diff options
| author | rnhmjoj <rnhmjoj@inventati.org> | 2021-09-29 12:09:20 +0200 |
|---|---|---|
| committer | rnhmjoj <rnhmjoj@inventati.org> | 2021-09-29 12:31:34 +0200 |
| commit | dd9883b2fbd2b9ea01d53654d383b29b4d68d05a (patch) | |
| tree | 7b9f043bacea88bb643a1353ce998b260fcbd0be /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch | |
| parent | a46a8a13deefc3744a62efa0a83cab2b353f173a (diff) | |
nixos/dhcpd: switch to DynamicUser
The service can run unprivileged -- by using capabilities -- and the
uid/gid can be dynamically allocated since there are only a handful of
state files.
This change improves the overall security of the service by leveraging
systemd's hardening and getting rids of `nogroup` and the initial root
permissions (before the daemon drop privileges).
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions
