Skip to content

Commit 4d2bb49

Browse files
committed
nixos/meme-bingo-web: harden
1 parent db6c599 commit 4d2bb49

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

nixos/modules/services/web-apps/meme-bingo-web.nix

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -89,6 +89,9 @@ in
8989
InaccessiblePaths = [
9090
"/dev/shm"
9191
"/sys"
92+
"/run/dbus"
93+
"/run/user"
94+
"/run/nscd"
9295
];
9396
LockPersonality = true;
9497
PrivateDevices = true;
@@ -124,6 +127,8 @@ in
124127
RemoveIPC = true;
125128
NoNewPrivileges = true;
126129
MemoryDenyWriteExecute = true;
130+
ExecPaths = [ "/nix/store" ];
131+
NoExecPaths = [ "/" ];
127132
};
128133
};
129134
};

0 commit comments

Comments
 (0)