summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch
diff options
context:
space:
mode:
authorMartin Weinelt <hexa@darmstadt.ccc.de>2021-04-30 03:23:55 +0200
committerMartin Weinelt <hexa@darmstadt.ccc.de>2021-04-30 18:49:43 +0200
commit506bc7ba029d4c587af532aff5bc7d66bba1fe53 (patch)
tree58f08b88759304d737a904156564ea0e72f2ca88 /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch
parentdbcbb7ec48efe48f593676fde8437d8f1fcfa0f3 (diff)
nixos/nginx: update hardening settings
- Set an explicit umask that allows u+rwx and g+r. - Adds `ProtectControlGroups` and `ProtectKernelLogs`, there should be no need to access either. - Adds `ProtectClock` to prevent write-access to the system clock. - `ProtectProc` hides processes from other users within the /proc filesystem and `ProcSubSet` hides all files/directories unrelated to the process management of the units process. - Sets `RemoveIPC`, as there is no SysV or POSIX IPC within nginx that I know of. - Restricts the creation of arbitrary namespaces - Adds a reasonable `SystemCallFilter` preventing calls to @privileged, @obsolete and others. And finally applies some sorting based on the order these options appear in systemd.exec(5).
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions