2024-12-30 02:27:37 +08:00
|
|
|
{
|
|
|
|
config,
|
|
|
|
lib,
|
|
|
|
mylib,
|
|
|
|
...
|
|
|
|
}:
|
2024-12-25 18:30:53 +08:00
|
|
|
{
|
|
|
|
services.nscd = {
|
|
|
|
enable = true;
|
|
|
|
enableNsncd = true;
|
|
|
|
};
|
|
|
|
|
|
|
|
systemd.services.nscd.serviceConfig = mylib.misc.serviceHardened // {
|
2024-12-30 02:27:37 +08:00
|
|
|
RuntimeDirectory = lib.mkForce "";
|
2024-12-25 18:30:53 +08:00
|
|
|
ProtectHome = lib.mkForce true;
|
|
|
|
};
|
2024-12-30 02:27:37 +08:00
|
|
|
|
|
|
|
systemd.tmpfiles.settings."20-nscd" = {
|
|
|
|
"/run/nscd".d = {
|
|
|
|
mode = "0755";
|
|
|
|
user = config.services.nscd.user;
|
|
|
|
group = config.services.nscd.group;
|
|
|
|
};
|
|
|
|
};
|
2024-12-25 18:30:53 +08:00
|
|
|
}
|