diff options
author | rnhmjoj <rnhmjoj@inventati.org> | 2021-10-03 11:43:13 +0200 |
---|---|---|
committer | rnhmjoj <rnhmjoj@inventati.org> | 2021-10-03 11:44:57 +0200 |
commit | 31790c81dcffee8c267cbc01f16938497ed172af (patch) | |
tree | 833ade1312a99c22ac689fe281320d675e9c3fd9 /nixos/modules/services/mail/postfix.nix | |
parent | 378d2c5dcec7fef958cca3760448c09a9be2b7a3 (diff) | |
download | nixpkgs-31790c81dcffee8c267cbc01f16938497ed172af.tar nixpkgs-31790c81dcffee8c267cbc01f16938497ed172af.tar.gz nixpkgs-31790c81dcffee8c267cbc01f16938497ed172af.tar.bz2 nixpkgs-31790c81dcffee8c267cbc01f16938497ed172af.tar.lz nixpkgs-31790c81dcffee8c267cbc01f16938497ed172af.tar.xz nixpkgs-31790c81dcffee8c267cbc01f16938497ed172af.tar.zst nixpkgs-31790c81dcffee8c267cbc01f16938497ed172af.zip |
nixos: make setgid wrappers root-owned
Diffstat (limited to 'nixos/modules/services/mail/postfix.nix')
-rw-r--r-- | nixos/modules/services/mail/postfix.nix | 8 |
1 files changed, 4 insertions, 4 deletions
diff --git a/nixos/modules/services/mail/postfix.nix b/nixos/modules/services/mail/postfix.nix index da18fae4ca7..6610399cad6 100644 --- a/nixos/modules/services/mail/postfix.nix +++ b/nixos/modules/services/mail/postfix.nix @@ -673,7 +673,7 @@ in services.mail.sendmailSetuidWrapper = mkIf config.services.postfix.setSendmail { program = "sendmail"; source = "${pkgs.postfix}/bin/sendmail"; - owner = "nobody"; + owner = "root"; group = setgidGroup; setuid = false; setgid = true; @@ -682,7 +682,7 @@ in security.wrappers.mailq = { program = "mailq"; source = "${pkgs.postfix}/bin/mailq"; - owner = "nobody"; + owner = "root"; group = setgidGroup; setuid = false; setgid = true; @@ -691,7 +691,7 @@ in security.wrappers.postqueue = { program = "postqueue"; source = "${pkgs.postfix}/bin/postqueue"; - owner = "nobody"; + owner = "root"; group = setgidGroup; setuid = false; setgid = true; @@ -700,7 +700,7 @@ in security.wrappers.postdrop = { program = "postdrop"; source = "${pkgs.postfix}/bin/postdrop"; - owner = "nobody"; + owner = "root"; group = setgidGroup; setuid = false; setgid = true; |