From 0b5b29a2a3903122897badfb0b6841eef260a0f1 Mon Sep 17 00:00:00 2001 From: Erik Arvstedt Date: Mon, 1 Feb 2021 22:53:09 +0100 Subject: [PATCH] netns-isolation: simplify permission definition for netns-exec The new definition is equivalent to the old one. --- modules/netns-isolation.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/netns-isolation.nix b/modules/netns-isolation.nix index d0088dc..30fb57c 100644 --- a/modules/netns-isolation.nix +++ b/modules/netns-isolation.nix @@ -105,7 +105,7 @@ in { source = config.nix-bitcoin.pkgs.netns-exec; capabilities = "cap_sys_admin=ep"; owner = cfg.allowedUser; - permissions = "u+rx,g+rx,o-rwx"; + permissions = "550"; }; systemd.services = {