summary refs log tree commit diff
path: root/nixos/modules/services/security/usbguard.nix
diff options
context:
space:
mode:
authorNadrieril <nadrieril@gmail.com>2018-08-30 21:50:43 +0100
committerNadrieril <nadrieril@gmail.com>2018-08-30 21:54:22 +0100
commit9b9ba8405bc9ba6965f82f7806b22c31f3514898 (patch)
tree1e4f08610d4aacb4167fe3f8beece4756bb21acf /nixos/modules/services/security/usbguard.nix
parent08148a746a47bd1a6888485226a5b55bb2754549 (diff)
downloadnixpkgs-9b9ba8405bc9ba6965f82f7806b22c31f3514898.tar
nixpkgs-9b9ba8405bc9ba6965f82f7806b22c31f3514898.tar.gz
nixpkgs-9b9ba8405bc9ba6965f82f7806b22c31f3514898.tar.bz2
nixpkgs-9b9ba8405bc9ba6965f82f7806b22c31f3514898.tar.lz
nixpkgs-9b9ba8405bc9ba6965f82f7806b22c31f3514898.tar.xz
nixpkgs-9b9ba8405bc9ba6965f82f7806b22c31f3514898.tar.zst
nixpkgs-9b9ba8405bc9ba6965f82f7806b22c31f3514898.zip
nixos/usbguard: ensure the audit log file can be created
Since version 0.7.3, usbguard-daemon won't start if the file cannot be opened.
Diffstat (limited to 'nixos/modules/services/security/usbguard.nix')
-rw-r--r--nixos/modules/services/security/usbguard.nix5
1 files changed, 4 insertions, 1 deletions
diff --git a/nixos/modules/services/security/usbguard.nix b/nixos/modules/services/security/usbguard.nix
index 48950fe4c22..88d2f69db57 100644
--- a/nixos/modules/services/security/usbguard.nix
+++ b/nixos/modules/services/security/usbguard.nix
@@ -188,7 +188,10 @@ in {
       wants = [ "systemd-udevd.service" "local-fs.target" ];
 
       # make sure an empty rule file and required directories exist
-      preStart = ''mkdir -p $(dirname "${cfg.ruleFile}") "${cfg.IPCAccessControlFiles}" && ([ -f "${cfg.ruleFile}" ] || touch ${cfg.ruleFile})'';
+      preStart = ''
+        mkdir -p $(dirname "${cfg.ruleFile}") $(dirname "${cfg.auditFilePath}") "${cfg.IPCAccessControlFiles}" \
+          && ([ -f "${cfg.ruleFile}" ] || touch ${cfg.ruleFile})
+      '';
 
       serviceConfig = {
         Type = "simple";