diff options
| author | Gary Guo <gary@garyguo.net> | 2023-11-05 20:48:21 +0000 |
|---|---|---|
| committer | Gary Guo <gary@garyguo.net> | 2023-11-06 20:22:27 +0000 |
| commit | de6c5343b6ab22fb8c2f76c8f5424d119a4727f6 (patch) | |
| tree | d7e40e11fe2064b4f2880fe41963d70a17ac623f /pkgs/development/python-modules/python-openstackclient/git@git.tavy.me:nixos | |
| parent | c70614c0a4f8b5239bb5fd0df1f9da6e0b9dd006 (diff) | |
nixos/unbound: remove setuid/gid capability
If username is set, then unbound will try to become that user using
`setusercontext`. But this is pointless since we are already instructing
systemd to launch unbound with that user.
So force username to be empty, which disables this behaviour in unbound.
This allows us to remove the capability granted, and also tighten the
syscall filter.
Diffstat (limited to 'pkgs/development/python-modules/python-openstackclient/git@git.tavy.me:nixos')
0 files changed, 0 insertions, 0 deletions
