diff options
| author | Dominique Martinet <asmadeus@codewreck.org> | 2025-01-09 20:10:24 +0900 |
|---|---|---|
| committer | Valentin Gagarin <valentin@gagarin.work> | 2025-03-25 13:37:25 +0000 |
| commit | fb5e34fb3976a8a3dbef502e2863c23619a1f596 (patch) | |
| tree | 34aa8d224651d4b1def308b76db27f378e7324ad /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch | |
| parent | 8407a64b5ca97888b29f4c543d580ab9db8b275b (diff) | |
nixos/cryptpad: fix service with nodejs 22.11 (for real)
The previous fix had only been tested locally through a runtime edit of
the service, and the order in which @chown had been re-added was
different so commit cf498c1a61b3 ("nixos/cryptpad: fix service with
nodejs 22.11") did not actually fix the issue.
This properly orders @chown after @privileged so the rule is respected,
and also properly denies with EPERM instead of allowing the chown family
of syscalls: this will properly prevent seccomp from killing nodejs
while still disallowing fchown()
Fixes https://github.com/NixOS/nixpkgs/issues/370717
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions
