nixos/pocket-id: harden after backend-frontend merge

This commit is contained in:
Gutyina Gergő
2025-06-03 23:15:45 +02:00
parent f4249b03a9
commit 259a75fb1f
@@ -174,12 +174,12 @@ in
CapabilityBoundingSet = "";
DeviceAllow = "";
DevicePolicy = "closed";
#IPAddressDeny = "any"; # communicates with the frontend
#IPAddressDeny = "any"; # provides the service through network
LockPersonality = true;
MemoryDenyWriteExecute = true;
NoNewPrivileges = true;
PrivateDevices = true;
PrivateNetwork = false; # communicates with the frontend
PrivateNetwork = false; # provides the service through network
PrivateTmp = true;
PrivateUsers = true;
ProcSubset = "pid";
@@ -191,7 +191,8 @@ in
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
ProtectSystem = "full"; # needs to write in cfg.dataDir
ProtectSystem = "strict";
ReadWritePaths = [ cfg.dataDir ];
RemoveIPC = true;
RestrictAddressFamilies = [
"AF_INET"
@@ -212,7 +213,7 @@ in
"@privileged"
"@raw-io"
"@reboot"
#"@resources" # vm test segfaults
"@resources"
"@swap"
];
UMask = "0077";