forked from mirrors/nixpkgs
dd9883b2fb
The service can run unprivileged -- by using capabilities -- and the uid/gid can be dynamically allocated since there are only a handful of state files. This change improves the overall security of the service by leveraging systemd's hardening and getting rids of `nogroup` and the initial root permissions (before the daemon drop privileges). |
||
---|---|---|
.. | ||
config | ||
hardware | ||
i18n/input-method | ||
installer | ||
misc | ||
profiles | ||
programs | ||
security | ||
services | ||
system | ||
tasks | ||
testing | ||
virtualisation | ||
module-list.nix | ||
rename.nix |