Unverified Commit 585a8b12 authored by Cabia Rangris's avatar Cabia Rangris Committed by GitHub
Browse files

Merge pull request #258853 from SuperSandro2000/dex

nixos/dex: fix start with latest systemd update
parents 9c30003e 39e1727f
Loading
Loading
Loading
Loading
+2 −5
Original line number Diff line number Diff line
@@ -108,8 +108,7 @@ in
        ProtectClock = true;
        ProtectHome = true;
        ProtectHostname = true;
        # Would re-mount paths ignored by temporary root
        #ProtectSystem = "strict";
        ProtectSystem = "strict";
        ProtectControlGroups = true;
        ProtectKernelLogs = true;
        ProtectKernelModules = true;
@@ -121,9 +120,7 @@ in
        RestrictSUIDSGID = true;
        SystemCallArchitectures = "native";
        SystemCallFilter = [ "@system-service" "~@privileged @setuid @keyring" ];
        TemporaryFileSystem = "/:ro";
        # Does not work well with the temporary root
        #UMask = "0066";
        UMask = "0066";
      } // optionalAttrs (cfg.environmentFile != null) {
        EnvironmentFile = cfg.environmentFile;
      };