nixos/paperless: Enable UMask now that it works (#240352)

According to
https://github.com/NixOS/nixpkgs/issues/147599#issuecomment-1272286679
the bug that prevented this UMask directive from working has been fixed
in systemd, so it should be safe to use now.

This stops paperless-ngx from making everything world-readable on disk,
but it does not change permissions of any files previously created.

(cherry picked from commit c23f47f23e)

Co-authored-by: Benjamin Staffin <benley@gmail.com>
This commit is contained in:
github-actions[bot]
2023-06-28 15:10:43 -04:00
committed by GitHub
parent 49ae3495e5
commit 4e2c47f4a3

View File

@@ -86,8 +86,7 @@ let
SupplementaryGroups = optional enableRedis redisServer.user;
SystemCallArchitectures = "native";
SystemCallFilter = [ "@system-service" "~@privileged @setuid @keyring" ];
# Does not work well with the temporary root
#UMask = "0066";
UMask = "0066";
};
in
{