diff options
| author | Martin Weinelt <hexa@darmstadt.ccc.de> | 2021-04-30 03:23:55 +0200 |
|---|---|---|
| committer | Martin Weinelt <hexa@darmstadt.ccc.de> | 2021-04-30 18:49:43 +0200 |
| commit | 506bc7ba029d4c587af532aff5bc7d66bba1fe53 (patch) | |
| tree | 58f08b88759304d737a904156564ea0e72f2ca88 /pkgs/development/python-modules/python-mapnik | |
| parent | dbcbb7ec48efe48f593676fde8437d8f1fcfa0f3 (diff) | |
nixos/nginx: update hardening settings
- Set an explicit umask that allows u+rwx and g+r.
- Adds `ProtectControlGroups` and `ProtectKernelLogs`, there should be
no need to access either.
- Adds `ProtectClock` to prevent write-access to the system clock.
- `ProtectProc` hides processes from other users within the /proc
filesystem and `ProcSubSet` hides all files/directories unrelated to
the process management of the units process.
- Sets `RemoveIPC`, as there is no SysV or POSIX IPC within nginx that I
know of.
- Restricts the creation of arbitrary namespaces
- Adds a reasonable `SystemCallFilter` preventing calls to @privileged,
@obsolete and others.
And finally applies some sorting based on the order these options appear
in systemd.exec(5).
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik')
0 files changed, 0 insertions, 0 deletions
