Merge pull request #108028 from Mic92/confinment

systemd-confinement: use /var/empty as chroot mountpoint
This commit is contained in:
Jörg Thalheim 2021-07-01 07:09:27 +01:00 committed by GitHub
commit 8737aa9311
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -105,7 +105,7 @@ in {
wantsAPIVFS = lib.mkDefault (config.confinement.mode == "full-apivfs");
in lib.mkIf config.confinement.enable {
serviceConfig = {
RootDirectory = pkgs.runCommand rootName {} "mkdir \"$out\"";
RootDirectory = "/var/empty";
TemporaryFileSystem = "/";
PrivateMounts = lib.mkDefault true;