixos/modules/security/chromium-suid-sandbox.nix
blob: b517e879f04ef9e21c14a6e900f44ed6f390eacb (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
{ config, lib, pkgs, ... }:

with lib;

let
  cfg     = config.security.chromiumSuidSandbox;
  sandbox = pkgs.chromium.sandbox;
in
{
  options.security.chromiumSuidSandbox.enable = mkEnableOption ''
    Whether to install the Chromium SUID sandbox which is an executable that
    Chromium may use in order to achieve sandboxing.

    If you get the error "The SUID sandbox helper binary was found, but is not
    configured correctly.", turning this on might help.

    Also, if the URL chrome://sandbox tells you that "You are not adequately
    sandboxed!", turning this on might resolve the issue.

    Finally, if you have <option>security.grsecurity</option> enabled and you
    use Chromium, you probably need this.
  '';

  config = mkIf cfg.enable {
    environment.systemPackages = [ sandbox ];
    security.setuidPrograms    = [ sandbox.passthru.sandboxExecutableName ];
  };
}