forked from mirrors/nixpkgs
Merge pull request #138516 from rnhmjoj/lock-kernel-fix
nixos/lock-kernel-modules: reorder before/after
This commit is contained in:
commit
ea1eae5b47
|
@ -35,10 +35,10 @@ with lib;
|
|||
wants = [ "systemd-udevd.service" ];
|
||||
wantedBy = [ config.systemd.defaultUnit ];
|
||||
|
||||
before = [ config.systemd.defaultUnit ];
|
||||
after =
|
||||
[ "firewall.service"
|
||||
"systemd-modules-load.service"
|
||||
config.systemd.defaultUnit
|
||||
];
|
||||
|
||||
unitConfig.ConditionPathIsReadWrite = "/proc/sys/kernel";
|
||||
|
|
|
@ -57,6 +57,7 @@ import ./make-test-python.nix ({ pkgs, latestKernel ? false, ... } : {
|
|||
# Test kernel module hardening
|
||||
with subtest("No more kernel modules can be loaded"):
|
||||
# note: this better a be module we normally wouldn't load ...
|
||||
machine.wait_for_unit("disable-kernel-module-loading.service")
|
||||
machine.fail("modprobe dccp")
|
||||
|
||||
|
||||
|
|
Loading…
Reference in a new issue