Merge pull request #61032 from dtzWill/feature/rngd-harden
rngd: harden service config, settings from arch
This commit is contained in:
commit
e8d7f17c81
@ -42,6 +42,11 @@ in
|
|||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
ExecStart = "${pkgs.rng-tools}/sbin/rngd -f"
|
ExecStart = "${pkgs.rng-tools}/sbin/rngd -f"
|
||||||
+ optionalString cfg.debug " -d";
|
+ optionalString cfg.debug " -d";
|
||||||
|
NoNewPrivileges = true;
|
||||||
|
PrivateNetwork = true;
|
||||||
|
PrivateTmp = true;
|
||||||
|
ProtectSystem = "full";
|
||||||
|
ProtectHome = true;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
Loading…
Reference in New Issue
Block a user