diff options
| author | Félix Baylac-Jacqué <felix@alternativebit.fr> | 2020-04-26 15:18:49 +0200 |
|---|---|---|
| committer | Félix Baylac-Jacqué <felix@alternativebit.fr> | 2020-04-30 20:40:00 +0200 |
| commit | 353a8b58e6b12daf2977870743a6dd85ee080448 (patch) | |
| tree | 1e4b09b7ceeb47a739a22fb7e664364ab7c1a4cf /pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch | |
| parent | 8aea5288725688f7f71bf12c8ee1bb83147b22c6 (diff) | |
nixos/prosody: leverage systemd sandbox features to harden service
We are leveraging the systemd sandboxing features to prevent the
service accessing locations it shouldn't do. Most notably, we are here
preventing the prosody service from accessing /home and providing it
with a private /dev and /tmp.
Please consult man systemd.exec for further informations.
Diffstat (limited to 'pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch')
0 files changed, 0 insertions, 0 deletions
