Unverified Commit 11d4f6e4 authored by oddlama's avatar oddlama
Browse files

nixos/typesense: disable MemoryDenyWriteExecute which is needed since 0.25.1

also adjust default state directory mode to allow typesense group
parent 9edb077a
Loading
Loading
Loading
Loading
+2 −2
Original line number Diff line number Diff line
@@ -83,12 +83,12 @@ in {
        Group = "typesense";

        StateDirectory = "typesense";
        StateDirectoryMode = "0700";
        StateDirectoryMode = "0750";

        # Hardening
        CapabilityBoundingSet = "";
        LockPersonality = true;
        MemoryDenyWriteExecute = true;
        # MemoryDenyWriteExecute = true; needed since 0.25.1
        NoNewPrivileges = true;
        PrivateUsers = true;
        PrivateTmp = true;