From 72f451bd01d7804715ee124152ac7e9bfb174b7e Mon Sep 17 00:00:00 2001 From: Minijackson Date: Thu, 13 Aug 2026 17:16:42 +0200 Subject: [PATCH] nixos/miniflux: fix AppArmor profile --- nixos/modules/services/web-apps/miniflux.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/web-apps/miniflux.nix b/nixos/modules/services/web-apps/miniflux.nix index ebc77394ad53..585f00b9891e 100644 --- a/nixos/modules/services/web-apps/miniflux.nix +++ b/nixos/modules/services/web-apps/miniflux.nix @@ -208,7 +208,13 @@ in abi , include - profile ${cfg.package}/bin/miniflux { + # Flag `attach_disconnected` is necessary + # because the PostgreSQL socket path appears + # as a "disconnected" path: `run/postgresql/.s.PGSQL.XXXX`, + # without the trailing slash, which AppArmor can't resolve. + # The flag prepends a `/`, which isn't recommended, + # but there aren't any alternative currently. + profile ${cfg.package}/bin/miniflux flags=(attach_disconnected) { include include include @@ -216,6 +222,8 @@ in include "${pkgs.apparmorRulesFromClosure { name = "miniflux"; } cfg.package}" ${cfg.package}/bin/miniflux r, /run/miniflux/** rw, + /run/postgresql/.s.PGSQL.* rw, + /run/credentials/** r, include if exists } '';