diff options
author | Vladimír Čunát <v@cunat.cz> | 2020-10-07 11:15:18 +0200 |
---|---|---|
committer | Vladimír Čunát <v@cunat.cz> | 2020-10-07 12:22:18 +0200 |
commit | 420f89ceb267b461eed5d025b6c3c0e57703cc5c (patch) | |
tree | 373179c02e9fd698fdb9c2b6fa1f4fd9b9a2dc87 /nixos/modules/virtualisation/lxd.nix | |
parent | 3b0886c9af7fadcb46fc04c28cf5b79280d38371 (diff) | |
download | nixpkgs-420f89ceb267b461eed5d025b6c3c0e57703cc5c.tar nixpkgs-420f89ceb267b461eed5d025b6c3c0e57703cc5c.tar.gz nixpkgs-420f89ceb267b461eed5d025b6c3c0e57703cc5c.tar.bz2 nixpkgs-420f89ceb267b461eed5d025b6c3c0e57703cc5c.tar.lz nixpkgs-420f89ceb267b461eed5d025b6c3c0e57703cc5c.tar.xz nixpkgs-420f89ceb267b461eed5d025b6c3c0e57703cc5c.tar.zst nixpkgs-420f89ceb267b461eed5d025b6c3c0e57703cc5c.zip |
Revert "apparmor: fix and improve the service"
This reverts commit fb6d63f3fdd95a5468d43a0693c8ca7c1894363f. I really hope this finally fixes #99236: evaluation on Hydra. This time I really did check basically the same commit on Hydra: https://hydra.nixos.org/eval/1618011 Right now I don't have energy to find what exactly is wrong in the commit, and it doesn't seem important in comparison to nixos-unstable channel being stuck on a commit over one week old.
Diffstat (limited to 'nixos/modules/virtualisation/lxd.nix')
-rw-r--r-- | nixos/modules/virtualisation/lxd.nix | 12 |
1 files changed, 4 insertions, 8 deletions
diff --git a/nixos/modules/virtualisation/lxd.nix b/nixos/modules/virtualisation/lxd.nix index 876956f654b..3958fc2c1d7 100644 --- a/nixos/modules/virtualisation/lxd.nix +++ b/nixos/modules/virtualisation/lxd.nix @@ -93,15 +93,11 @@ in security.apparmor = { enable = true; + profiles = [ + "${cfg.lxcPackage}/etc/apparmor.d/usr.bin.lxc-start" + "${cfg.lxcPackage}/etc/apparmor.d/lxc-containers" + ]; packages = [ cfg.lxcPackage ]; - policies = { - "bin.lxc-start".profile = '' - include ${cfg.lxcPackage}/etc/apparmor.d/usr.bin.lxc-start - ''; - "lxc-containers".profile = '' - include ${cfg.lxcPackage}/etc/apparmor.d/lxc-containers - ''; - }; }; systemd.services.lxd = { |