1
0
Fork 1
mirror of https://github.com/NixOS/nixpkgs.git synced 2024-11-18 11:40:45 +00:00
nixpkgs/nixos/modules/config
Bjørn Forsman fa8ace3618 nixos: don't implicitly map missing user groups to nogroup
Before: `users.users.user1.group = "group-not-defined-anywhere-else"`
would result in user1 having the primary group `nogroup`, assigned at
activation time and only with a (easy to miss) warning from the
activation script. This behaviour is a security issue becase no files
should be owned by `nogroup` and it allows for unrelated users (and
services) to accidentally have access to files they shouldn't have.

After: The configuration above results in this eval error:
  - The following users have a primary group that is undefined: user1
  Hint: Add this to your NixOS config:
    users.groups.group-not-defined-anywhere-else = {};
2023-10-06 19:33:01 +02:00
..
fonts noto-fonts-emoji → noto-fonts-color-emoji 2023-09-12 12:38:07 +00:00
gtk
krb5
xdg nixos: fix typos 2023-05-19 22:31:04 -04:00
appstream.nix
console.nix nixos/console: use systemd-vconsole-setup.service from upstream for sd initrd 2023-09-13 12:02:40 +02:00
debug-info.nix
gnu.nix nixos/*: remove boot.grub.version 2023-05-10 21:51:26 +02:00
i18n.nix nixos/i18n: correct defaultText for supportedLocales 2023-07-08 16:43:22 +02:00
iproute2.nix
ldap.nix
locale.nix
malloc.nix Revert "nixos/malloc: add back maybe unnecessary line" 2023-08-10 03:02:39 +02:00
mysql.nix
networking.nix
nix-channel.nix nixos/nix-channel: only try to remove the nix-channel binary if it exists 2023-07-24 10:34:48 +02:00
nix-flakes.nix nixos: flakes.nix -> nix-flakes.nix 2023-07-06 23:27:17 +02:00
nix-remote-build.nix nixos/nix*: remove not necessary imports 2023-07-07 11:01:12 +02:00
nix.nix nixos: flakes.nix -> nix-flakes.nix 2023-07-06 23:27:17 +02:00
no-x-libs.nix nixos/no-x-libs: use pythonPackagesExtensions to construct python overlay 2023-08-01 15:36:15 +02:00
nsswitch.nix
power-management.nix
pulseaudio.nix
qt.nix nixos/qt: install qt6gtk2 when using gtk2 2023-07-27 15:39:30 -03:00
resolvconf.nix
shells-environment.nix
stevenblack.nix
swap.nix nixos/swap: make sure all kernel modules are loaded before creating swap devices. (#239163) 2023-07-13 17:12:54 +02:00
sysctl.nix nixos/sysctl: raise default vm.max_map_count to 1048576 2023-06-21 19:25:42 +02:00
system-environment.nix
system-path.nix nixos/nano: add enable, package option, do not create /etc/nanorc by default 2023-09-29 00:24:34 +02:00
terminfo.nix nixos/{sudo, terminfo}: Adjust defaults for compatibility with sudo-rs 2023-09-18 17:36:15 +00:00
unix-odbc-drivers.nix
update-users-groups.pl nixos/user-groups: fixup of 5666a378 2023-09-13 11:44:19 +02:00
users-groups.nix nixos: don't implicitly map missing user groups to nogroup 2023-10-06 19:33:01 +02:00
vte.nix
zram.nix nixos/zram: use nixos/zram-generator as backing implementation 2023-08-13 15:38:40 +08:00