nixos/hardened: simplify script

This commit is contained in:
Joachim Fasting 2017-09-10 01:10:29 +02:00
parent 84bd2f4ab0
commit 15a4f9d8ef
No known key found for this signature in database
GPG Key ID: 66EAB6B14F6B6E0D

View File

@ -21,15 +21,15 @@ with lib;
description = "Disable kernel module loading";
wantedBy = [ config.systemd.defaultUnit ];
after = [ "systemd-udev-settle.service" "firewall.service" "systemd-modules-load.service" ] ++ wantedBy;
script = "echo -n 1 > /proc/sys/kernel/modules_disabled";
after = [ "systemd-udev-settle.service" "firewall.service" "systemd-modules-load.service" ] ++ wantedBy;
unitConfig.ConditionPathIsReadWrite = "/proc/sys/kernel";
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
ExecStart = "/bin/sh -c 'echo -n 1 >/proc/sys/kernel/modules_disabled'";
};
};
};