summary refs log tree commit diff
diff options
context:
space:
mode:
authorIzorkin <izorkin@elven.pw>2020-08-15 11:13:44 +0300
committerIzorkin <izorkin@elven.pw>2020-08-15 11:21:09 +0300
commit26898b851803f046faa70c5e254dabfaf8af3de7 (patch)
tree834f6722ad958a15ae52a3f338d2fdfccc7fabb2
parentd56514c76a3a2f3c1523936ea00b620b4d7b2cad (diff)
downloadnixpkgs-26898b851803f046faa70c5e254dabfaf8af3de7.tar
nixpkgs-26898b851803f046faa70c5e254dabfaf8af3de7.tar.gz
nixpkgs-26898b851803f046faa70c5e254dabfaf8af3de7.tar.bz2
nixpkgs-26898b851803f046faa70c5e254dabfaf8af3de7.tar.lz
nixpkgs-26898b851803f046faa70c5e254dabfaf8af3de7.tar.xz
nixpkgs-26898b851803f046faa70c5e254dabfaf8af3de7.tar.zst
nixpkgs-26898b851803f046faa70c5e254dabfaf8af3de7.zip
nixos/unit: update sandboxing options
-rw-r--r--nixos/modules/services/web-servers/unit/default.nix3
1 files changed, 3 insertions, 0 deletions
diff --git a/nixos/modules/services/web-servers/unit/default.nix b/nixos/modules/services/web-servers/unit/default.nix
index 65dcdbed000..894271d1e55 100644
--- a/nixos/modules/services/web-servers/unit/default.nix
+++ b/nixos/modules/services/web-servers/unit/default.nix
@@ -120,9 +120,12 @@ in {
         ProtectHome = true;
         PrivateTmp = true;
         PrivateDevices = true;
+        PrivateUsers = false;
         ProtectHostname = true;
+        ProtectClock = true;
         ProtectKernelTunables = true;
         ProtectKernelModules = true;
+        ProtectKernelLogs = true;
         ProtectControlGroups = true;
         RestrictAddressFamilies = [ "AF_UNIX" "AF_INET" "AF_INET6" ];
         LockPersonality = true;