Fuck it, allow everything for now
This commit is contained in:
parent
9ea8c59f48
commit
f92c5ce3a3
|
@ -63,26 +63,25 @@ in {
|
||||||
OBJECTIFIER_BUFFER_SIZE = "524288";
|
OBJECTIFIER_BUFFER_SIZE = "524288";
|
||||||
OBJECTIFIER_CLEANUP_MAX_AGE = toString cfg.cleanup.max_file_age;
|
OBJECTIFIER_CLEANUP_MAX_AGE = toString cfg.cleanup.max_file_age;
|
||||||
OBJECTIFIER_CLEANUP_DELAY = toString cfg.cleanup.delay;
|
OBJECTIFIER_CLEANUP_DELAY = toString cfg.cleanup.delay;
|
||||||
TMPDIR = "/tmp";
|
|
||||||
};
|
};
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
PrivateUsers = true;
|
# PrivateUsers = true;
|
||||||
PrivateDevices = true;
|
# PrivateDevices = true;
|
||||||
PrivateTmp = true;
|
# PrivateTmp = true;
|
||||||
PrivateMounts = true;
|
# PrivateMounts = true;
|
||||||
ProtectControlGroups = true;
|
# ProtectControlGroups = true;
|
||||||
ProtectKernelTunables = true;
|
# ProtectKernelTunables = true;
|
||||||
ProtectKernelModules = true;
|
# ProtectKernelModules = true;
|
||||||
ProtectSystem = true;
|
# ProtectSystem = true;
|
||||||
ProtectHostname = true;
|
# ProtectHostname = true;
|
||||||
ProtectHome = true;
|
# ProtectHome = true;
|
||||||
ProtectClock = true;
|
# ProtectClock = true;
|
||||||
ProtectKernelLogs = true;
|
# ProtectKernelLogs = true;
|
||||||
DynamicUser = true;
|
# DynamicUser = true;
|
||||||
MemoryDenyWriteExecute = true;
|
# MemoryDenyWriteExecute = true;
|
||||||
RestrictRealtime = true;
|
# RestrictRealtime = true;
|
||||||
LockPersonality = true;
|
# LockPersonality = true;
|
||||||
PermissionsStartOnly = true;
|
# PermissionsStartOnly = true;
|
||||||
WorkingDirectory = "${pkgs.objectifier}";
|
WorkingDirectory = "${pkgs.objectifier}";
|
||||||
StateDirectory = "objectifier";
|
StateDirectory = "objectifier";
|
||||||
CacheDirectory = "objectifier";
|
CacheDirectory = "objectifier";
|
||||||
|
|
Loading…
Reference in New Issue