summary refs log tree commit diff
path: root/nixos/modules/security
diff options
context:
space:
mode:
authorNikolay Amiantov <ab@fmap.me>2016-08-30 22:42:19 +0400
committerGitHub <noreply@github.com>2016-08-30 22:42:19 +0400
commit509733a34393b5cb15dbb04ed597e069e08d345a (patch)
tree12175bb3ecf8f55557f4a33fc3d1323a6b84e12a /nixos/modules/security
parentcb4cd5d7f03a12cc53b1ce5bd83572786a5f6ab7 (diff)
parent6efcfe03ae4ef426b77a6827243433b5296613a4 (diff)
downloadnixpkgs-509733a34393b5cb15dbb04ed597e069e08d345a.tar
nixpkgs-509733a34393b5cb15dbb04ed597e069e08d345a.tar.gz
nixpkgs-509733a34393b5cb15dbb04ed597e069e08d345a.tar.bz2
nixpkgs-509733a34393b5cb15dbb04ed597e069e08d345a.tar.lz
nixpkgs-509733a34393b5cb15dbb04ed597e069e08d345a.tar.xz
nixpkgs-509733a34393b5cb15dbb04ed597e069e08d345a.tar.zst
nixpkgs-509733a34393b5cb15dbb04ed597e069e08d345a.zip
Merge pull request #17822 from abbradar/systemd-mounts
nixos filesystems: unify special filesystems handling
Diffstat (limited to 'nixos/modules/security')
-rw-r--r--nixos/modules/security/hidepid.nix19
1 files changed, 1 insertions, 18 deletions
diff --git a/nixos/modules/security/hidepid.nix b/nixos/modules/security/hidepid.nix
index 8271578c55d..4917327d617 100644
--- a/nixos/modules/security/hidepid.nix
+++ b/nixos/modules/security/hidepid.nix
@@ -20,23 +20,6 @@ with lib;
   config = mkIf config.security.hideProcessInformation {
     users.groups.proc.gid = config.ids.gids.proc;
 
-    systemd.services.hidepid = {
-      wantedBy = [ "local-fs.target" ];
-      after = [ "systemd-remount-fs.service" ];
-      before = [ "local-fs-pre.target" "local-fs.target" "shutdown.target" ];
-      wants = [ "local-fs-pre.target" ];
-
-      serviceConfig = {
-        Type = "oneshot";
-        RemainAfterExit = true;
-        ExecStart = ''${pkgs.utillinux}/bin/mount -o remount,hidepid=2,gid=${toString config.ids.gids.proc} /proc'';
-        ExecStop = ''${pkgs.utillinux}/bin/mount -o remount,hidepid=0,gid=0 /proc'';
-      };
-
-      unitConfig = {
-        DefaultDependencies = false;
-        Conflicts = "shutdown.target";
-      };
-    };
+    fileSystems."/proc".options = [ "hidepid=2" "gid=${toString config.ids.gids.proc}" ];
   };
 }