nixos/tor: add onion service unix sockets to BindPaths (#440889)

This commit is contained in:
h7x4
2025-10-13 14:22:31 +00:00
committed by GitHub

View File

@@ -1410,7 +1410,14 @@ in
RootDirectoryStartOnly = true;
#InaccessiblePaths = [ "-+${runDir}/root" ];
UMask = "0066";
BindPaths = [ stateDir ];
BindPaths = [
stateDir
]
++ lib.catAttrs "unix" (
lib.catAttrs "target" (
lib.concatMap (onionService: onionService.map) (lib.attrValues cfg.relay.onionServices)
)
);
BindReadOnlyPaths = [
builtins.storeDir
"/etc"