diff --git a/objectifier-module.nix b/objectifier-module.nix index 5a96a1f..a5e5b18 100644 --- a/objectifier-module.nix +++ b/objectifier-module.nix @@ -77,11 +77,11 @@ in { ProtectHome = true; ProtectClock = true; ProtectKernelLogs = true; - DynamicUser = true; + # DynamicUser = true; MemoryDenyWriteExecute = true; RestrictRealtime = true; - # LockPersonality = true; - # PermissionsStartOnly = true; + LockPersonality = true; + PermissionsStartOnly = true; WorkingDirectory = "${pkgs.objectifier}"; StateDirectory = "objectifier"; CacheDirectory = "objectifier";