Unverified Commit b1732ebd authored by Martin Weinelt's avatar Martin Weinelt
Browse files

nixos/tetrd: remove CAP_DAC_OVERRIDE

That's just a bonkers capability to hand out because a program uses
stupid paths that it does not have permissions on.
parent 788368c3
Loading
Loading
Loading
Loading
+1 −4
Original line number Diff line number Diff line
@@ -89,17 +89,14 @@

          BindPaths = [
            "/etc/tetrd/resolv.conf:/etc/resolv.conf"
            "/run"
            "/var/log"
            "/run/tetrd:/run"
          ];

          CapabilityBoundingSet = [
            "CAP_DAC_OVERRIDE"
            "CAP_NET_ADMIN"
          ];

          AmbientCapabilities = [
            "CAP_DAC_OVERRIDE"
            "CAP_NET_ADMIN"
          ];
        };