diff --git a/modules/config/sysctl.nix b/modules/config/sysctl.nix index c3d5b8d223b2..f3cc21307680 100644 --- a/modules/config/sysctl.nix +++ b/modules/config/sysctl.nix @@ -53,6 +53,12 @@ in }; }; + # Enable hardlink and symlink restrictions. See + # https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=800179c9b8a1e796e441674776d11cd4c05d61d7 + # for details. + boot.kernel.sysctl."fs.protected_hardlinks" = true; + boot.kernel.sysctl."fs.protected_symlinks" = true; + }; }