diff options
| author | Martin Weinelt <hexa@darmstadt.ccc.de> | 2021-04-24 15:40:12 +0200 |
|---|---|---|
| committer | Martin Weinelt <hexa@darmstadt.ccc.de> | 2021-04-30 19:42:26 +0200 |
| commit | a691549f7e2e466aa3833992de55c72bcee36885 (patch) | |
| tree | 4d14077e18c113b4b0a03fc02a7374cbb888d894 /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch | |
| parent | e0f1e1f7bf7e27f92c1a0215a7cc19eeed0499dd (diff) | |
nixos/zigbee2mqtt: harden systemd unit
This is what is still exposed, and it allows me to control my lamps from
within home-assistant.
✗ PrivateNetwork= Service has access to the host's network 0.5
✗ RestrictAddressFamilies=~AF_(INET|INET6) Service may allocate Internet sockets 0.3
✗ DeviceAllow= Service has a device ACL with some special devices 0.1
✗ IPAddressDeny= Service does not define an IP address allow list 0.2
✗ PrivateDevices= Service potentially has access to hardware devices 0.2
✗ RootDirectory=/RootImage= Service runs within the host's root directory 0.1
✗ SupplementaryGroups= Service runs with supplementary groups 0.1
✗ MemoryDenyWriteExecute= Service may create writable executable memory mappings 0.1
→ Overall exposure level for zigbee2mqtt.service: 1.3 OK 🙂
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions
