From a71c60bfe4cf71ffca38242814f0d1877489b2bd Mon Sep 17 00:00:00 2001 From: Erik Arvstedt Date: Sat, 21 Jan 2023 13:14:28 +0100 Subject: [PATCH] fulcrum: allow access to `/proc/meminfo` This still hides the proc subdirectories for other processes. Without this setting, fulcrum fails when the config value of `fast-sync` is greater than 2^31 bytes. --- modules/fulcrum.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/fulcrum.nix b/modules/fulcrum.nix index 0cbb87d..592757a 100644 --- a/modules/fulcrum.nix +++ b/modules/fulcrum.nix @@ -126,6 +126,7 @@ in { Restart = "on-failure"; RestartSec = "10s"; ReadWritePaths = cfg.dataDir; + ProcSubset = "all"; # Fulcrum requires read access to /proc/meminfo } // nbLib.allowedIPAddresses cfg.tor.enforce; };