diff options
| author | Felix Singer <felixsinger@posteo.net> | 2024-10-10 07:12:28 +0200 |
|---|---|---|
| committer | Felix Singer <felixsinger@posteo.net> | 2024-10-10 07:12:28 +0200 |
| commit | 3d30811d4edeeeee1740a07b21a41f4f257dd5a1 (patch) | |
| tree | 0cf8d9f5a42b50cc3ca84a2aa865203d64863747 /pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch | |
| parent | 6b955bdbb9efe4a5c047746323951fe1bdf8d01b (diff) | |
nixos/gerrit: Apply initial hardening using the systemd unit
These options are a good start for sandboxing the service. It's planned
to set `ProtectSystem` to `strict` instead of `full`, but that requires
specific directories to be configured as writable. It's also planned to
filter system calls. However, that requires more testing but it
shouldn't prevent us from applying these options for now and add others
later.
Signed-off-by: Felix Singer <felixsinger@posteo.net>
Diffstat (limited to 'pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch')
0 files changed, 0 insertions, 0 deletions
