nixos/tor: add onion service unix sockets to BindPaths (#440889)
This commit is contained in:
@@ -1410,7 +1410,14 @@ in
|
|||||||
RootDirectoryStartOnly = true;
|
RootDirectoryStartOnly = true;
|
||||||
#InaccessiblePaths = [ "-+${runDir}/root" ];
|
#InaccessiblePaths = [ "-+${runDir}/root" ];
|
||||||
UMask = "0066";
|
UMask = "0066";
|
||||||
BindPaths = [ stateDir ];
|
BindPaths = [
|
||||||
|
stateDir
|
||||||
|
]
|
||||||
|
++ lib.catAttrs "unix" (
|
||||||
|
lib.catAttrs "target" (
|
||||||
|
lib.concatMap (onionService: onionService.map) (lib.attrValues cfg.relay.onionServices)
|
||||||
|
)
|
||||||
|
);
|
||||||
BindReadOnlyPaths = [
|
BindReadOnlyPaths = [
|
||||||
builtins.storeDir
|
builtins.storeDir
|
||||||
"/etc"
|
"/etc"
|
||||||
|
|||||||
Reference in New Issue
Block a user