Unverified Commit e0e68c54 authored by h7x4's avatar h7x4 Committed by GitHub
Browse files

nixos/tor: add onion service unix sockets to BindPaths (#440889)

parents 1f47d970 16a1b0e5
Loading
Loading
Loading
Loading
+8 −1
Original line number Diff line number Diff line
@@ -1410,7 +1410,14 @@ in
        RootDirectoryStartOnly = true;
        #InaccessiblePaths = [ "-+${runDir}/root" ];
        UMask = "0066";
        BindPaths = [ stateDir ];
        BindPaths = [
          stateDir
        ]
        ++ lib.catAttrs "unix" (
          lib.catAttrs "target" (
            lib.concatMap (onionService: onionService.map) (lib.attrValues cfg.relay.onionServices)
          )
        );
        BindReadOnlyPaths = [
          builtins.storeDir
          "/etc"