nixos/podman: wrap /run/wrappers for setuid shadow binaries

adding it here so it only needs to be done once
This commit is contained in:
zowoq 2023-02-10 08:21:36 +10:00
parent 8ee6a032ca
commit 04b9fcca93

View file

@ -7,6 +7,8 @@ let
podmanPackage = (pkgs.podman.override {
extraPackages = cfg.extraPackages
# setuid shadow
++ [ "/run/wrappers" ]
++ lib.optional (builtins.elem "zfs" config.boot.supportedFilesystems) config.boot.zfs.package;
});