diff --git a/nixos/modules/services/networking/vdirsyncer.nix b/nixos/modules/services/networking/vdirsyncer.nix index 692ce12c7a6c..325c7e60a11d 100644 --- a/nixos/modules/services/networking/vdirsyncer.nix +++ b/nixos/modules/services/networking/vdirsyncer.nix @@ -45,6 +45,7 @@ let } // (optionalAttrs (cfg'.user == null) { DynamicUser = true; + ProtectHome = true; }) // (optionalAttrs (cfg'.additionalGroups != [ ]) { SupplementaryGroups = cfg'.additionalGroups; @@ -63,7 +64,6 @@ let PrivateTmp = true; NoNewPrivileges = true; ProtectSystem = "strict"; - ProtectHome = true; ProtectKernelTunables = true; ProtectKernelModules = true; ProtectControlGroups = true; diff --git a/nixos/tests/vdirsyncer.nix b/nixos/tests/vdirsyncer.nix index bd7b8316eff3..2376a6d689a1 100644 --- a/nixos/tests/vdirsyncer.nix +++ b/nixos/tests/vdirsyncer.nix @@ -217,13 +217,6 @@ import ./make-test-python.nix ( }; }; - # ProtectHome is the default, but we must access our storage - # in ~. - systemd.services = { - "vdirsyncer@alice".serviceConfig.ProtectHome = lib.mkForce false; - "vdirsyncer@bob".serviceConfig.ProtectHome = lib.mkForce false; - }; - users.users = { alice.isNormalUser = true; bob.isNormalUser = true;