Remove Some Static IDs (#367563)
This commit is contained in:
@@ -102,6 +102,7 @@ nixos/modules/installer/tools/nix-fallback-paths.nix @NixOS/nix-team @raitobeza
|
||||
/nixos/default.nix @infinisil
|
||||
/nixos/lib/from-env.nix @infinisil
|
||||
/nixos/lib/eval-config.nix @infinisil
|
||||
/nixos/modules/misc/ids.nix @R-VdP
|
||||
/nixos/modules/system/activation/bootspec.nix @grahamc @cole-h @raitobezarius
|
||||
/nixos/modules/system/activation/bootspec.cue @grahamc @cole-h @raitobezarius
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@ in
|
||||
config = lib.mkIf cfg.enable {
|
||||
boot.kernelModules = [ "uinput" ];
|
||||
|
||||
users.groups.uinput.gid = config.ids.gids.uinput;
|
||||
users.groups.uinput = { };
|
||||
|
||||
services.udev.extraRules = ''
|
||||
SUBSYSTEM=="misc", KERNEL=="uinput", MODE="0660", GROUP="uinput", OPTIONS+="static_node=uinput"
|
||||
|
||||
@@ -2,12 +2,15 @@
|
||||
# central list to prevent id collisions.
|
||||
|
||||
# IMPORTANT!
|
||||
# We only add static uids and gids for services where it is not feasible
|
||||
# to change uids/gids on service start, for example a service with a lot of
|
||||
# files. Please also check if the service is applicable for systemd's
|
||||
# DynamicUser option and does not need a uid/gid allocation at all.
|
||||
# Systemd can also change ownership of service directories using the
|
||||
# RuntimeDirectory/StateDirectory options.
|
||||
#
|
||||
# https://github.com/NixOS/rfcs/blob/master/rfcs/0052-dynamic-ids.md
|
||||
#
|
||||
# Use of static ids is deprecated within NixOS. Dynamic allocation is
|
||||
# required, barring special circumstacnes. Please check if the service
|
||||
# is applicable for systemd's DynamicUser option and does not need a
|
||||
# uid/gid allocation at all. Systemd can also change ownership of
|
||||
# service directories using the RuntimeDirectory/StateDirectory
|
||||
# options.
|
||||
|
||||
{ lib, ... }:
|
||||
|
||||
@@ -355,7 +358,6 @@ in
|
||||
rstudio-server = 324;
|
||||
localtimed = 325;
|
||||
automatic-timezoned = 326;
|
||||
whisparr = 328;
|
||||
|
||||
# When adding a uid, make sure it doesn't match an existing gid.
|
||||
#
|
||||
@@ -683,8 +685,6 @@ in
|
||||
rstudio-server = 324;
|
||||
localtimed = 325;
|
||||
automatic-timezoned = 326;
|
||||
uinput = 327;
|
||||
whisparr = 328;
|
||||
|
||||
# When adding a gid, make sure it doesn't match an existing
|
||||
# uid. Users and groups with the same name should have equal
|
||||
|
||||
@@ -64,10 +64,10 @@ in
|
||||
whisparr = {
|
||||
group = cfg.group;
|
||||
home = cfg.dataDir;
|
||||
uid = config.ids.uids.whisparr;
|
||||
isSystemUser = true;
|
||||
};
|
||||
};
|
||||
|
||||
users.groups = lib.mkIf (cfg.group == "whisparr") { whisparr.gid = config.ids.gids.whisparr; };
|
||||
users.groups.whisparr = lib.mkIf (cfg.group == "whisparr") { };
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user