summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch
diff options
context:
space:
mode:
authorMartin Weinelt <hexa@darmstadt.ccc.de>2021-04-24 15:40:12 +0200
committerMartin Weinelt <hexa@darmstadt.ccc.de>2021-04-30 19:42:26 +0200
commita691549f7e2e466aa3833992de55c72bcee36885 (patch)
tree4d14077e18c113b4b0a03fc02a7374cbb888d894 /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch
parente0f1e1f7bf7e27f92c1a0215a7cc19eeed0499dd (diff)
nixos/zigbee2mqtt: harden systemd unit
This is what is still exposed, and it allows me to control my lamps from within home-assistant. ✗ PrivateNetwork= Service has access to the host's network 0.5 ✗ RestrictAddressFamilies=~AF_(INET|INET6) Service may allocate Internet sockets 0.3 ✗ DeviceAllow= Service has a device ACL with some special devices 0.1 ✗ IPAddressDeny= Service does not define an IP address allow list 0.2 ✗ PrivateDevices= Service potentially has access to hardware devices 0.2 ✗ RootDirectory=/RootImage= Service runs within the host's root directory 0.1 ✗ SupplementaryGroups= Service runs with supplementary groups 0.1 ✗ MemoryDenyWriteExecute= Service may create writable executable memory mappings 0.1 → Overall exposure level for zigbee2mqtt.service: 1.3 OK 🙂
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions